Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

141–150 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#141
post #80

If the dead comment by user ‘paveldurov’ is the actual Pavel Durov, then I just found extremely solid reasons never to go near Telegram. Yikes.

I'm not seeing it here in this post at least.

It’s a dead comment; you need to enable ‘showdead’.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#142

Earlier quoted context omitted.

You don’t seem to actually respond the criticism, instead you just dismiss it as “half-baked snark” or with “other apps do bad stuff too!” You complain about the quality of discussion here, but do little to participate in a constructive manner.

Yeah, I definitely got worked up so I partially contributed to the problem. Can't deny the facts. I already responded to those criticisms elsewhere but here goes: I never expected any messenger to do end-to-end encryption. I am quite aware how un-ergonomic such a messenger would be so I know that Telegram does little more than TLS protection of the network socket. And that's fine with me and with millions of others.…

> I am quite aware how un-ergonomic such a messenger would be so I know that Telegram does little more than TLS protection of the network socket. And that's fine with me and with millions of others.

The amount of people who understand this certainly isn’t in the millions. The fact is that most Telegram users have no idea that their conversations aren’t encrypted, most people incorrectly assume that it’s more secure than whatsapp.

> WhatsApp threads I've seen lately only aim at the user's data privacy and almost nobody ever mentions that their "encryption" is also a glorified TLS and their claims for end-to-end encryption are very likely dubious and a pure PR stunt.

This is complete nonsense. Whatsapp uses the Signal Protocol. Their claims of end-to-end encryption are true (and easily verifiable! just pull out the debugger of your choice)

> Admittedly some of the responses earlier -- which were very unconstructive -- got to me.

I think your (perfectly understandable) misinterpretation was corrected in a rather polite manner, but you still wanted to argue after being corrected by multiple native english speakers.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#143

Earlier quoted context omitted.

As said in another comment of mine, putting a generic "hey I might be wrong" at the end is pure fluff. Stick to what you believe in, you are not in front of a court. Case in point: the Hanlon's Razor mention definitely did mislead me in terms of your stance.

My position is that this looks like a backdoor but there is no way to know for sure, and I stand by it. If you find it too nuanced that's ok.

I found it ambiguous, nothing more. And I expressed an opinion to which half I subscribe to. Maybe that's valuable feedback for you as a writer, maybe it's not.

In any case, no hard feelings were intended anywhere.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#145
post #97
post #92

Earlier quoted context omitted.

Good. (At the risk of stating the obvious: Changing commonly established things is how progress works.)

The downside is the cost to communication. I didn't know what a PitM was. After a bit I guessed it was Person, i.e. man in the middle, but I wasn't sure that it didn't mean something else. I'm not sure how big the gain is here. Are people really going to read "man in the middle" and assume that no woman could ever do this?

Well, now you know. And I bet the first time you read 'MitM' you didn't know what it was either.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#146

Earlier quoted context omitted.

Yeah, I definitely got worked up so I partially contributed to the problem. Can't deny the facts. I already responded to those criticisms elsewhere but here goes: I never expected any messenger to do end-to-end encryption. I am quite aware how un-ergonomic such a messenger would be so I know that Telegram does little more than TLS protection of the network socket. And that's fine with me and with millions of others.…

> I am quite aware how un-ergonomic such a messenger would be so I know that Telegram does little more than TLS protection of the network socket. And that's fine with me and with millions of others. The amount of people who understand this certainly isn’t in the millions. The fact is that most Telegram users have no idea that their conversations aren’t encrypted, most people incorrectly assume that it’s more secure t…

> This is complete nonsense. Whatsapp uses the Signal Protocol. Their claims of end-to-end encryption are true (and easily verifiable! just pull out the debugger of your choice)

I don't dispute this but apparently there's still a way for Facebook to give FBI et. al. un-encrypted chats, no? So is that truly encrypted?

> I think your (perfectly understandable) misinterpretation was corrected in a rather polite manner, but you still wanted to argue after being corrected by multiple native english speakers.

Yes and no. Being a native speaker doesn't excuse ambiguity and idiomatic expressions. I believe people who write in English on the internet have a duty to avoid idioms as much as possible. I am not a native speaker and easily misrepresented the meaning.

But, even the author corrected me so, okay.

As for polite... let's agree to disagree there. You are questioning my opinion that I get snarky replies but IMO it's clearly visible that no small amount of replies weren't made in good faith and were only aimed to express hurtful sarcasm.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#147

> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.

Eh, you don't get to control the language of others. If someone wants to say PitM, that's their business.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#148
post #95
post #86

Earlier quoted context omitted.

Do you really consider an "encrypted conversation" if you just do TLS to a central server that has everything in plaintext? Is Facebook Messaging encrypted messaging? Because that's the kind of thing we already had before this wave of apps and Telegram is marketed within this new wave but doesn't have any more security than what the previous wave already had, even if you trust their homegrown protocol.

Sending plaintext in a secure transport is not what they do either. They do have e2e encrypted secret chat on day one, and the ends are bound to the devices, so even if you login from your desktop app, you won't see the secret chats on your phone, unlike Signal. Seriously, please educate yourself first.

> They do have e2e encrypted secret chat on day one

I was specifically replying to your complaint that non-E2E encrypted chats should not be called unencrypted because they had encryption in transit to the server. You're now shifting the conversation back to the E2E encryption they do have.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#149

Earlier quoted context omitted.

TextSecure (essentially the old name for Signal) is 3 years older (2010 vs. 2013), isn't it?

The timeline seems to suggest e2e had always been at the heart of the protocol, but I'm not sure if TextSecure and RedPhone were actually apps that people could install after Whisper Systems was acquired by Twitter. Regardless, instant messaging hadn't seem to be introduced until 2014. Tough call. https://en.wikipedia.org/wiki/TextSecure#/media/File:Signal_...

TextSecure was available from Google Play for years, I've used it since release. The transformation to Signal was pretty seamless.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#150

- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…

> - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check.

That it might not apply is already in the title. backdoor-looking already explicitly expresses that.

> - HN going crazy negative when Telegram is mentioned, as it always happens: Check.

glass houses...

And nobody here is claiming that Telegram is "uniquely awful", it's just that Telegram is more notable than 99.9% of other apps, in a field (messengers) where both privacy is generally more looked at and alternatives that are widely considered better in that regard exist, all the while Telegram is widely advertised/recommended as "secure" despite being worse in that regard. On the other hand, this criticism isn't new and widely known. That's why it's called out a lot, and tbh both (paraphrased) other unrelated apps have problems too and (unsourced) people surely understand that it's just advertising and Telegrams limitations are really bad defenses.

EDIT: and I suspect Telegram is especially annoying because it's otherwise really good, so if it also solved the security question it'd be a no-brainer recommendation.

Post reply on HN