Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

141–150 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#141
post #41

Here are some of their comments: ibeatle Большое спасибо, автор поста полностью прав. Со своей стороны хотим пояснить, что сделано это было из лучших побуждений: исправление плохого рандома на клиентах. С настоящего момента в nonce всегда будет приходить ноль, и в следующем слое мы обязательно удалим это поле из схемы и поясним в документации. Автор топика безусловно заслужил награды, просьба обратиться хабраюзера x7…

Second comment (W_K) is by Nick Durov, the leading author of MTProto, Telegram's protocol.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#143
Noone should trust a service that advertises itself as being safe from governments ears. Pure and simple.

First, there's a risk the NSA is actually the one initiating those services.

Secondly, in cryptography, it's very hard if not impossible to effectively prove your messages are not read by someone else. Cryptography experts do not tend to work for people's interests. And if some do, the NSA has too many resources to just defeat those who try to not be listened to.

I understand the intention is noble, but if you release such a safe tool, the NSA will view it as a terrorist threat, because that's the job they have been given, and they will end up listening anyways.

I can't understand the paranoia about all this. If you're really afraid the NSA might use information against you, it's because you made political enemies, in this case, why use digital means of communication at all ?

I really tend to think it's being cool to use those cryptographic features, rather than anything else, and that's worrying.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#144

I'm excited by the insight and modesty of this guy. I will see to it that he gets a mighty prize. It's great to see how open software can leverage the power of the community to find weak spots and become stronger.

How much might a mighty prize be, if I may ask?

$100 000 http://vk.com/wall-52630202_7858

Эта история заставляет в очередной раз восхититься российскими программистами. Целую неделю маститые американские криптографы на HackerNews безуспешно цеплялись к протоколу — в основном, с требованием заменить наше решение на алгоритмы, которые продвигает АНБ в своем Suite B. А российский программист, называющий себя "новичком", смог в рамках статьи на Хабре с ходу определить потенциально уязвимое место в секретных чатах.

На всякий случай, поясню для массовых пользователей: утечки данных не было, уязвимость закрыта, опасности нет.

Еще раз убедился в том, насколько правильным решением было полностью открывать протокол и исходный код. Это позволяет привлекать тысячи умных людей, которые могут помогать нам постоянно совершенствовать систему, находя потенциально уязвимые места.

Разработчик, нашедший слабое место в нашем алгоритме, заслужил награду в $100,000. Подобную награду заслужит любой, кто найдет возможности схожей атаки (напоминаю, за расшифровку потока трафика мной была объявлена награда в $200,000). Продолжаем искать — вместе мы сделаем протокол нерушимым.

This story makes us once again admire the Russian programmers . Whole week at the venerable American cryptographers HackerNews unsuccessfully clung to the protocol - mainly with our decision to replace the requirement for algorithms that promotes its NSA Suite B. A Russian programmer who calls himself a "newcomer " could under Article Habré stride identify potential vulnerabilities in secret chats .

In any case , I will explain the bulk of users : data leakage was not a vulnerability is closed, there is no danger .

Once again convinced of how the right decision was fully open protocol, and source code. This allows you to attract thousands of smart people who can help us to constantly improve the system by finding potential vulnerabilities .

The developer, who found a weak spot in our algorithm , deserve a reward of $ 100,000 . Deserve such an award anyone who finds the possibility of similar attacks (remember, for decrypting traffic flow me was declared a reward of $ 200,000) . Continue to seek - together we will make a protocol indestructible .

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#145

Earlier quoted context omitted.

How much might a mighty prize be, if I may ask?

$100 000 http://vk.com/wall-52630202_7858 Эта история заставляет в очередной раз восхититься российскими программистами. Целую неделю маститые американские криптографы на HackerNews безуспешно цеплялись к протоколу — в основном, с требованием заменить наше решение на алгоритмы, которые продвигает АНБ в своем Suite B. А российский программист, называющий себя "новичком", смог в рамках статьи на Хабре с ходу определить…

That's a literal jawdropper. I'm stunned.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#146

I hope this person will get the full $200,000. I definitely don't think we can ever trust Telegram's strength again. They won't be paying him the full $200,000 even though he has rendered the Telegram to be weak. Major, major backfire for Telegram stakeholders.

They gave him $100 000. And yet the flaw he pointed out doesn't help you read encrypted messages and has been already fixed/

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#147
post #41

Here are some of their comments: ibeatle Большое спасибо, автор поста полностью прав. Со своей стороны хотим пояснить, что сделано это было из лучших побуждений: исправление плохого рандома на клиентах. С настоящего момента в nonce всегда будет приходить ноль, и в следующем слое мы обязательно удалим это поле из схемы и поясним в документации. Автор топика безусловно заслужил награды, просьба обратиться хабраюзера x7…

Second comment (W_K) is by Nick Durov, the leading author of MTProto, Telegram's protocol.

Ah this explains a lot. About the whole thing, not just the comment.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#148
post #103
post #79

Earlier quoted context omitted.

The reason for these comments is because you're exactly right– they are gambling . Putting $200k on the line in the hopes of winning mindshare, reputation, etc. Of course if you lose, you'll lose all of that and your money. I'm really happy that more people are getting into crypto and not browbeating themselves out of creating new stuff because it's necessary for any field to grow. These negative responses are also n…

I'm not sure they were gambling. My feeling is ghat they were victim of the bias of self judgment regarding the security of the protocol they designed. They overlooked some security weakness and didn't see it. They didn't do it on purpose like the NSA. In their eyes, the protocol was perfectly secure and most of it is of course. The only way to avoid this self judgment bias is to use review by other people.

Actually, this security hole is almost exactly what you'd expect well-done deliberate sabotage of the protocol to look like - it's a small, easy to miss and just about plausibly deniable modification of a standard crypto primitive that totally destroys its security. (Though it's a bit weak in the area of plausible deniablity - why use xor rather than some more sensible key derivation function?)

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#149
post #94
post #36

Earlier quoted context omitted.

Never forget. RIP Telegram (2013-2013). This whole thing has been interesting to follow because it seems this same thing happens every time someone make macho Crypto-claims. From seeing how confident the Telegram team was to reading all the detractors who were so ready to criticize. It's an interesting dynamic in the Crypto community.

Hate tone discussion makes me sad. Telegram is very young project and it has bugs for sure. Some guy found potential issue in protocol and developers committed to fix it soon. There is no information that any messages were revealed due to this bug but Telegram should go away and developers should do something else. Whatsapp is less secure then Telegram but I have not seed “Whatsapp RIP” messages. Not so hard to save…

Whatsapp doesn't say that it's the most secure messaging app in the world. Telegram did. And they were wrong.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#150
post #129
post #118

Earlier quoted context omitted.

> Whatsapp is less secure then Telegram Whatsapp never claimed to keep your chat secure. Telegram did. Many people offered gentle advice to Telegram, and they ignored it. Maybe it's a cultural thing? Not just domains-of-expertise (mathematicians going into crypto) but international?

Snapchat creators claim (at least imply) that messages could not be saved which is untrue. Most advices to telegram developers at previous HN discussion were to stop doing crypto and do something else. I would not consider them as “gentle advices”. The only help from the community to their application is the bug report x7mz user from habrahabr site.

Crypto is life and death. I have spent a lot of years learning it as a hobby... Its a dangerous field to play in. It's super complex, and all it takes is one tiny mistake anywhere in the program (be it at the protocol level or implementation) and then bam: game over. So, when you release something, you are nervous about it. Telegram wasn't, and as it turns out, they should have been. That is bad.
Post reply on HN