Earlier quoted context omitted.
Where can we see this comment? Here at HN or the post itself? I could not see any comments with 'paveldurov'.
https://news.ycombinator.com/item?id=25726879
The Most Backdoor-Looking Bug I’ve Ever Seen
181–190 of 222 posts
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#182Earlier quoted context omitted.
MitM means Man-in-the-Middle, unless otherwise specified. There's no ambiguity. You just copied that list from Wikipedia. PitM is much more confusing because only a few weirdos use that.
Are you sure? I'm not a cryptogrpher and I think neither are you while Filippo Valsorda is indeed a serious cryptographer. And yes, I copied that list from Wikipedia because people is genuinely trying to replace the word without altering the abbreviation.
What? It's changed from "MITM" to "PITM". The first letter of the abbreviation is altered.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#183Earlier quoted context omitted.
You can also call it SITC (someone in the centre) attack if you will, but the point still stands - it impedes communication.
So long as you expand the acronym in the first use, no one reasonable cares.
I care. There's no need to make challenging technical texts more obtuse to read by reinventing all the terms.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#184Earlier quoted context omitted.
> by the mere virtue of not being hosted in the USA I don't know where Telegram is hosted, but whenever I fire the desktop app there is always at least a google DNS request, sometimes some additional connections to google hosts. It certainly does seem to partially rely on the USA.
The point was about where is the data hosted. The answer is that it's distributed, so you would need court orders in an insane amount of countries to get any decrypted data from telegram
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#185Earlier quoted context omitted.
They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. This was a time when WhatsApp was found using a plaintext protocol, and right after the Snowden revelations. They did move the needle a bit at the right time. One of the most vocal critics was Moxie, who later founded Signal. It's ironic that 7 years after Snowden and Telegram, Signal the supposed more…
>They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. Off The Record showed up in 2004 and was used over multiple instant messaging systems. OpenPGP was used over various IM systems before that...
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#186Earlier quoted context omitted.
Are you sure? I'm not a cryptogrpher and I think neither are you while Filippo Valsorda is indeed a serious cryptographer. And yes, I copied that list from Wikipedia because people is genuinely trying to replace the word without altering the abbreviation.
> people is genuinely trying to replace the word without altering the abbreviation What? It's changed from "MITM" to "PITM". The first letter of the abbreviation is altered.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#187> Most backdoor looking bug While a backdoor is not a bug but a feature, it helps to disguise a backdoor as a bug (i.e. plausible deniability). I know of one instance (in MS Windows) where the backdoor feature was not even hidden so much: https://en.wikipedia.org/wiki/NSAKEY That's why we need opensource. It's a hedge against tyranny.
The NSAKEY backdoor claim should be trivial to prove with a debugger, until someone does so I think we can safely dismiss it as a lie. It’s been two decades, and nobody has been able to explain how it would’ve been used.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#188Earlier quoted context omitted.
If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…
I think Textsecure[1], the predecessor of Signal, is even older (2010) And Wikipeida also says that the first version of the Signal Protocol is from 2013[2] [1] https://en.wikipedia.org/wiki/TextSecure [2] https://en.wikipedia.org/wiki/Signal_Protocol
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#189Earlier quoted context omitted.
I view it as marketing trade-offs. Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. But IMO somebody had to make the call for the right balance between ergonomy and security. I quite like Telegram as well but I am under no illusions that it's bulletproof in terms of protecting my chats. I still think it protects them better than WhatsApp though, b…
> Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. You missed the point, again. Not only does Telegram rely on your phone number to identify you, but unlike the competition it’ll happily send out your past conversation history to anyone who manages to take control of your phone number. Actual encrypted messengers can’t do this. >hosted in the USA…
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#190Earlier quoted context omitted.
> Deep in a sub-thread another poster pointed out that they rely on SIM identification which can be spoofed, for example. You missed the point, again. Not only does Telegram rely on your phone number to identify you, but unlike the competition it’ll happily send out your past conversation history to anyone who manages to take control of your phone number. Actual encrypted messengers can’t do this. >hosted in the USA…
Telegram has an option to add an additional password to your account precisely for that reason.