Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

181–190 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#181
post #155

Earlier quoted context omitted.

I've not found any attempts to help them apart from this bug report. >TextSecure's interest is in security, whereas Telegram's interest seems to be in money and power I can't read minds or even their messenger logs so I can't comment what is their interest but I'd be interested to know why you think so > TextSecure completely safe app Just wrong. How could you call something "completely safe" or bug free? >Each of th…

Telegram seems to be interested in money and power because they've turned down offers from Moxie (the creator of TextSecure and a well-known cryptographer) to join forces. There's no reason to do that unless they were interested in money or power more than security. I didn't say TextSecure is completely safe. I said Telegram has been demonstrated to be broken. Telegram is prone to passive listening because their desi…

>Telegram seems to be interested in money and power because they've turned down offers from Moxie (the creator of TextSecure and a well-known cryptographer) to join forces.

Is there a cause-effect relationship I'm missing here?

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#182
post #178
post #62

Earlier quoted context omitted.

The problem is that if the authors had actually consulted crypto guys, none of this would have happened. Their lack of security shouldn't be excused.

Yeah you're right, the 'crypto guys' would've probably just said "Don't even try it because you'll kill people and even we wouldn't want to try and do it". Crypto is hard to get right, that doesn't mean anyone shouldn't even bother trying.

If you want to build new crypto, people would be absolutely happy for you to design and present a new cryptographic scheme - hopefully with some advantages over existing ones. People will analyze it, tell you where the weaknesses are, and if they're not critical flaws you can fix them and come out stronger - and if they are critical flaws, you know your scheme is broken before it's been used for anything important.

Likewise, building a hot new secure messaging app with existing well-analyzed, battle-tested cryptographic schemes is generally going to be welcomed.

If you try to do both at once, you're building your application on shaky, untested cryptographical foundations. Cryptographers would similarly probably warn you not to base your application on a new cipher someone else announced at a cryptography conference last week - give it a bit of time for others to analyze it and spot any flaws it might have before you entrust anything sensitive to it.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#183
post #115

Earlier quoted context omitted.

> To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. But it is not secure! That's the entire point. Never mind "not secure against a well funded government agency", it's not secure against other attackers. There are lots of usable chat apps that do not…

Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of…

> As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks.

Most users, disregarding the government for the moment, don't need encryption full stop. They don't send anything commercially sensitive that an attacker's going to be interested enough in to try to intercept their messages.

The use of encryption presupposes a motivated threat, and it's not clear to me that the NSA is significantly more powerful than other adversaries in that area. They've more computing power, more political power, they can buy zero day exploits. They probably even have some very smart people, who can find flaws faster than the attackers in civ-space. But speed isn't required, only persistence; motivation, interest. Which is, after all, what we're supposing in the first place if someone's going to go to the trouble of intercepting your messages.

It's not clear to me that unless your goal is 'make something that the NSA can't break into', you're going to make something that a well motivated attacker can't break into either. And this stuff only has to be broken once, then they'll just sell or share the attack. The conflict is asymmetrical.

Your argument seems to be posited on the idea that there will be no attacker; no-one anywhere, ever; sufficiently motivated to breach the protocol. And I find that highly questionable, given that a flaw has already been found - and with far lower levels of incentive than will be present if the system is widely deployed and used to protect valuable information.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#184
post #180

Earlier quoted context omitted.

Telegram seems to be interested in money and power because they've turned down offers from Moxie (the creator of TextSecure and a well-known cryptographer) to join forces. There's no reason to do that unless they were interested in money or power more than security. I didn't say TextSecure is completely safe. I said Telegram has been demonstrated to be broken. Telegram is prone to passive listening because their desi…

> I didn't say TextSecure is completely safe. Yes you do. "TextSecure completely safe app" was copied from your message before you or someone else edited it. I've not typed it but copied exact phrase from your message.

You copied it from your own message, not mine. http://i.imgur.com/pxMVDwA.png

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#185
post #167

Earlier quoted context omitted.

>Terms of bug bounty are very hard to satisfy even with bad protocol but Durov seems decided to play safe with such amount of money. Guy that found problem in MTproto doesn’t win money according to conditions of the bug bounty because message is not decrypted. The guy gets $100 000: https://vk.com/wall-52630202_7858 You may want to check before you post.

At first my statement is still valid even after Durov decided to pay for bug report. This bug report has no connection with extracting plain message I've written. Apart from that I can't check Durov's posts that from the future. My post was written before Durov's announcement.

Technically you're right. I thought that “decided” wasn't the right word to use before you give him a chance to decide. In other words, I read your post as conveying the idea that Pavel actively dismissed the bug report as unworthy of rewarding, when in fact the opposite was true. Perhaps I misread your post being a non-native English speaker. Apologies for that.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#186
post #155

Earlier quoted context omitted.

I've not found any attempts to help them apart from this bug report. >TextSecure's interest is in security, whereas Telegram's interest seems to be in money and power I can't read minds or even their messenger logs so I can't comment what is their interest but I'd be interested to know why you think so > TextSecure completely safe app Just wrong. How could you call something "completely safe" or bug free? >Each of th…

Telegram seems to be interested in money and power because they've turned down offers from Moxie (the creator of TextSecure and a well-known cryptographer) to join forces. There's no reason to do that unless they were interested in money or power more than security. I didn't say TextSecure is completely safe. I said Telegram has been demonstrated to be broken. Telegram is prone to passive listening because their desi…

[deleted]

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#187
post #103
post #79

Earlier quoted context omitted.

The reason for these comments is because you're exactly right– they are gambling . Putting $200k on the line in the hopes of winning mindshare, reputation, etc. Of course if you lose, you'll lose all of that and your money. I'm really happy that more people are getting into crypto and not browbeating themselves out of creating new stuff because it's necessary for any field to grow. These negative responses are also n…

I'm not sure they were gambling. My feeling is ghat they were victim of the bias of self judgment regarding the security of the protocol they designed. They overlooked some security weakness and didn't see it. They didn't do it on purpose like the NSA. In their eyes, the protocol was perfectly secure and most of it is of course. The only way to avoid this self judgment bias is to use review by other people.

Actually, I'm pretty sure they weren't gambling at all.

Pavel previously set up contests with monetary rewards about half the same value for developing a mobile VK app for iOS, Android and WP.

It's not a gamble—it is really an expensive way to find holes. What I don't understand is why they don't hire a crypto consultant instead.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#188

This is my first comment on the Telegram bruhaha. Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride. To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. I will not wish failure on anyone that is confident i…

They did give him a reward. Telegram has just posted the translation on twitter. Moved to separate discussion: https://news.ycombinator.com/item?id=6950129

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#189

This is my first comment on the Telegram bruhaha. Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride. To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. I will not wish failure on anyone that is confident i…

Really?

The protocol is bad, this competition protects only the most basic attacks and still was broken in about 5 days.

It's not "unnecessary pride". You have to be really cautios with cryptography. Not use the first thing that has "Secure!" sticker on it.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#190

This is my first comment on the Telegram bruhaha. Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride. To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January. I will not wish failure on anyone that is confident i…

The app was far from being a "secure" app. And going by how far they've to promote it as a "secure" app, of course there should be an equal amount of response for why it's not secure (since it isn't!). This is not just about some "guys making an app and being taken down for it". This is serious stuff. They're claiming their security is one of the best in the world, when it couldn't be farther from the truth. Why would you want such an app to be popular and make people think it's actually secure, when it's not?
Post reply on HN