Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

131–140 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#131

I'm excited by the insight and modesty of this guy. I will see to it that he gets a mighty prize. It's great to see how open software can leverage the power of the community to find weak spots and become stronger.

It is good to see that you recognise modesty as a virtue.

May I suggest that you guys take a leaf out of his book and rewrite the security claims in your FAQ to reflect the fact that the protocol is new and at this point there are likely to be some bugs but that you are working hard to make it secure.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#132
post #36

Earlier quoted context omitted.

Never forget. RIP Telegram (2013-2013). This whole thing has been interesting to follow because it seems this same thing happens every time someone make macho Crypto-claims. From seeing how confident the Telegram team was to reading all the detractors who were so ready to criticize. It's an interesting dynamic in the Crypto community.

By that logic, Linux, Chrome, Android are RIP at least a hundred times.

[deleted]

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#133
post #115

This is my first comment on the Telegram bruhaha. Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride. To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. I will not wish failure on anyone that is confident i…

> To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. But it is not secure! That's the entire point. Never mind "not secure against a well funded government agency", it's not secure against other attackers. There are lots of usable chat apps that do not…

Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of the cryptography process.

I like your commentary it is level headed and explains the position of the non biased "other side".

I think the conflicted position of the lead bashers did not help their position. It would have been much more useful for a neutral party to do a comparative analysis and stated the pros and cons of each side.

As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks. There may be some sacrifices that may have to be made. Just like the position Ubuntu plays where Linux distros are concerned

For people like Snowden, Greenwald and others with NSA level adversaries, I do not expect them to rely on any third party application at all.

Now your argument may be that they have created stuff for sexting teens and claimed to be good enough for Snowden. In that case, I would argue that it could have been pointed out that in a different and perhaps more polite way.

I would worry about anyone who has created any crypto tool who is not over confident in his product. I will also expect the person to be receptive to constructive feedback NOT "leave your product and join us" or "This is shit because no noted crypto person is on your team"

I remember when cperciva that built Tarsnap, an online "backup for paranoid users" launched, he was rather confident in his product and I did not see any intense bashing of him. As expected,there have been bugs in his system and he has fixed them as they have arisen.

We should help things grow right here on HN not hope for things to fail if they do not support the view of the crowd.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#134
post #122

Earlier quoted context omitted.

I’m not security expert, but I believe that: - military-grade encryption – true - world's most secure protocol – I’d consider this statement as false, I don’t know what they mean by most secure and what protocols were considered. May be messengers available at app store, better to ask them Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition…

Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition? I've written about this pretty extensively: https://www.hnsearch.com/search#request/all&q=by%3Asillysaur... It's an interesting contrast in cultures that you phrase it like "Why do you think Telegram lies more than TextSecure advocates?" .... As far as I'm aware, TextSecure advocates have…

> Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app

> I just don't know what to say to this. Telegram has been proven insecure, TextSecure hasn't. Telegram isn't designed by cryptographers, TextSecure is. There is absolutely every reason to assume Telegram is broken.

Textsecure is designed by cryptographers, and hasn't been broken yet, but that doesn't mean that it is secure. People need to risk assess when they're using any software.

> If you want to be secure from the NSA, use TextSecure [...]. It's really that simple.

That claim is far too confidant! If you want to be secure from NSA you need to do many things - have a look at the specifications for buildings that handle secret documents for example, as well as just using a piece of well designed but relatively untested software.

Most people do not have nearly enough operational discipline to withstand investigation by well funded government agencies. Merely using this software is not enough.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#135
post #134

Earlier quoted context omitted.

Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition? I've written about this pretty extensively: https://www.hnsearch.com/search#request/all&q=by%3Asillysaur... It's an interesting contrast in cultures that you phrase it like "Why do you think Telegram lies more than TextSecure advocates?" .... As far as I'm aware, TextSecure advocates have…

> Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app > I just don't know what to say to this. Telegram has been proven insecure, TextSecure hasn't. Telegram isn't designed by cryptographers, TextSecure is. There is absolutely every reason to assume Telegram is broken. Textsecure is designed by cryptographers, and hasn't been broken yet, but that doesn…

> If you want to be secure from the NSA, use TextSecure [...]. It's really that simple.

That claim is far too confidant! If you want to be secure from NSA you need to do many things - have a look at the specifications for buildings that handle secret documents for example, as well as just using a piece of well designed but relatively untested software.

That's why I removed it 15 seconds after I wrote it. But perhaps it could be downgraded to "if you want to live in a world where it's very difficult for governments to vacuum up all your data by default, then use TextSecure, because it's the first step towards that." Telegram offers no such protection since it's vulnerable to MITM attacks (even after they fix this one).

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#136
post #28

As a side note, I didn't notice it was google translate until half way through the article. It's getting really good. Is Russian an "easy" language to translate to English?

Does this seem good to you? Damn, I feel I should stop worrying about my English.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#137
post #115

Earlier quoted context omitted.

> To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. But it is not secure! That's the entire point. Never mind "not secure against a well funded government agency", it's not secure against other attackers. There are lots of usable chat apps that do not…

Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of…

I wholeheartedly disagree. For any user, the security we need is prevent eavesdropping & data mining by our governments. They use it to profile us, to find thoughtcrime and to secure their standing in a surveillance society. We should not let that happen.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#138
post #51
post #42

Earlier quoted context omitted.

That's absolutely true, but I think the reason this seems so devastating for Telegram is not necessarily because there was a vulnerability, but because they were so dismissive of the feedback they got and so willing to immediately make such strong claims. The way I hope TextSecure can be different from Telegram is not by having an absolutely perfect security record forever (although that'd be great), but by publicly…

To be fair, no one here mentioned anything related to the found vulnerability. Instead people seemed to have focused on their choice of SHA1 and IGE.

I think that is incorrect. This is a problem with the protocol which is the main thing people were raising as having a distinct smell and being novel for no good reason so while most of the comments were not about specific flaws they were not unrelated. IGE and SHA1 were the obvious red flags that people involved were not up to date with the latest crypto research.

[Edit: I can't find the comment so I withdraw this claim:

There was at least one comment possibly from moxie mentioning odd use of nonces that may have been in this area, if so it was right on target.]

To make a harsh analogy it's like using a colander for a boat and then complaining that a particular hole wasn't pointed out to them.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#140
post #115

Earlier quoted context omitted.

> To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. But it is not secure! That's the entire point. Never mind "not secure against a well funded government agency", it's not secure against other attackers. There are lots of usable chat apps that do not…

Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of…

I don't think your arguments make a lot of sense:

> It would have been much more useful for a neutral party to do a comparative analysis and stated the pros and cons of each side.

And what would this neutral party be?

> As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks. There may be some sacrifices that may have to be made. Just like the position Ubuntu plays where Linux distros are concerned

You make it sound as if having government-grade encryption was very hard or very costly but that's obviously not the case, there are many open encryption standard who wouldn't have had the kind of issues Telegram has. Do you want to start a new contest targeting a properly configured openSSH for instance? There is no need for tradeoff there.

> I remember when cperciva that built Tarsnap, an online "backup for paranoid users" launched, he was rather confident in his product and I did not see any intense bashing of him. As expected,there have been bugs in his system and he has fixed them as they have arisen.

Colin Percival has credentials and experience in the cryptoworld. When he makes "new" crypto like scrypt he publishes it and it's been thoroughly reviewed. It also has distinct advantages over previous technologies, it's not just new for the sake of being new.

Crypto is serious business, people can get hurt. Toying with crypto, proposing new ideas is of course to be encouraged, but be humble about it and listen to the feedback. Actually, this last part is true for everything.

Post reply on HN