Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

171–180 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#171

Earlier quoted context omitted.

My position is that this looks like a backdoor but there is no way to know for sure, and I stand by it. If you find it too nuanced that's ok.

I found it ambiguous, nothing more. And I expressed an opinion to which half I subscribe to. Maybe that's valuable feedback for you as a writer, maybe it's not. In any case, no hard feelings were intended anywhere.

The situation is (slightly) ambiguous. It looks like a backdoor. Anyone competent writing that code would be doing so because they wanted the backdoor. But there's no reason to assume Telegram's authors are competent unnecessarily, and competence in UI design doesn't imply competence in security. And it's also a rather obvious-looking backdoor, anyone competent would presumably try to hide it better. Then again, the NSA backdoor in Dual-EC-DRBG was pointed out before anyone started using the spec and not that well hidden, and the NSA are generally considered competent.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#172

Earlier quoted context omitted.

I like Telegram. In my (subjective) view it has the best UX of all messengers. It also has APIs which should give a big plus on here and at least till now they are not doing censorship to my knowledge. What might be problematic is that its reception is generally to be the "rebellish" alternative to WhatsApp etc. and people tend to think that it is more secure and has a better encryption. Another pro Telegram point wo…

I view it as marketing trade-offs. Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. But IMO somebody had to make the call for the right balance between ergonomy and security. I quite like Telegram as well but I am under no illusions that it's bulletproof in terms of protecting my chats. I still think it protects them better than WhatsApp though, b…

> by the mere virtue of not being hosted in the USA

I don't know where Telegram is hosted, but whenever I fire the desktop app there is always at least a google DNS request, sometimes some additional connections to google hosts. It certainly does seem to partially rely on the USA.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#173

Earlier quoted context omitted.

So long as you expand the acronym in the first use, no one reasonable cares.

I care. Always preferred well established acronyms that everyone is familiar with.

From this day forward, I will refer to this sort of attack as a PiTM attack. Not much you can do to stop me I'm afraid.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#174

Earlier quoted context omitted.

You can also call it SITC (someone in the centre) attack if you will, but the point still stands - it impedes communication.

So long as you expand the acronym in the first use, no one reasonable cares.

The same reasoning applies to "single letter variable names are fine".

Humans aren't computers. They have a finite number of concepts they can keep in their head. Using existing conventions leads to better understanding as it allow folks to get through a discussion without having to backtrack as often.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#175

Earlier quoted context omitted.

I view it as marketing trade-offs. Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. But IMO somebody had to make the call for the right balance between ergonomy and security. I quite like Telegram as well but I am under no illusions that it's bulletproof in terms of protecting my chats. I still think it protects them better than WhatsApp though, b…

> by the mere virtue of not being hosted in the USA I don't know where Telegram is hosted, but whenever I fire the desktop app there is always at least a google DNS request, sometimes some additional connections to google hosts. It certainly does seem to partially rely on the USA.

Fair point, thank you.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#176

Earlier quoted context omitted.

I found it ambiguous, nothing more. And I expressed an opinion to which half I subscribe to. Maybe that's valuable feedback for you as a writer, maybe it's not. In any case, no hard feelings were intended anywhere.

The situation is (slightly) ambiguous. It looks like a backdoor. Anyone competent writing that code would be doing so because they wanted the backdoor. But there's no reason to assume Telegram's authors are competent unnecessarily, and competence in UI design doesn't imply competence in security. And it's also a rather obvious-looking backdoor, anyone competent would presumably try to hide it better. Then again, the…

Oh, I am not firmly claiming that it's not a backdoor. It very well might be!

But that's what mostly what I was saying (granted, I got worked up at one point because the blind stereotyping puts a black mark on HN's reputation in my eyes) is that indeed the situation is ambiguous and both possibilities are [mostly] equally likely.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#177
post #165
post #164

Earlier quoted context omitted.

Considering the founder of Telegram more or less had his previous startup VK (Russian competitor to Facebook) stolen by Putin after his refusal to hand over info about Ukrainian protestors [1], and has left the country with no interest in returning, I'd be inclined to trust that Telegram is not a front for the Russian state, quite the contrary in fact. [1] https://en.wikipedia.org/wiki/Pavel_Durov#Dismissal_from_VK

Telegram was developed in the VK offices for a long time after VK was supposedly "stolen" from Durov. >left the country with no interest in returning Well, except for when he does https://tjournal.ru/tech/52954-durov-back-in-ussr http://uip.me/2016/04/dark-side-of-the-telegram/ https://lenta.ru/news/2017/03/20/durov/ https://medium.com/@anton.rozenberg/friendship-betrayal-clai... https://theoutline.com/post/2348/what…

Thanks for the background info!

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#178
post #83
post #69

Earlier quoted context omitted.

If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…

They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. This was a time when WhatsApp was found using a plaintext protocol, and right after the Snowden revelations. They did move the needle a bit at the right time. One of the most vocal critics was Moxie, who later founded Signal. It's ironic that 7 years after Snowden and Telegram, Signal the supposed more…

[deleted]

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#179
post #83

Earlier quoted context omitted.

They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. This was a time when WhatsApp was found using a plaintext protocol, and right after the Snowden revelations. They did move the needle a bit at the right time. One of the most vocal critics was Moxie, who later founded Signal. It's ironic that 7 years after Snowden and Telegram, Signal the supposed more…

>They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. Off The Record showed up in 2004 and was used over multiple instant messaging systems. OpenPGP was used over various IM systems before that...

SCIMP also predates Telegram by several months https://web.archive.org/web/20150402122917/https://silentcir...

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#180

Earlier quoted context omitted.

I view it as marketing trade-offs. Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. But IMO somebody had to make the call for the right balance between ergonomy and security. I quite like Telegram as well but I am under no illusions that it's bulletproof in terms of protecting my chats. I still think it protects them better than WhatsApp though, b…

> by the mere virtue of not being hosted in the USA I don't know where Telegram is hosted, but whenever I fire the desktop app there is always at least a google DNS request, sometimes some additional connections to google hosts. It certainly does seem to partially rely on the USA.

The point was about where is the data hosted.

The answer is that it's distributed, so you would need court orders in an insane amount of countries to get any decrypted data from telegram

Post reply on HN