Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

101–110 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#101
post #41

Here are some of their comments: ibeatle Большое спасибо, автор поста полностью прав. Со своей стороны хотим пояснить, что сделано это было из лучших побуждений: исправление плохого рандома на клиентах. С настоящего момента в nonce всегда будет приходить ноль, и в следующем слое мы обязательно удалим это поле из схемы и поясним в документации. Автор топика безусловно заслужил награды, просьба обратиться хабраюзера x7…

Does "nonce" here have a meaning I don't know? Its just that here in the UK, its common meaning isnt exactly positive.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#102

Earlier quoted context omitted.

I'm not actually familiar with that one. Clue me in?

Well chances are that the OP I responded to (I can't even see his name well enough to repeat it he's so faded now) will have his account ghosted if he keeps this up. One too many mega-downvote-comments by a new user and you end up being ghosted. Where you still think you're posting to HN, and you are, but nobody else can read it. All I was saying is perhaps if pg et all decreased whatever threshold they have set for…

It is not automatic, as far as I know. It requires human intervention for someone to be hellbanned, or "ghosted". It isn't very systematic, and I've seen people hellbanned who probably didn't deserve it (and it usually does get fixed when that happens).

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#103
post #79
post #61

Earlier quoted context omitted.

Why would you post such an inane one-liner like that? Jimmytucson made a very good point, which is that the very intelligent Telegram authors tried really hard to make a solid product, made a huge gamble that didn't quite pay off like they wanted, and that all we see now are the smug, told-you-so vultures swooping in to pat themselves on the back for being oh so much smarter than the stupid crypto guys.

The reason for these comments is because you're exactly right– they are gambling . Putting $200k on the line in the hopes of winning mindshare, reputation, etc. Of course if you lose, you'll lose all of that and your money. I'm really happy that more people are getting into crypto and not browbeating themselves out of creating new stuff because it's necessary for any field to grow. These negative responses are also n…

I'm not sure they were gambling. My feeling is ghat they were victim of the bias of self judgment regarding the security of the protocol they designed.

They overlooked some security weakness and didn't see it. They didn't do it on purpose like the NSA. In their eyes, the protocol was perfectly secure and most of it is of course.

The only way to avoid this self judgment bias is to use review by other people.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#104
post #41

Here are some of their comments: ibeatle Большое спасибо, автор поста полностью прав. Со своей стороны хотим пояснить, что сделано это было из лучших побуждений: исправление плохого рандома на клиентах. С настоящего момента в nonce всегда будет приходить ноль, и в следующем слое мы обязательно удалим это поле из схемы и поясним в документации. Автор топика безусловно заслужил награды, просьба обратиться хабраюзера x7…

Does "nonce" here have a meaning I don't know? Its just that here in the UK, its common meaning isnt exactly positive.

https://en.wikipedia.org/wiki/Cryptographic_nonce

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#105
post #48

Earlier quoted context omitted.

I don't get it. If it's not secure why can't the message be revealed? What's the value of breaking someone's crypto if you are still unable to see the data unencrypted? Was the recipe for decryption given, with the actual decryption being much harder (terms so narrow, as you say)?

Moxie's blog post does a better job explaining the problems than I can [1]. Basically, the framework of the contest precludes many avenues of attack to which a given cryptosystem could be vulnerable. The researcher who discovered the vulnerability in the OP used a man-in-the-middle attack, which cannot be used in the Telegram contest.

[1] http://thoughtcrime.org/blog/telegram-crypto-challenge/

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#106
post #61
post #60

Earlier quoted context omitted.

Are you suffering from testosterone poisoning or something?

Why would you post such an inane one-liner like that? Jimmytucson made a very good point, which is that the very intelligent Telegram authors tried really hard to make a solid product, made a huge gamble that didn't quite pay off like they wanted, and that all we see now are the smug, told-you-so vultures swooping in to pat themselves on the back for being oh so much smarter than the stupid crypto guys.

The problem is, people who know better told them they were in over their heads and gave them some constructive criticism. Sure moxie can sound condescending, but he was right about telegram.

Telegram's response was basically, "LOL. We know better cuz' we got binders full of mathematicians and I'm not listening unless you win our rigged contest designed purposefully to instill a false sense of security in our customers."

Cryptographic software isn't developed the same way as ordinary software. A normal program is launched with tons of bugs and gets fixed over the course of years. Custom crypto solutions should not be delivered to customers in a similar state without explicitly telling them that it hasn't been proven secure.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#107
post #28

As a side note, I didn't notice it was google translate until half way through the article. It's getting really good. Is Russian an "easy" language to translate to English?

English to Russian is a bit easier than Russian to English. Word order doesn't mean as much in Russian as in English, so the translation is lossy.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#108
This is my first comment on the Telegram bruhaha.

Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride.

To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January.

I will not wish failure on anyone that is confident in his product. Of course they could have shown more humility but it he face of "take downs" on all sides especially the ones sponsored or initiated by the Whispersystem/Texsecure chaps, I do not see why they should have bowed down to be crushed.

Considering the type of responses given by Pavel Durov, I am almost certain he would have been much more humble if his attackers toned it down a notch.

To the person that found a flaw, kudos to you on doing something and not spending all your time doing take downs of telegram on HN threads and blogs.

Pavel, I am hopeful that you will reward the chap even though the discovery was not within the "guidelines". it is all about the spirit of the competition.

As for the TextSecure/WhisperSystems guys, stop being like the politicians we hate who campaign by slinging mud on opponents instead of selling their stuff. Focus on selling the TextSecure app and not looking to takeout anyone who has a different approach.

PS: I have no relationship with either party. I am a neutral observer that has his own opinions.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#109
post #36
post #34

There's a lesson here. I genuinely don't mean to sound smug, but -- remember how confident the Telegram guys were? Remember how sure they were that their protocol would be able to resist the eavesdropping efforts of the NSA and whatever other nefarious interlopers may come along? Remember how they said they'd been working on it for years, and presumably expected for it to last many more years? Remember how that was,…

Never forget. RIP Telegram (2013-2013). This whole thing has been interesting to follow because it seems this same thing happens every time someone make macho Crypto-claims. From seeing how confident the Telegram team was to reading all the detractors who were so ready to criticize. It's an interesting dynamic in the Crypto community.

By that logic, Linux, Chrome, Android are RIP at least a hundred times.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#110
post #41

Here are some of their comments: ibeatle Большое спасибо, автор поста полностью прав. Со своей стороны хотим пояснить, что сделано это было из лучших побуждений: исправление плохого рандома на клиентах. С настоящего момента в nonce всегда будет приходить ноль, и в следующем слое мы обязательно удалим это поле из схемы и поясним в документации. Автор топика безусловно заслужил награды, просьба обратиться хабраюзера x7…

  as opposed to all those so-called professionals whose 
  criticisms were largely unfounded.
Those criticisms still stand. Your perjorative 'so-called' is the only thing unfounded. And actually, the DH modification was one of the red flags mentioned.
Post reply on HN