Earlier quoted context omitted.
Eh, you don't get to control the language of others. If someone wants to say PitM, that's their business.
You can also call it SITC (someone in the centre) attack if you will, but the point still stands - it impedes communication.
The Most Backdoor-Looking Bug I’ve Ever Seen
161–170 of 222 posts
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#162> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.
There is another reason that might be valuable for cryptographers though: MitM might mean either {man,monster,machine,monkey}-in-the-middle (interception and manipulation unbeknownst to both parties) or meet-in-the-middle (space-time tradeoff for nested encyption schemes). AFAIK there is no other well-known suitable term for the latter, unlike the former.
PitM is much more confusing because only a few weirdos use that.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#163> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.
Good. (At the risk of stating the obvious: Changing commonly established things is how progress works.)
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#164It's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger. This blog post is far too charitable.
> It's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger. It's still likely better than WeChat FB Messenger in terms of privacy. You just get to choose the devil, and some consider Russia no worse than Facebook (and all that it represents) or China.
[1] https://en.wikipedia.org/wiki/Pavel_Durov#Dismissal_from_VK
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#165Earlier quoted context omitted.
> It's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger. It's still likely better than WeChat FB Messenger in terms of privacy. You just get to choose the devil, and some consider Russia no worse than Facebook (and all that it represents) or China.
Considering the founder of Telegram more or less had his previous startup VK (Russian competitor to Facebook) stolen by Putin after his refusal to hand over info about Ukrainian protestors [1], and has left the country with no interest in returning, I'd be inclined to trust that Telegram is not a front for the Russian state, quite the contrary in fact. [1] https://en.wikipedia.org/wiki/Pavel_Durov#Dismissal_from_VK
>left the country with no interest in returning
Well, except for when he does
https://tjournal.ru/tech/52954-durov-back-in-ussr
http://uip.me/2016/04/dark-side-of-the-telegram/
https://lenta.ru/news/2017/03/20/durov/
https://medium.com/@anton.rozenberg/friendship-betrayal-clai...
https://theoutline.com/post/2348/what-isn-t-telegram-saying-...
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#166Earlier quoted context omitted.
You can also call it SITC (someone in the centre) attack if you will, but the point still stands - it impedes communication.
So long as you expand the acronym in the first use, no one reasonable cares.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#167- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…
A back door means losing trust forever. It doesn't matter if it was 7 years ago.
Further, the fact that this was caught so quickly is in some sense a vindication of Telegram's model - even in its infancy when it had orders of magnitude fewer users, the fact that the client was open source allowed someone to quickly spot a vulnerability.
The verdict? IMO Telegram secret chats are probably secure (90% certain), but if I were plotting a murder or something, I wouldn't do it over a smartphone app anyway. There's just too many leaky, complex layers in the stack, some of which aren't even open, and quite dubiously so. If security is a life-or-death situation for you, you'd be a fool to use any smartphone app.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#168Earlier quoted context omitted.
There is another reason that might be valuable for cryptographers though: MitM might mean either {man,monster,machine,monkey}-in-the-middle (interception and manipulation unbeknownst to both parties) or meet-in-the-middle (space-time tradeoff for nested encyption schemes). AFAIK there is no other well-known suitable term for the latter, unlike the former.
MitM means Man-in-the-Middle, unless otherwise specified. There's no ambiguity. You just copied that list from Wikipedia. PitM is much more confusing because only a few weirdos use that.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#169Earlier quoted context omitted.
A back door means losing trust forever. It doesn't matter if it was 7 years ago.
If it was indeed a backdoor, sure, but that's a judgment call, not something anyone knows. As others have noted, e2e was a novelty at the time, not a norm, and the platform itself was extremely new (less than a year old), and their stated reason for this was to protect against weak client RNG, which in retrospect sounds like a weak reason, but looking back at the news of 2013, this was right around the time the Snowd…
Everything you said here was addressed by the OP. The connection to telegram servers is already encrypted, the only adversary this server-side RNG could possibly defend against is one that has access to the server.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#170The most backdoor-looking feature for me in supposedly encrypted systems are cloud backups. They are “optional” yet most users will agree (especially when given software constantly nags about it until you give up) and their backups will leak both sides of conversations, despite all end-to-end encryption attempts.
This is something i don't understand (at least for me/my use case): Are historic chats that important to have them backed up? To me, if there's anything of value, i'll save it via other means...