Crowdsourcing a More Secure Future
11–20 of 95 posts
Re: Crowdsourcing a More Secure Future
#12On a side note, I am still not sure, if i will ever use this app. This is primarily because, I act on the internet in the same fashion as i do in real life. I won't do anything online, what I can't do in real life. Hence I don't and perhaps would never need an app like this.
As for sending someone 'secret' message, I always whisper that in the ears. It's an old fashioned trick but has proven to be most secured.
Re: Crowdsourcing a More Secure Future
#13Good for Telegram. I haven't downloaded and installed their App yet, but I applaud their effort at putting out a secure chat app that everyone can use. I've been using TextSecure for a while (as everyone on HN ruthlessly suggests) but guess how many encrypted texts I've sent? 0. That's because they have no iOS app and very few Android users. There are two problems when it comes to creating a good, secure messaging ap…
They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.
Re: Crowdsourcing a More Secure Future
#14This is actually really generous considering it didn't meet the terms of the contest. They have a long way to go before anyone here trusts them but perhaps we could be more positive and constructive?
You find DanBC's comment interesting. It explains why there's been a general tone of negativity towards Telegram's security product. https://news.ycombinator.com/item?id=6949842
Re: Crowdsourcing a More Secure Future
#15Re: Crowdsourcing a More Secure Future
#16These latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. I have one question that doesn't seem to be covered anywhere (FAQ, Google): What about Offline messages? I'd like to be able to send encrypted messages even when people are offline - on smartphones it could make use of push notifications, on the Desktop it would just wait until the cl…
Why is that? This latest revelation should give less faith in Telegram, not more.
Re: Crowdsourcing a More Secure Future
#17Re: Crowdsourcing a More Secure Future
#18Good for Telegram. I haven't downloaded and installed their App yet, but I applaud their effort at putting out a secure chat app that everyone can use. I've been using TextSecure for a while (as everyone on HN ruthlessly suggests) but guess how many encrypted texts I've sent? 0. That's because they have no iOS app and very few Android users. There are two problems when it comes to creating a good, secure messaging ap…
I applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.
What I applaud is their effort here and I hope it continues and moves in the right direction. This announcement makes it seem like they are in fact moving in the right direction.
Re: Crowdsourcing a More Secure Future
#19Earlier quoted context omitted.
Yes, they did. This was not the goal of the bounty, but was still a serious issue. They couldn't give away the prize for the contest and instead decided on a still quite generous $100,000. http://telegram.org/crypto_contest
This was not the goal of the bounty, but was still a serious issue. To be clear, this bug was enough to compromise the security of every Telegram secret chat session. I can't think of a more serious issue.
Re: Crowdsourcing a More Secure Future
#20Earlier quoted context omitted.
I applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.
I don't mean to sound snide, but judging from your comment history on Telegram related posts, are you really the right person to determine what "reasonable effort" means in this context? Every single post you make is biased negatively towards Telegram. What I applaud is their effort here and I hope it continues and moves in the right direction. This announcement makes it seem like they are in fact moving in the right…
Why? Because they're literally paying people to like their product? This developer who found the bug wasn't even trying to get any money. He was, by his own admission, a cryptography newbie who happened to be looking over their protocol and found a serious bug. Now they're throwing money at him. How is that in any way a good thing?