Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

211–220 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#211

This is my first comment on the Telegram bruhaha. Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride. To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. I will not wish failure on anyone that is confident i…

As for the TextSecure/WhisperSystems guys, stop being like the politicians we hate who campaign by slinging mud on opponents instead of selling their stuff.

It's funny that you mention politicians at the end of the post, because as I was reading your posts in this thread, I couldn't help but think you were feeding into the huge cable-newsification of this disagreement. It is what happens when a bunch of lookie-loo viewers want to be involved in the debate but can't keep up on the issues. I struggle to completely follow the tech here but my job occasionally brings me close enough to crypto that if nothing else I understand the huge disparity between the technical discussion and the superficial one at play here.

Attempts to fit this disagreement into the same oblique, non-existent, ideal behavior for a disagreement subverts the ability to productivity disagree and makes behavior worse overall. Your remedy is for them to not disagree. I take it differently. I want them to disagree, but I don't want anyone involved in the disagreement to dishonestly play to the masses. But that would involve conceding a point, and what would that do to the bottom line?

Focus on selling the TextSecure app and not looking to takeout anyone who has a different approach.

You mistakenly seem to think that TextSecure exists primarily for profit. It is obvious the aim is good crypto. They're playing a different ball game than Telegraph's freemium model, one where marketplace success doesn't determine if they implemented their crypto right. Promoting _that_ involves explaining why the Telegraph tech is deficient.

Back to the cable news analogy, in a post of yours further down the thread, you bring up what the right level of security is for this app. That's a good question, one moxie (I think) brought up days ago by pointing out they didn't have threat model and tptacek (I think) called them out for using nation-state actors as the adversary in selling the app. They played that card in technical criticism, you bringing it up here for goalpost shifting now that they're starting to look bad and you want to keep driving down the middle of the disagreement.

PS: I have no relationship with either party. I am a neutral observer that has his own opinions.

Oh, I know. You're playing into the US-politics detached observer rote well. You should know that the system adapted to account for that stance years ago. You're getting played as hard as everyone else.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#212
post #203

Earlier quoted context omitted.

> As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks. Most users, disregarding the government for the moment, don't need encryption full stop. They don't send anything commercially sensitive that an attacker's going to be interested enough in to try to intercept their messages. The use of encryption presupposes a motivated threat, and it's not clear to me t…

> Most users, disregarding the government for the moment, don't need encryption full stop. You've no idea what you're talking about. Please stop spreading such bullshit around; other people might fall for it! Fireship is an app that allows you to hijack the account of any user on the same Wi-Fi network as you are, if the network is not encrypted, and the user used a non-encrypted connection to the website. Facebook,…

We were having a discussion about Telegram and similar uses of encryption, a discussion where I specifically responded to a remark on the strength required of Telegram-style encryption. I would hope that most people are capable of interpreting the context of a remark - especially embedded in paragraphs that expand on it. Rather than, 'fall[ing] for it!'

-sigh-

Beyond that I'm not going to engage with you any further, on this or any other point. You strike me as a bully, restrained where you are simply by the absence of an excuse rather than the presence of decency. As such, I've no interest in associating with you.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#214

Earlier quoted context omitted.

RIP Telegram (2013-2013) would make an interesting T-shirt. No one except a few cryptography buffs might understand it, but it would be a funny way to start conversations about information security.

Would indeed be interesting to get to know some other cryptography-interetsted people on the bus, metro and other public places, so here you go: http://teespring.com/riptelegram

Haha. I love it!

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#215
post #155

Earlier quoted context omitted.

Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition? I've written about this pretty extensively: https://www.hnsearch.com/search#request/all&q=by%3Asillysaur... It's an interesting contrast in cultures that you phrase it like "Why do you think Telegram lies more than TextSecure advocates?" .... As far as I'm aware, TextSecure advocates have…

I've not found any attempts to help them apart from this bug report. >TextSecure's interest is in security, whereas Telegram's interest seems to be in money and power I can't read minds or even their messenger logs so I can't comment what is their interest but I'd be interested to know why you think so > TextSecure completely safe app Just wrong. How could you call something "completely safe" or bug free? >Each of th…

You seem to be missing the larger point. Nobody is proposing that secure messaging apps should not exist. Everyone is better when more people try, iterate and fail (then recover and fix) to create secure messaging solutions.

What's unsafe and unproductive is when bozos jump in the pool, apparently ignorant or otherwise misrepresentative of the reality of how difficult it is to create a correct solution -- and confidently declare their implementations to be trustable.

If the messaging on Telegram had been, the world needs a secure messaging solution and we're committed to building it starting with this thing which we think is pretty good for XYZ, nobody would be objecting. Instead, these guys presented themselves as having solved a problem which is known to be difficult, and moreover using an unlikely method.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#216

Earlier quoted context omitted.

Well chances are that the OP I responded to (I can't even see his name well enough to repeat it he's so faded now) will have his account ghosted if he keeps this up. One too many mega-downvote-comments by a new user and you end up being ghosted. Where you still think you're posting to HN, and you are, but nobody else can read it. All I was saying is perhaps if pg et all decreased whatever threshold they have set for…

It is not automatic, as far as I know. It requires human intervention for someone to be hellbanned, or "ghosted". It isn't very systematic, and I've seen people hellbanned who probably didn't deserve it (and it usually does get fixed when that happens).

Perhaps it would make sense to automatically hellban possibly problematic posters and then hand review those hellbans later. Worst case scenario is a good posters posts aren't seen for a short period of time.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#217
post #203

Earlier quoted context omitted.

> Most users, disregarding the government for the moment, don't need encryption full stop. You've no idea what you're talking about. Please stop spreading such bullshit around; other people might fall for it! Fireship is an app that allows you to hijack the account of any user on the same Wi-Fi network as you are, if the network is not encrypted, and the user used a non-encrypted connection to the website. Facebook,…

We were having a discussion about Telegram and similar uses of encryption, a discussion where I specifically responded to a remark on the strength required of Telegram-style encryption. I would hope that most people are capable of interpreting the context of a remark - especially embedded in paragraphs that expand on it. Rather than, 'fall[ing] for it!' -sigh- Beyond that I'm not going to engage with you any further,…

Yeah, I probably overreacted.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#218
There is another "tab" for MITM (at least in android client and in the documentation there are no clues of it) :

Even in the corrected version of Diffie-Hellman (with nonce removed) the server can slip customers a number which is zero modulo p as g_a or g_b (since the documentation says about the 2048- bit sequence -- it can be either 0 or p itself). Then both clients will see the same identicon ("visualization key", 'cause it will be a presentation of SHA1 applied to zero).

However, judging by further manipulation with the "shared secret" key (because MTProto doesn't use Diffie-Hellman method of multiplying by g^ab^-1 or any multiplication by the shared key whatsoever) the multiplication by zero will not happen with client messages and they will successfully flow through the "bare" AES ( and therefore users will think that everything is fine and will proceed to transmitting sensitive data in this mode ).

P. S.: Correct me if I missed something . This might be a corner case, but, nevertheless, it formally differs from the one with server xor salt not much (at least , need fixes in the client and the doc too). Or am I making ​​a mistake somewhere? P. S.: Original version of this my comment in russian: http://habrahabr.ru/post/206900/#comment_7128970

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#219
Noone should trust a service that advertises itself as being safe from governments ears. Pure and simple.

First, there's a risk the NSA is actually the one initiating those services.

Secondly, in cryptography, it's very hard if not impossible to effectively prove your messages are not read by someone else. Cryptography experts do not tend to work for people's interests. And if some do, the NSA has too many resources to just defeat those who try to not be listened to.

I understand the intention is noble, but if you release such a safe tool, the NSA will view it as a terrorist threat, because that's the job they have been given, and they will end up listening anyways.

I can't understand the paranoia about all this. If you're really afraid the NSA might use information against you, it's because you made political enemies, in this case, why use digital means of communication at all ?

I really tend to think it's being cool to use those cryptographic features, rather than anything else, and that's worrying.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#220
post #54
post #48

Earlier quoted context omitted.

I don't get it. If it's not secure why can't the message be revealed? What's the value of breaking someone's crypto if you are still unable to see the data unencrypted? Was the recipe for decryption given, with the actual decryption being much harder (terms so narrow, as you say)?

genwin, I’ve invented a secure system. If you can tell me what this message says, you win $200k: jo You don’t know what the message says, because it’s so short. You will never win the prize. But my system was not so secure. My cipher system was this: Take a message and type it on a US Qwerty keyboard, but shift every letter over one place. So `hi` became `jo`. Not very strong. It would easily be cracked with a messag…

I think I get it now, thanks. So if Telegraph provided a much longer conversation to decrypt, the contest could be fair.
Post reply on HN