Live data from Hacker News

Telegram founder: US intelligence tried to bribe us to weaken encryption

news.fastcompany.com

151–160 of 220 posts

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#153
post #89

Earlier quoted context omitted.

and yeah, currently Internet is a spying tool of USA.

It's a spying tool for American corporations far more than it is one for the government.

It's a spying tool for American corporations which is very convenient for the government

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#154
post #98

Earlier quoted context omitted.

Which public key algorithm? In what mode of operation? What are you going to use to actually encrypt messages? You don't want to directly use the public key primitives to do this. In what mode of operation are you going to use that second, bulk encryption algorithm? How are you going to authenticate messages? What will you do to validate the public keys of your peers? When you close the application, will it forget ev…

> What happens if someone is briefly compromised? Could you give an example please? How do current protocols deal with that?

https://en.wikipedia.org/wiki/Forward_secrecy

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#155

Earlier quoted context omitted.

Pavel Durov wants everyone to think security is about trust in people. Most companies in that business do the same, because it's easier than building something that doesn't require trust in people. The way Pavel Durov and others like him present "trust" is (ironically) shady corporate structures[1], shell companies, or use of the word "Switzerland." They want people to think like that because they've built businesses…

I read the WP article you cited, titled, "The secret American origins of Telegram, the encrypted messaging app favored by the Islamic State". If Telegram isn't that secure, then why are extremists like IS using it over Signal or WhatsApp? I know Telegram has better features for big groups and much better multi-platform support, so is that the reason? I'm legitimately asking without any snark.

Telegram offers at least some degree of anonymity, you can join group chat without exposing your phone number. And even if telegram administration closes the group, they are unlikely to report all members to police.

WhatsApp and Signal offer non-anonymous groups only. They are probably used by people who already know each other.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#156
post #15

The ridiculousness of it all is it's unreasonable at its base to try to prevent encryption as a form of safety and security from violence. Sure, you can lock up all communication for privacy reasons, and the government can spend all kinds of resources on trying to control to prevent or circumvent encryption - however it's a waste of resources as it's simply a bandaid. If I wanted to do something violent or evil I/you…

> however a lot is because people's basic needs aren't being met which prevents the higher levels of Maslow's Hierarchy of Needs from being reached and maintained.

This is contradicted by a lot of evidence. Terrorists are most commonly middle class members of their society and often well educated. If anything, terrorism is a powerful means of satisfying the higher levels of 'needs', e.g. meaning, purpose, community.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#157

Earlier quoted context omitted.

when telegram has been proven insecure? in every topic about telegram people keep saying telegram is not secure. i failed to find info about how insecure their secure chats. maybe you can help me?

I think he's spreading a lie.. based on what I've seen, at least. It's a not yet proven secure protocol, is the worst you can say against it I believe. I'm not a security guy mind you, I'm just parroting what I keep seeing. Rightfully so, lack of deep audit is a very valid reason to worry. Yet, worry and untrusted is vastly different than actively exploitable / broken.

Encryption should probably be considered broken until demonstrated otherwise.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#158
post #84

Earlier quoted context omitted.

I think the question should be do we have proof that it is secure?

Moxie Marlinspike's reputation is dependent on his ability to deliver a secure product. Signal/Signal Protocol development is funded by donations and grants from groups like the Freedom of the Press Foundation, EFF, etc, and those groups desire a secure messaging product. Moxie has staked his reputation on WhatsApp's implementation of the Signal Protocol multiple times on the OWS blog, which he would not do if he dis…

And you call that a proof? :-)

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#159
post #86
post #48

Earlier quoted context omitted.

Of course not, but there should be more to it than merely seeing the word 'Russian'. I see this all the time now in left-leaning US papers (NYTimes, WaPo) that immediately imply association with something bad happening (he spoke with a Russian!). Much like the other popular generalization of 'Muslim' without qualification of type of Muslim where significant subsets have never been involved with terrorism (sufism vs w…

The stuff in the papers is not taking "Russian" to mean "bad." It's looking at serious allegations of collusion with the Russian government, known interference in the 2016 election by the Russian government, statements by various administration officials that they had no contact with the Russian government, and then using meetings with high-level officials in the Russian government to imply something bad happening. W…

> The stuff in the papers is not taking "Russian" to mean "bad." It's looking at serious allegations of collusion with the Russian government

That's a very generous assessment.

If only accusations of "speaking to a Russian" were qualified by the conversation actually involving something malicious or illegal before suggesting it was improper then I'd be in much more agreement.

The fact is besides Michael Flynn who was immediately fired once people with real power found out, there hasn't been anything that has come out that was bad on the administrations part. Even the accusations against Kushner seemed to be the handy work of Flynn who was at the only meeting he had with a Russian official.

Even the level of manipulation of the election results was seemingly marginal. If leaking Clinton/Podestas/DNC's emails was the limit of the interference (assuming they even leaked the Podesta emails to Wikileaks), despite most Americans on the left falsely believing it involved manipulating actual votes, then I really don't think it was as bad as people seem to think.

At most the worst that can be said is that Trump/RNC's emails weren't also leaked but everyone knows Trump doesn't use email so the damage would be limited to the RNC who Trump attacked on multiple occassions.

That would be a preferred scenario to Clinton/DNC emails never being leaked IMO.

So overall I don't see the total effect of Russian manipulation having a deciding factor. Especially considering the reason he won was in poorly educated industrial swing states where things like the latest Wikileaks Podesta email isn't as big news as a Trump ralley getting people excited over populist messaging.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#160
post #115

Earlier quoted context omitted.

Did the FBI give any reason/leverage as to why you should comply with their ask? If you are writing about it here, I'm assuming it wasn't an NSL (national security letter) and so would you be open to publishing a copy of it publicly? Would be great to get sunlight on that.

Probably in an old desk somewhere, it wasn't an NSL but I wish I would have held onto it, I would have captured it on my phone if smart phones were around then. It basically said if you are going to keep using PGP or custom encryption for the app that they would like to meet with us to discuss since we were connecting to government financial endpoints. Then it said if we use RSA that this would not be a needed discus…

To be fair, naively and given the use case you described, that sounds to me like in this particular instance they are trying to ensure that the encryption being used is "secure enough" for the govt. rather than "not too secure". It just so happens that the bureaucracy's definition of "secure enough" is a keyword whitelist that happens to have 'RSA' there and not 'PGP'.
Post reply on HN