Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

191–200 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#191
post #4

Earlier quoted context omitted.

For me, chat history has a huge value. How many times things looks like meaningless when they are said but have a lot of values at a later date? For example, sometimes you wonder, "when was it that time when XXX event happened". Or "I remember that one day someone told me that he had the same problem as me, but who was it and what was his solution?" Otherwise, we are used to share thousands of links and snippets with…

>"when was it that time when XXX event happened" Then you go and look that up in your issue tracker. >"I remember that one day someone told me that he had the same problem as me, but who was it and what was his solution?" Ideally, you've that saved to your Wiki/FAQ Database or at least have it in your ticketing system. That is, if we're talking about a professional setting - or some random "might be useful later" not…

You are thinking of a professional dev context. But it is not the same thing for everyday discussions with friends.

A lot of things can look not useful and common at the current time, but have a lot of values in the future. But you can't document every step of your life.

For example, imagine that some friend tell you that his brother is currently working in Singapore and that everything goes well for him and all. But so far you have no relation to Singapore and don't travel so much.

Then 1 year later, you will unexpectedly be sent to Singapore for work and you would highly appreciate a contact there. At that point you remember that the brother of someone is there, but who was it?

You just have to search for 'singapore' in Telegram and you can get easily the reply to your question and so recontact the relevant friend.

Same thing when you are suddenly thinking about buying a Xiaomi phone, and you are wondering who was the friend that told you that he bought one 6 months ago to get his review.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#192
post #169

Earlier quoted context omitted.

If it was indeed a backdoor, sure, but that's a judgment call, not something anyone knows. As others have noted, e2e was a novelty at the time, not a norm, and the platform itself was extremely new (less than a year old), and their stated reason for this was to protect against weak client RNG, which in retrospect sounds like a weak reason, but looking back at the news of 2013, this was right around the time the Snowd…

>If it was indeed a backdoor, sure, but that's a judgment call, not something anyone knows. As others have noted, e2e was a novelty at the time, not a norm, and the platform itself was extremely new (less than a year old), and their stated reason for this was to protect against weak client RNG, which in retrospect sounds like a weak reason, but looking back at the news of 2013, this was right around the time the Snow…

So maybe they just made the same mistake I did?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#193
post #187

Earlier quoted context omitted.

The NSAKEY backdoor claim should be trivial to prove with a debugger, until someone does so I think we can safely dismiss it as a lie. It’s been two decades, and nobody has been able to explain how it would’ve been used.

I beg to differ. This stuff is called reverse engineering and it's all but trivial.

The debugging symbols and most of the source is out there, this really isn’t a particularly difficult task.

If you can’t do this, then you certainly aren’t qualified to claim that such a backdoor exists.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#195

> Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. I don't think people give credit for just how deep this actually does cut. On one project I worked on, which stored obscenely sensitive information, their product manager gave a speech about password security and told us he had a better algorithm than bcrypt. You couldn't explain why this was a bad id…

Yup, when you get bosses dictating algorithms such bugs are likely.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#196
post #3

The most backdoor-looking feature for me in supposedly encrypted systems are cloud backups. They are “optional” yet most users will agree (especially when given software constantly nags about it until you give up) and their backups will leak both sides of conversations, despite all end-to-end encryption attempts.

This is something i don't understand (at least for me/my use case): Are historic chats that important to have them backed up? To me, if there's anything of value, i'll save it via other means...

Yes. Backups without easy access are mostly worthless. If I make backups, I have to think about how they're stored, where they're stored, how they're preserved, how I access them, and how I query them.

Do I have a backup per contact? Per app? Are they stored in my Google Drive? In flat files on my local PC? What happens if my PC's hard drive crashes? How do I automatically keep the backups up to date? How do I keep them in sync? How do I access and query them remotely if I'm not at my PC?

Now multiply that across every different service you use, and that's a lot of mental effort that I don't want to go through if I don't have to. Most users don't want to either.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#198
post #150

- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…

> - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. That it might not apply is already in the title. backdoor-looking already explicitly expresses that. > - HN going crazy negative when Telegram is mentioned, as it always happens: Check. glass houses... And nobody here is claiming that Telegram is "uniquely awful", it's just that Telegram is mor…

> EDIT: and I suspect Telegram is especially annoying because it's otherwise really good, so if it also solved the security question it'd be a no-brainer recommendation.

That would be quite hilarious and paradoxical: to attract so much negative reactions because the app is very good but it doesn't do everything as the tech-savvy crowd expects (in terms of cryptography). But I can see it being the true sentiment. Interesting perspective, thank you for it.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#199

Earlier quoted context omitted.

Telegram has an option to add an additional password to your account precisely for that reason.

Why does Telegram make all important security features opt-in?

Ergonomics. The HN crowd is really quick to forget that many users have no patience to setup several passwords and/or keys after installing an app.

You and I discussed quite a bit already and we can't agree on many things -- but I can still see where Telegram's team is coming from in their security decisions. A balance between ergonomics and security has to be struck if you want wide adoption.

We likely both abhor how quick and easy it is for many users to just say "yeah, sure, get access to my contacts so I don't have to re-add my people one by one" -- I feel that this practice is responsible for trillions of personal data points sitting out there in warehouses waiting to be used for advertising profiling, but what can we do? Seems that this is what the people want.

Having stricter -- and thus non-ergonomic in terms of UX -- security as an opt-in is apparently the best we can do in this age. By "we" I mean "all programmers and corporations".

Before you say it: I used Matrix and Riot/Elements for several months. The app itself is hopelessly behind in basically everything: it's not responsive even on a very modern Linux laptop, it often hides messages (and shows them up again a few minutes later after the app somehow force-refreshes its UI by itself), synchronization of chats when logging in from a new device was almost non-existent and took minutes to recover a channel with like 30 messages (although I heard they are working on this)... Even notifications would fire 9 out of 10 times and I had to make it a habit to check the client every 10-15 minutes or so (since it was a work chat).

Very far from convenient. Not to mention part of the time non-functional.

Telegram makes security trade-offs, I have no doubts about it. But it's a damn good app in almost all regards -- and me and many others can forgive their lack of to-the-letter end-to-end encryption implementation.

If there's an app with such a good UX and polish like Telegram that also does end-to-end encryption and doesn't drown you in GPG-like keys and passwords management minutiae, I'll gladly switch tomorrow.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#200

Earlier quoted context omitted.

Me too, but after Snowden I doubt we'd be able to even if it were true.

I don’t get it, this claim should be fairly easy to prove by reverse engineering the app.

Then why has nobody done it? F.ex. Google's Project Zero?
Post reply on HN