Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

121–130 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#121
post #69

Earlier quoted context omitted.

If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…

I think Textsecure[1], the predecessor of Signal, is even older (2010) And Wikipeida also says that the first version of the Signal Protocol is from 2013[2] [1] https://en.wikipedia.org/wiki/TextSecure [2] https://en.wikipedia.org/wiki/Signal_Protocol

[deleted]

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#122
post #86
post #71

Earlier quoted context omitted.

> Telegram does not encrypt most conversations, you cannot compare it to Signal. I wish people will stop repeating this nonsense. Just because they don't do end to end encryption by default, doesn't mean they don't encrypt, which implies messages are sent in plaintext. There are plenty of reasons why they did what they did, and these questions are all available publicly in their FAQ or the founder's Telegram channel.…

Do you really consider an "encrypted conversation" if you just do TLS to a central server that has everything in plaintext? Is Facebook Messaging encrypted messaging? Because that's the kind of thing we already had before this wave of apps and Telegram is marketed within this new wave but doesn't have any more security than what the previous wave already had, even if you trust their homegrown protocol.

Edit, first things first:

> Is Facebook Messaging encrypted messaging?

Facebook messaging is not "encrypted messaging" AFAIK.

But if you say it sends the messages unencrypted like people claim Telegram does I will probably point out that you are wrong even if I don't like Facebook at all.

end Edit.

--------

Tell me then: If you call point-to-point-encrypted "unencrypted", what do you call the old WhatsApp protocol from before Moxie helped them, which actually sent messages unencrypted? [1]

What do you call the files that Whatsapp store on my phone (messages.db or something) that I can transfer to my computer and open without any tooling besides a zip tool and SQLite?

Unencrypted -- ?

Even more unencrypted?

There is a reason why we keep repeating our plea to differ between unencrypted, point-to-point-encrypted and end-to-end-encrypted and it is not because we adore all of Telegrams decisions, at least not for all of us.

It is because precision often matters in engineering and I think especially for security work.

[1]: Irony over irony, I used to love them back then. I knew fixing the crypto part would be doable and they were such a nice company with such a nice business model which aligned so nicely with our interests as users.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#123
post #118

> Most backdoor looking bug While a backdoor is not a bug but a feature, it helps to disguise a backdoor as a bug (i.e. plausible deniability). I know of one instance (in MS Windows) where the backdoor feature was not even hidden so much: https://en.wikipedia.org/wiki/NSAKEY That's why we need opensource. It's a hedge against tyranny.

The NSAKEY backdoor claim should be trivial to prove with a debugger, until someone does so I think we can safely dismiss it as a lie.

It’s been two decades, and nobody has been able to explain how it would’ve been used.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#124

- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…

I like Telegram. In my (subjective) view it has the best UX of all messengers. It also has APIs which should give a big plus on here and at least till now they are not doing censorship to my knowledge. What might be problematic is that its reception is generally to be the "rebellish" alternative to WhatsApp etc. and people tend to think that it is more secure and has a better encryption. Another pro Telegram point would be that they at least don't have an as big incentive as FB to capitalise on their users data.

What saddens me is that Signal seems to be the go to alternative. Which is obviously more secure but still centralised and has a terrible UX (e.g. drains the battery of my laptop very fast when I tried it the last time). Why not directly go for Matrix / Element.io for a secure and decentralised (like eMail) approach? Do you really want to upload your contacts?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#125
post #80

If the dead comment by user ‘paveldurov’ is the actual Pavel Durov, then I just found extremely solid reasons never to go near Telegram. Yikes.

Their account is 7 years old. They used to post substantive things about Telegram. Looks like him.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#126
post #86

Earlier quoted context omitted.

Do you really consider an "encrypted conversation" if you just do TLS to a central server that has everything in plaintext? Is Facebook Messaging encrypted messaging? Because that's the kind of thing we already had before this wave of apps and Telegram is marketed within this new wave but doesn't have any more security than what the previous wave already had, even if you trust their homegrown protocol.

Edit, first things first: > Is Facebook Messaging encrypted messaging? Facebook messaging is not "encrypted messaging" AFAIK. But if you say it sends the messages unencrypted like people claim Telegram does I will probably point out that you are wrong even if I don't like Facebook at all. end Edit. -------- Tell me then: If you call point-to-point-encrypted "unencrypted", what do you call the old WhatsApp protocol fr…

> Unencrypted

Yes?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#127

Earlier quoted context omitted.

Well, sue them. I don't think all other messengers save for maybe Matrix and Signal are any better. Even better, make a messenger that does encrypt chats. Make it paid. Prove its end-to-end encryption properties. I'll buy it and advocate for it to my friends and family. In any case, the constant hate is (a) very tiring and (b) very uncharacteristic for HN.

Why are you so bothered by Telegram receiving some well deserved criticism? It’s weird. There are lots of posts on HN I don’t care about, but I don’t think I’ve ever had the urge to make comments like yours. > In any case, the constant hate is (a) very tiring and (b) very uncharacteristic for HN. There are people who trust their life and liberty on these apps, I don’t think the “hate” towards Telegram is inappropriat…

It's only weird if (a) I accept that the criticism is well-deserved, which I don't, and (b) because I want to read educated technical discussions. If I want to read half-baked snark then I can go to Reddit or 9GAG. Place like HN should be better than this.

I see some people linking old articles and cryptography research, and some historic incidents. Good! That's arguing in good faith and I've read those with an interest, and upvoted them. "I don't trust Durov", which many of the HN comments about Telegram boil down to, is just noise. I don't want noise in threads where I want to find objective information. I am doing my part to improve HN by downvoting / flagging comments I see as noise or non-constructive attacks.

> Usually I see comments criticizing it get downvoted. Funny, no?

Filter bubbles then, I suppose. Seems we are both in our own and apparently neither of us is right in their generalization. ¯\_(ツ)_/¯ I can live with that.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#128

Earlier quoted context omitted.

I don’t think your paraphrase is an accurate representation of the article.

It's not. (I'm the author.)

As said in another comment of mine, putting a generic "hey I might be wrong" at the end is pure fluff. Stick to what you believe in, you are not in front of a court.

Case in point: the Hanlon's Razor mention definitely did mislead me in terms of your stance.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#129

> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.

There is another reason that might be valuable for cryptographers though: MitM might mean either {man,monster,machine,monkey}-in-the-middle (interception and manipulation unbeknownst to both parties) or meet-in-the-middle (space-time tradeoff for nested encyption schemes). AFAIK there is no other well-known suitable term for the latter, unlike the former.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#130
post #43

Earlier quoted context omitted.

That's not saying anything of substance unless you offer your own interpretation. "You're wrong" is not a discussion, it's a kick in the gut. > The lady doth protest too much, methinks. Solid criticism with well laid-out arguments from you, no doubt. > Besides, look at Pavel Durovs flagkilled reply here. Since when do upvote / downvote count mean anything at all about somebody's opinion or statements? (I haven't read…

>I haven't read the comment though Maybe do that. Not being snarky, you’re missing important context.

I did read it now. It's not constructive, that's a fact, but have you never got worked up by unrelenting criticism?

Still, he's an official public face and should know better. That I fully agree with.

Post reply on HN