Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

131–140 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#131
post #4
post #3

Earlier quoted context omitted.

This is something i don't understand (at least for me/my use case): Are historic chats that important to have them backed up? To me, if there's anything of value, i'll save it via other means...

For me, chat history has a huge value. How many times things looks like meaningless when they are said but have a lot of values at a later date? For example, sometimes you wonder, "when was it that time when XXX event happened". Or "I remember that one day someone told me that he had the same problem as me, but who was it and what was his solution?" Otherwise, we are used to share thousands of links and snippets with…

>"when was it that time when XXX event happened"

Then you go and look that up in your issue tracker.

>"I remember that one day someone told me that he had the same problem as me, but who was it and what was his solution?"

Ideally, you've that saved to your Wiki/FAQ Database or at least have it in your ticketing system.

That is, if we're talking about a professional setting - or some random "might be useful later" notes.

But still, this isn't something i am going to dig up in a random chat log - because if you're able to find / search for it there, chances are you are pretty close to the solution anyways...

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#132

Earlier quoted context omitted.

Why are you so bothered by Telegram receiving some well deserved criticism? It’s weird. There are lots of posts on HN I don’t care about, but I don’t think I’ve ever had the urge to make comments like yours. > In any case, the constant hate is (a) very tiring and (b) very uncharacteristic for HN. There are people who trust their life and liberty on these apps, I don’t think the “hate” towards Telegram is inappropriat…

It's only weird if (a) I accept that the criticism is well-deserved, which I don't, and (b) because I want to read educated technical discussions. If I want to read half-baked snark then I can go to Reddit or 9GAG. Place like HN should be better than this. I see some people linking old articles and cryptography research, and some historic incidents. Good! That's arguing in good faith and I've read those with an inter…

You don’t seem to actually respond the criticism, instead you just dismiss it as “half-baked snark” or with “other apps do bad stuff too!”

You complain about the quality of discussion here, but do little to participate in a constructive manner.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#133

- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…

I like Telegram. In my (subjective) view it has the best UX of all messengers. It also has APIs which should give a big plus on here and at least till now they are not doing censorship to my knowledge. What might be problematic is that its reception is generally to be the "rebellish" alternative to WhatsApp etc. and people tend to think that it is more secure and has a better encryption. Another pro Telegram point wo…

I view it as marketing trade-offs. Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. But IMO somebody had to make the call for the right balance between ergonomy and security.

I quite like Telegram as well but I am under no illusions that it's bulletproof in terms of protecting my chats. I still think it protects them better than WhatsApp though, by the mere virtue of not being hosted in the USA where you can be ordered to give away an unencrypted dump of your database and keep silent about it until your grave.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#134

Earlier quoted context omitted.

I like Telegram. In my (subjective) view it has the best UX of all messengers. It also has APIs which should give a big plus on here and at least till now they are not doing censorship to my knowledge. What might be problematic is that its reception is generally to be the "rebellish" alternative to WhatsApp etc. and people tend to think that it is more secure and has a better encryption. Another pro Telegram point wo…

I view it as marketing trade-offs. Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. But IMO somebody had to make the call for the right balance between ergonomy and security. I quite like Telegram as well but I am under no illusions that it's bulletproof in terms of protecting my chats. I still think it protects them better than WhatsApp though, b…

> Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example.

You missed the point, again. Not only does Telegram rely on your phone number to identify you, but unlike the competition it’ll happily send out your past conversation history to anyone who manages to take control of your phone number.

Actual encrypted messengers can’t do this.

>hosted in the USA

You think the UAE is better? I live here, it’s not. If the US government wants access to telegram conversation logs, the UAE government will happily retrieve them.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#135

Earlier quoted context omitted.

It's only weird if (a) I accept that the criticism is well-deserved, which I don't, and (b) because I want to read educated technical discussions. If I want to read half-baked snark then I can go to Reddit or 9GAG. Place like HN should be better than this. I see some people linking old articles and cryptography research, and some historic incidents. Good! That's arguing in good faith and I've read those with an inter…

You don’t seem to actually respond the criticism, instead you just dismiss it as “half-baked snark” or with “other apps do bad stuff too!” You complain about the quality of discussion here, but do little to participate in a constructive manner.

Yeah, I definitely got worked up so I partially contributed to the problem. Can't deny the facts.

I already responded to those criticisms elsewhere but here goes: I never expected any messenger to do end-to-end encryption. I am quite aware how un-ergonomic such a messenger would be so I know that Telegram does little more than TLS protection of the network socket. And that's fine with me and with millions of others.

But I still don't get why Telegram is the constant target of HN. Why not WhatsApp? Viber? Or literally every other messenger? I challenge you to find such brutal and full of flagged comments threads not pertaining to Telegram. As said above, we both live in our own bubble but all WhatsApp threads I've seen lately only aim at the user's data privacy and almost nobody ever mentions that their "encryption" is also a glorified TLS and their claims for end-to-end encryption are very likely dubious and a pure PR stunt.

Admittedly some of the responses earlier -- which were very unconstructive -- got to me.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#136

> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.

When people have enough time to recreate dictionaries it is immediately apparent that person is far more privledged than they want to believe.

They have the free time to gather people, harass others online, and not do any of the work they're trying to redefine. A lot of it used to just be tumblr kids with wealthy parents trying to talk about privledge, but here we are again.

Its also a movement that becomes quite discriminatory. The removal of slave/master is discriminatory to BDSM.

Almost all of it is of course based on a lack of understanding to the english language. People glance over context and circumstances now, and will boldly claim "context doesn't matter". Which is entirely demonstrably false. But again - these people don't care about what's true, they have too much time on their hands and words are easier to do something about than to delve into something effective like their cities council and politics.

Nobody ever meant mitm to only mean a man, the declaration of independence did not only mean men. 'man' is used contextually as essentially a definition for homo sapien.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#137

Earlier quoted context omitted.

I view it as marketing trade-offs. Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. But IMO somebody had to make the call for the right balance between ergonomy and security. I quite like Telegram as well but I am under no illusions that it's bulletproof in terms of protecting my chats. I still think it protects them better than WhatsApp though, b…

> Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. You missed the point, again. Not only does Telegram rely on your phone number to identify you, but unlike the competition it’ll happily send out your past conversation history to anyone who manages to take control of your phone number. Actual encrypted messengers can’t do this. >hosted in the USA…

> Not only does Telegram rely on your phone number to identify you, but unlike the competition it’ll happily send out your past conversation history to anyone who manages to take control of your phone number.

Many, myself included, are aware of this. I prefer it because if I get a newer iPhone tomorrow I still want all of my conversations and all history to be there. I question how many people can to a SIM takeover. No, it's not "everyone". Very few will actually do it and it seems it was a marketing tradeoff. Quite a normal practice and Telegram is not an outlier in this case.

> You think the UAE is better? I live here, it’s not. If the US government wants access to telegram conversation logs, the UAE government will happily retrieve them.

Sigh. Suspected, but never knew for sure. Thanks for letting me know. Now "all" that remains is for somebody to both incorporate end-to-end encrypted chats and allow synchronization of history between devices without a central server, in a single app, I suppose. But Telegram isn't that app and I am aware and okay with it.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#138

Earlier quoted context omitted.

It's not. (I'm the author.)

As said in another comment of mine, putting a generic "hey I might be wrong" at the end is pure fluff. Stick to what you believe in, you are not in front of a court. Case in point: the Hanlon's Razor mention definitely did mislead me in terms of your stance.

My position is that this looks like a backdoor but there is no way to know for sure, and I stand by it. If you find it too nuanced that's ok.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#139
post #83

Earlier quoted context omitted.

They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. This was a time when WhatsApp was found using a plaintext protocol, and right after the Snowden revelations. They did move the needle a bit at the right time. One of the most vocal critics was Moxie, who later founded Signal. It's ironic that 7 years after Snowden and Telegram, Signal the supposed more…

TextSecure (essentially the old name for Signal) is 3 years older (2010 vs. 2013), isn't it?

The timeline seems to suggest e2e had always been at the heart of the protocol, but I'm not sure if TextSecure and RedPhone were actually apps that people could install after Whisper Systems was acquired by Twitter. Regardless, instant messaging hadn't seem to be introduced until 2014. Tough call.

https://en.wikipedia.org/wiki/TextSecure#/media/File:Signal_...

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#140
post #83
post #69

Earlier quoted context omitted.

If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…

They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. This was a time when WhatsApp was found using a plaintext protocol, and right after the Snowden revelations. They did move the needle a bit at the right time. One of the most vocal critics was Moxie, who later founded Signal. It's ironic that 7 years after Snowden and Telegram, Signal the supposed more…

>They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat.

Off The Record showed up in 2004 and was used over multiple instant messaging systems. OpenPGP was used over various IM systems before that...

Post reply on HN