Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

201–210 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#201
post #115

Earlier quoted context omitted.

> To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. But it is not secure! That's the entire point. Never mind "not secure against a well funded government agency", it's not secure against other attackers. There are lots of usable chat apps that do not…

Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of…

It would have been much more useful for a neutral party to do a comparative analysis and stated the pros and cons of each side.

Like, say, tptacek, who is not in the "instant messenger" business, who is in the security audit business, and whose comments here on the technical details of the Telegram protocol have been absolutely damning? See https://news.ycombinator.com/item?id=6941934 for example.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#202
post #59
post #41

Here are some of their comments: ibeatle Большое спасибо, автор поста полностью прав. Со своей стороны хотим пояснить, что сделано это было из лучших побуждений: исправление плохого рандома на клиентах. С настоящего момента в nonce всегда будет приходить ноль, и в следующем слое мы обязательно удалим это поле из схемы и поясним в документации. Автор топика безусловно заслужил награды, просьба обратиться хабраюзера x7…

A small correction: use "irrelevant" instead of "unfounded" to translate "не по существу". "unfounded" is closer to "не обосновано". It is a English-speaking forum, put English text first.

I agree, "irrelevant" would be a better choice.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#203

Earlier quoted context omitted.

Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of…

> As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks. Most users, disregarding the government for the moment, don't need encryption full stop. They don't send anything commercially sensitive that an attacker's going to be interested enough in to try to intercept their messages. The use of encryption presupposes a motivated threat, and it's not clear to me t…

> Most users, disregarding the government for the moment, don't need encryption full stop.

You've no idea what you're talking about. Please stop spreading such bullshit around; other people might fall for it!

Fireship is an app that allows you to hijack the account of any user on the same Wi-Fi network as you are, if the network is not encrypted, and the user used a non-encrypted connection to the website. Facebook, Google, Twitter and Flicker were all susceptible to such attacks before the advent of this tool; afterwards, they fixed it by using https by default.

Do you want random strangers to have full access to your Facebook account? No? Then you should realize that most people do need encryption full stop.

Also, only very powerful attackers can hack https encryption (they need either access to your laptop (hardware access, or a zero-day exploit), or access to the website (e.g. court warrant, or coercing a certificate authority)).

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#204
post #51

Earlier quoted context omitted.

To be fair, no one here mentioned anything related to the found vulnerability. Instead people seemed to have focused on their choice of SHA1 and IGE.

To be fair, no one actually discovered the bridge was made of rotting wood. They seemed focused on the fact that math PhDs design it with no civil engineering background and stated plastic had no known defects.

No. They saw that the bridge was made of such a material, that it would collapse if the material turns out to be anything but steel-reinforced concrete. Which it was pretty likely to be, because it was designed by people who have been, up until now, building igloos.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#205

This is my first comment on the Telegram bruhaha. Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride. To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. I will not wish failure on anyone that is confident i…

This trend of ignoring the content because of the tone is pervasive and troubling. I understand that tone matters in regards to reception, but in this place i assume we all, grammar nazis and privilege checkers alike, choose to asses the technical aspects of comments and largely disregard the "gift wrap". In this situation, the problem with Telegram is their words right big checks their work cannot cash. The TextSecure chaps are defending their turf viciously, but i have yet to see one of them make a personal assessment as the predicate for their assault. I have been following it very closely, comment wise, and all it has really been is long winded explanations (on the TextSecure side) of why the Telegram contest was a sham (it was) and why TextSecure is better (i have no way to judge). On the other side (Telegram), all i see are pleas to leave the Telegram guys alone, hate toward Moxie et al., and general pseudo-martyr comments about how mean Hacker News is.

Good. Let's be hard to please. This is not [spoiler]fucking[/spoiler] macaroni paintings we are making and using to please mommy. These are the apps we all use to continue our work and edify our lives. I want it to be a gauntlet; i think it is great that people's products are critiqued so meticulously, and i am happy that a competition with such glaring inconsistencies (to whomever wrote the alternate competition explanation...thank you)did not survive for long. As an American, i am so tired of security theater. If something is touted as secure and is not, i want to know about it.

And as for the ridicule, if you obfuscate and misrepresent, you invite a harsh response.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#206
post #36

Earlier quoted context omitted.

Never forget. RIP Telegram (2013-2013). This whole thing has been interesting to follow because it seems this same thing happens every time someone make macho Crypto-claims. From seeing how confident the Telegram team was to reading all the detractors who were so ready to criticize. It's an interesting dynamic in the Crypto community.

By that logic, Linux, Chrome, Android are RIP at least a hundred times.

While I'm not saying that Telegram "is RIP" (whatever it means in this thread), Linux, Chrome and Android don't have crypto as their main killer feature.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#207

This is my first comment on the Telegram bruhaha. Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride. To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. I will not wish failure on anyone that is confident i…

[deleted]

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#208

Earlier quoted context omitted.

I see you've only been here for 33 days so I'll lend you a hand. This is HN, and we don't make posts like that.

Counterexamples: 1) Every Bitcoin thread 2) Every NSA/Snowden thread Source (cough): I've been around for 6.3 years, am in the top 40 users in terms of net karma, and am actually very frustrated with the unfortunate turn the community has taken in the past 12-18 months. And am considering leaving, which makes me sad.

I think it's going to become more necessary to moderate through downvotes. I've almost never downvoted anybody on HN ever, especially not in comparison to reddit where downvoting is extremely rampant, but I think, sadly, the times might be changing.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#209

Excruciating evidence that supports Moxie's position. Vuln rewards should exist for two purposes: 1)An act of good faith on the part of the developer that says "I am interested in securing my product and I won't prosecute direct disclosure" 2) The Dev knows exploitable vuln discovery has value, but cannot compete with black market pricing. Instead, the reward is a token of appreciation for a shared code of ethics. I…

I have no idea what you are trying to say here. The guy is rewarded half the bounty: https://vk.com/wall-52630202_7858

Vuln reward programs that payout at this level are broken.

1) They don't achieve their objective of securing a product. Moxie eloquently captured why here: http://thoughtcrime.org/blog/telegram-crypto-challenge/

2) At this level of payout, they are inefficient and unsustainable. There were less expensive ways to discover implementation flaws, and certainly more direct ways to discover design flaws. Was the lesson they just learned really worth $100 grand from some random dude on the Internet? Seems to me you could find more problems per dollar by directly engaging with some of the top class security consultancies out there.

So to summarize, telegram's reward was an extremely inefficient stunt that did not achieve it's likely real objective. I imagine the team is licking it's wounds right now and regretting their approach. We'll be able to tell by whether or not they continue their offer under the same rules and same budget.

I expect this to continue for another couple of rounds because random security people on the Internet will be smelling blood right now.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#210

Earlier quoted context omitted.

Moxie's blog post does a better job explaining the problems than I can [1]. Basically, the framework of the contest precludes many avenues of attack to which a given cryptosystem could be vulnerable. The researcher who discovered the vulnerability in the OP used a man-in-the-middle attack, which cannot be used in the Telegram contest.

[1] http://thoughtcrime.org/blog/telegram-crypto-challenge/

Thanks, I totally forgot!
Post reply on HN