Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

101–110 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#101
post #65

And obligatory reference to Backdoored Streebog cipher : https://eprint.iacr.org/2016/071 https://www.sstic.org/media/SSTIC2019/SSTIC-actes/RussianSty... The backdoor was hidden in the plain sight: the s-box was said to be randomly picked, but years long evasive answers of authors about cryptographic properties of the box made people to think that there was something really not right with it. If not for that specific…

I find it such a shame that such amazing mathematical research was pumped into ultimately producing such a backward-minded result.

At the very least I suppose we will be able to glean more knowledge out of it in the end.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#102
post #97
post #92

Earlier quoted context omitted.

Good. (At the risk of stating the obvious: Changing commonly established things is how progress works.)

The downside is the cost to communication. I didn't know what a PitM was. After a bit I guessed it was Person, i.e. man in the middle, but I wasn't sure that it didn't mean something else. I'm not sure how big the gain is here. Are people really going to read "man in the middle" and assume that no woman could ever do this?

Also: where are the people who were offended by "man-in-the-middle"? Can you point to a single non-man who was offended that the evil-doer in this example was identified as a man? Or can you point to a single man who was offended for the same reason?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#103
post #69

Earlier quoted context omitted.

If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…

I think Textsecure[1], the predecessor of Signal, is even older (2010) And Wikipeida also says that the first version of the Signal Protocol is from 2013[2] [1] https://en.wikipedia.org/wiki/TextSecure [2] https://en.wikipedia.org/wiki/Signal_Protocol

So Telegram launched by about a month early, but the people behind Signal had released prior art earlier, and merely the protocol a few months later, but the Signal app didn't come out until 2015 according to Wikipedia.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#104

Earlier quoted context omitted.

WhatsApp backups are a bit of an anti-feature, as I found out while trying to ditch the app after the recent policy update. 1) The backup can only be made to Google drive, you cannot create a manual backup to a location of your chosing 2) The backup is created in a secret folder that cannot be accessed by the user 3) The backup is deleted if you delete your account. (not much of a backup, eh?) 4) You can only create…

Interesting. I just created a 900MB backup of a chat history, on my iOS WhatsApp, that appears to have all messages and all data.

Being an iOS device it probably doesn’t ‘backup’ to Google Drive so this story may not apply

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#105
post #37

Earlier quoted context omitted.

I think you’re completely missing the nuance in the words surrounding the authors mention of “Hanlon’s razor”. Besides, look at Pavel Durovs flagkilled reply here. The lady doth protest too much, methinks.

I certainly hope that’s not the real Pavel Durov…

Their account is 7 years old. They used to post substantive things about Telegram. Looks like him.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#106
post #95
post #86

Earlier quoted context omitted.

Do you really consider an "encrypted conversation" if you just do TLS to a central server that has everything in plaintext? Is Facebook Messaging encrypted messaging? Because that's the kind of thing we already had before this wave of apps and Telegram is marketed within this new wave but doesn't have any more security than what the previous wave already had, even if you trust their homegrown protocol.

Sending plaintext in a secure transport is not what they do either. They do have e2e encrypted secret chat on day one, and the ends are bound to the devices, so even if you login from your desktop app, you won't see the secret chats on your phone, unlike Signal. Seriously, please educate yourself first.

Yes, they have opt-in e2e secret chats.

Oh, except the Windows and Linux clients don’t even support those.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#107
- Clickbait title: Check.

- Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check.

- Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much).

- Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check.

- HN going crazy negative when Telegram is mentioned, as it always happens: Check.

---

I am not shilling for Telegram. I have no reason to. I can switch to Signal with my most important contacts in the space of one hour if I wanted to. I never invested any money in them either. I won't get sad if they get nuked from orbit tomorrow.

But it's really baffling how non-constructive most Telegram HN coverage is, both articles and comments. Sure, they have no bulletproof end-to-end encryption of messages. So, like 99.9% of all apps on all app stores then? Some generic marketing on the homepage using vaguely non-accurate language ("secure chats")? So, again, like 99.9% of the apps that have a page and put marketing lingo on them?

What's so uniquely awful about Telegram?

It's legitimately intriguing how hostile HN gets at the mention of Telegram. There might be some interesting sociological study hidden there somewhere.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#108
post #100
post #80

If the dead comment by user ‘paveldurov’ is the actual Pavel Durov, then I just found extremely solid reasons never to go near Telegram. Yikes.

Where can we see this comment? Here at HN or the post itself? I could not see any comments with 'paveldurov'.

Set ‘showdead’ in your profile to yes and scroll down the comments to the end.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#109
post #100
post #80

If the dead comment by user ‘paveldurov’ is the actual Pavel Durov, then I just found extremely solid reasons never to go near Telegram. Yikes.

Where can we see this comment? Here at HN or the post itself? I could not see any comments with 'paveldurov'.

https://news.ycombinator.com/item?id=25726879

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#110

- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…

> What's so uniquely awful about Telegram?

Telegram puts its users in danger by lying to them. They claim to be a secure, encrypted messenger but do not actually encrypt chats.

Then there’s the backdoor...

>I am not shilling for Telegram

:)

Post reply on HN