Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

121–130 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#121
post #111
post #52

Would this hole allow him to decrypt chat text?

no, but it allows server to decrypt it. Government in case of the need can "ask" them to forward your chat and they will do it, but it was stated in their PR that server is unable to decrypt your messages.

exactly, the prize was at their own discretion(telegram) in the first place. And it was still for breaking their End-to-End encryption process.

To simply put it, you don't have to break a wall, just find a loose brick, once that is gone, the wall will have even more loose bricks, and eventually it will fall.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#122
post #94

Earlier quoted context omitted.

Hate tone discussion makes me sad. Telegram is very young project and it has bugs for sure. Some guy found potential issue in protocol and developers committed to fix it soon. There is no information that any messages were revealed due to this bug but Telegram should go away and developers should do something else. Whatsapp is less secure then Telegram but I have not seed “Whatsapp RIP” messages. Not so hard to save…

You must not have followed Telegram much. From the beginning they've done nothing but pretend their protocol is absolutely secure ("military-grade encryption", "world's most secure protocol", etc) and rejected any attempt from the crypto community to help them fix problems before they endanger people. So, let's put it this way: Was it ok of them to lie through their teeth to users? If so, then that's a sad state of m…

I’m not security expert, but I believe that:

- military-grade encryption – true

- world's most secure protocol – I’d consider this statement as false, I don’t know what they mean by most secure and what protocols were considered. May be messengers available at app store, better to ask them

Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition?

Why do you think that they lie more then TextSecure advocates? Each of these messengers is safe to passive listening. But unsecure to similar degree if user downloads them from app store and runs on hardware and software that could be easily patched. Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app and that every other app should be thrown out.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#123
post #44
post #8

Earlier quoted context omitted.

Telegram's contest itself is meaningless regarding the security of its protocol (as others explained in details). Finding bugs such as this deserves 200k more than anything else

Offering the contest was shady and stupid enough. Not paying just proves they're chiselers that never intended to pay in the first place. This wins the runner-up award for second most botched PR disaster ever. The consolation prize is a lump of coal.

The contest was stupid and shady, but they did explicitly state the rules. Its not really fair to accuse them of wrongdoing if they don't give this guy $200,000. If I were in charge of telegram, I'd pay the guy the whole amount, but that would just be out of the kindness of my heart. Morally, they aren't obligated to pay just because the rules of their contest are ridiculous.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#124
Lol, I don't know whats so bad in Telegram being a bit "braggy" about their stuff. I mean, it took them a lot of hard work, in the first place since they did a lot of things on their own, instead of using pre-set standards. Everyone can loose a grip on self control, more than a few times. So what!

Besides, its only to inspire someone to crack their program, it is necessary to come across as a bit arrogant, so someone would loose a screw and crack it. never mind the buttery language post-cracking, since that usually comes from appreciation for each other.

Putting up a challenge publicly is a great PR tool, I feel its not reasonable to only bash 1 company about it. Unless, there is something I don't know, about what they said/did earlier on HN.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#125
post #72

Why is Telegram in the HNews so much? Are they part of the YC fraternity? Why do pay so much attention to crypto hucksters? It hasn't been so long since the last snake oil peddlers had their roasting -- I forget the name, it was some cutesy web-browser "secure" chat thing. It's cool to report debunkings, but if it weren't for HN, I (and most others?) never would have even seen these products in the first place.

HN is (rightly) interested in easy to use secure software.

So when something easy to use claims to be secure HN waits for some of the well known cryptographers here to kick the tires.

In this case many people kicked the tires and pointed out some weird obvious flaws. People hoped that Telegram would listen, and seek help and advice, and continue to make a great product.

Telegram's actions made the situation worse, and created a pile-on.

Telegram made a few mistakes.

1) Smart people without crypto experience designed crypto software, but without getting involvement from cryptographers.

2) They released this product as finished, secure, ready to use.

3) They dismissed concerns.

4) To try to quash those concerns they created a rigged challenge with a high value prize. This is a well known red flag for cryptography software, and it's surprising they weren't aware of it, but as soon as people saw that the pile on accelerated.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#126

This is my first comment on the Telegram bruhaha. Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride. To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. I will not wish failure on anyone that is confident i…

The wishing of failure isn't great, my personal wish would be for the Telegram people to learn the errors of their ways rather than necessarily completely fail.

Overstated claims of privacy could get people killed if they trust them so it is a serious issue.

Telegram have an arrogance that is inappropriate in security/crypto protocol development. Most crypto protocols, even those developed by experts initially have problems (at the protocol design level even ignoring the implementation bugs) which is why even experts only come up with new ones when there isn't any existing one with the required properties and even then reuse as much existing battle tested technology as possible and submit it to worldwide evaluation tentatively and nervously.

The competition was set up in a way that clearly excluded most threats and was either another sign that Telegram didn't understand most of the threat space OR that they did and wanted to rig the competition to be unwinnable while claiming that it validated the security in some way.

So at least until yesterday Telegram were arrogant and either completely clueless about crypto protocols or PR bullshitters with some clue and a poor protocol. They need to get a clue AND drop the arrogance to get support from me.

Until these things happen Telegram are a danger that people should be warned about and not regard as secure.

I am also a neutral party with no relationship with either party.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#127
post #103
post #79

Earlier quoted context omitted.

The reason for these comments is because you're exactly right– they are gambling . Putting $200k on the line in the hopes of winning mindshare, reputation, etc. Of course if you lose, you'll lose all of that and your money. I'm really happy that more people are getting into crypto and not browbeating themselves out of creating new stuff because it's necessary for any field to grow. These negative responses are also n…

I'm not sure they were gambling. My feeling is ghat they were victim of the bias of self judgment regarding the security of the protocol they designed. They overlooked some security weakness and didn't see it. They didn't do it on purpose like the NSA. In their eyes, the protocol was perfectly secure and most of it is of course. The only way to avoid this self judgment bias is to use review by other people.

> In their eyes, the protocol was perfectly secure and most of it is of course.

That there is exactly the problem. There is no reason to believe the protocol is secure, and when looking at crypto you start from the assumption that it's "maybe broken", not "perfectly secure". Assuming that some new crypto is secure is hubris.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#128
post #122

Earlier quoted context omitted.

You must not have followed Telegram much. From the beginning they've done nothing but pretend their protocol is absolutely secure ("military-grade encryption", "world's most secure protocol", etc) and rejected any attempt from the crypto community to help them fix problems before they endanger people. So, let's put it this way: Was it ok of them to lie through their teeth to users? If so, then that's a sad state of m…

I’m not security expert, but I believe that: - military-grade encryption – true - world's most secure protocol – I’d consider this statement as false, I don’t know what they mean by most secure and what protocols were considered. May be messengers available at app store, better to ask them Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition…

Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition?

I've written about this pretty extensively: https://www.hnsearch.com/search#request/all&q=by%3Asillysaur...

It's an interesting contrast in cultures that you phrase it like "Why do you think Telegram lies more than TextSecure advocates?" .... As far as I'm aware, TextSecure advocates haven't lied at all. TextSecure's interest is in security, whereas Telegram's interest seems to be in money and power.

Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app

I just don't know what to say to this. Telegram has been proven insecure, TextSecure hasn't. Telegram isn't designed by cryptographers, TextSecure is. There is absolutely every reason to assume Telegram is broken.

Each of these messengers is safe to passive listening.

This is mistaken because Telegram has been proven vulnerable to MITM attacks. Even after they patch this latest security problem, it would be very unwise to trust them.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#129
post #118
post #94

Earlier quoted context omitted.

Hate tone discussion makes me sad. Telegram is very young project and it has bugs for sure. Some guy found potential issue in protocol and developers committed to fix it soon. There is no information that any messages were revealed due to this bug but Telegram should go away and developers should do something else. Whatsapp is less secure then Telegram but I have not seed “Whatsapp RIP” messages. Not so hard to save…

> Whatsapp is less secure then Telegram Whatsapp never claimed to keep your chat secure. Telegram did. Many people offered gentle advice to Telegram, and they ignored it. Maybe it's a cultural thing? Not just domains-of-expertise (mathematicians going into crypto) but international?

Snapchat creators claim (at least imply) that messages could not be saved which is untrue.

Most advices to telegram developers at previous HN discussion were to stop doing crypto and do something else. I would not consider them as “gentle advices”. The only help from the community to their application is the bug report x7mz user from habrahabr site.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#130

TextSecure's protocol, on the other hand, hasn't ever been compromised. Don't use Telegram. Use TextSecure. https://whispersystems.org/

What about iOS? I wish there was one go-to secure messenger for iOS, and I thought telegram would be it.
Post reply on HN