Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

181–190 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#181
post #100

Earlier quoted context omitted.

Where can we see this comment? Here at HN or the post itself? I could not see any comments with 'paveldurov'.

https://news.ycombinator.com/item?id=25726879

"[flagged]". I'm a HN noob, is there a way to see it? Or what did it say?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#182

Earlier quoted context omitted.

MitM means Man-in-the-Middle, unless otherwise specified. There's no ambiguity. You just copied that list from Wikipedia. PitM is much more confusing because only a few weirdos use that.

Are you sure? I'm not a cryptogrpher and I think neither are you while Filippo Valsorda is indeed a serious cryptographer. And yes, I copied that list from Wikipedia because people is genuinely trying to replace the word without altering the abbreviation.

> people is genuinely trying to replace the word without altering the abbreviation

What? It's changed from "MITM" to "PITM". The first letter of the abbreviation is altered.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#183

Earlier quoted context omitted.

You can also call it SITC (someone in the centre) attack if you will, but the point still stands - it impedes communication.

So long as you expand the acronym in the first use, no one reasonable cares.

> no one reasonable cares

I care. There's no need to make challenging technical texts more obtuse to read by reinventing all the terms.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#184

Earlier quoted context omitted.

> by the mere virtue of not being hosted in the USA I don't know where Telegram is hosted, but whenever I fire the desktop app there is always at least a google DNS request, sometimes some additional connections to google hosts. It certainly does seem to partially rely on the USA.

The point was about where is the data hosted. The answer is that it's distributed, so you would need court orders in an insane amount of countries to get any decrypted data from telegram

This is hilariously out of touch. If the telegram team is based out of UAE, then the UAE government can easily force them to hand over data even if it’s stored on foreign servers.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#185
post #83

Earlier quoted context omitted.

They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. This was a time when WhatsApp was found using a plaintext protocol, and right after the Snowden revelations. They did move the needle a bit at the right time. One of the most vocal critics was Moxie, who later founded Signal. It's ironic that 7 years after Snowden and Telegram, Signal the supposed more…

>They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. Off The Record showed up in 2004 and was used over multiple instant messaging systems. OpenPGP was used over various IM systems before that...

Well, if you go that far lol. I remember OTR on Pidgin and Adium back in the days. Not sure I'd consider these third party tacked on solutions e2ee messaging app that can e2e encrypt your chat. OpenPGP doesn't come with email and OTR doesn't come with GTalk.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#186

Earlier quoted context omitted.

Are you sure? I'm not a cryptogrpher and I think neither are you while Filippo Valsorda is indeed a serious cryptographer. And yes, I copied that list from Wikipedia because people is genuinely trying to replace the word without altering the abbreviation.

> people is genuinely trying to replace the word without altering the abbreviation What? It's changed from "MITM" to "PITM". The first letter of the abbreviation is altered.

"That" list refers to {man,monster,machine,monkey}. Any three alternatives equally work for me. But cryptographers may have other concerns.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#187
post #118

> Most backdoor looking bug While a backdoor is not a bug but a feature, it helps to disguise a backdoor as a bug (i.e. plausible deniability). I know of one instance (in MS Windows) where the backdoor feature was not even hidden so much: https://en.wikipedia.org/wiki/NSAKEY That's why we need opensource. It's a hedge against tyranny.

The NSAKEY backdoor claim should be trivial to prove with a debugger, until someone does so I think we can safely dismiss it as a lie. It’s been two decades, and nobody has been able to explain how it would’ve been used.

I beg to differ. This stuff is called reverse engineering and it's all but trivial.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#188
post #69

Earlier quoted context omitted.

If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…

I think Textsecure[1], the predecessor of Signal, is even older (2010) And Wikipeida also says that the first version of the Signal Protocol is from 2013[2] [1] https://en.wikipedia.org/wiki/TextSecure [2] https://en.wikipedia.org/wiki/Signal_Protocol

[deleted]

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#189

Earlier quoted context omitted.

I view it as marketing trade-offs. Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. But IMO somebody had to make the call for the right balance between ergonomy and security. I quite like Telegram as well but I am under no illusions that it's bulletproof in terms of protecting my chats. I still think it protects them better than WhatsApp though, b…

> Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. You missed the point, again. Not only does Telegram rely on your phone number to identify you, but unlike the competition it’ll happily send out your past conversation history to anyone who manages to take control of your phone number. Actual encrypted messengers can’t do this. >hosted in the USA…

Telegram has an option to add an additional password to your account precisely for that reason.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#190

Earlier quoted context omitted.

> Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. You missed the point, again. Not only does Telegram rely on your phone number to identify you, but unlike the competition it’ll happily send out your past conversation history to anyone who manages to take control of your phone number. Actual encrypted messengers can’t do this. >hosted in the USA…

Telegram has an option to add an additional password to your account precisely for that reason.

Why does Telegram make all important security features opt-in?
Post reply on HN