Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

21–30 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#21
post #10

It's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger. This blog post is far too charitable.

well, any messaging service, you're only on it for the people. Certainly the only reason I use Telegram is a few favourite chat groups.

The problem with Telegram's crypto is that Nikolai Durov is super-smart - he has two Ph.Ds in mathematics - but he thinks he's smarter than everyone else in the world put together, so Telegram roll their own crypto all the time, and keep being a worked example of why "don't roll your own crypto" is a saying.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#22
post #10

It's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger. This blog post is far too charitable.

And it's amazing to me that any Telegram coverage on HN is met with extremely hostile reactions. All they did was not invent the best encryption in the world... like you, me, and 99.9% of the world. Mortal sin, right?

So please stick to facts and what can be reasonably proven, please. The rest is meaningless noise and mindless hate.

The author himself admits it's much more likely this was an amateurish mistake than some man-in-the-middle conspiracy. Did you make it until the end of the article?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#23

The most backdoor-looking feature for me in supposedly encrypted systems are cloud backups. They are “optional” yet most users will agree (especially when given software constantly nags about it until you give up) and their backups will leak both sides of conversations, despite all end-to-end encryption attempts.

WhatsApps cloud backup on Android sits on Google drive by default. It is encrypted with a per user key known to WhatsApp. That means for a third party to access the chats, they need Google to hand over the data, and Facebook to hand over the key. The logical next step to add would be for Google to additionally encrypt the data with the users logon password or something derived from it. Google won't do this anytime so…

I've posted this here before.

> It is encrypted with a per user key known to WhatsApp.

This is no longer true! For a few years now. The backup is stored on Google Drive in plain text.

https://faq.whatsapp.com/android/chats/about-google-drive-ba...

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#24
post #10

It's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger. This blog post is far too charitable.

And it's amazing to me that any Telegram coverage on HN is met with extremely hostile reactions. All they did was not invent the best encryption in the world... like you, me, and 99.9% of the world. Mortal sin, right? So please stick to facts and what can be reasonably proven, please. The rest is meaningless noise and mindless hate. The author himself admits it's much more likely this was an amateurish mistake than s…

I don’t think your paraphrase is an accurate representation of the article.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#25
post #10

It's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger. This blog post is far too charitable.

And it's amazing to me that any Telegram coverage on HN is met with extremely hostile reactions. All they did was not invent the best encryption in the world... like you, me, and 99.9% of the world. Mortal sin, right? So please stick to facts and what can be reasonably proven, please. The rest is meaningless noise and mindless hate. The author himself admits it's much more likely this was an amateurish mistake than s…

>All they did was not invent the best encryption in the world.

They shipped a backdoor. It's pretty clear that Telegram is actively malicious. They haven't been caught again? They probably realized that the front door of not encrypting chats was sufficient.

>The author himself admits it's much more likely this was an amateurish mistake than some man-in-the-middle conspiracy

This is not at all what the author is saying.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#26

Earlier quoted context omitted.

WhatsApps cloud backup on Android sits on Google drive by default. It is encrypted with a per user key known to WhatsApp. That means for a third party to access the chats, they need Google to hand over the data, and Facebook to hand over the key. The logical next step to add would be for Google to additionally encrypt the data with the users logon password or something derived from it. Google won't do this anytime so…

WhatsApp backups are a bit of an anti-feature, as I found out while trying to ditch the app after the recent policy update. 1) The backup can only be made to Google drive, you cannot create a manual backup to a location of your chosing 2) The backup is created in a secret folder that cannot be accessed by the user 3) The backup is deleted if you delete your account. (not much of a backup, eh?) 4) You can only create…

I believe there is still an (undocumented, unofficial) way to backup to the SD card. The backup is still encrypted tho, and can only be restored to the same whatsapp account as created it.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#27

Earlier quoted context omitted.

And it's amazing to me that any Telegram coverage on HN is met with extremely hostile reactions. All they did was not invent the best encryption in the world... like you, me, and 99.9% of the world. Mortal sin, right? So please stick to facts and what can be reasonably proven, please. The rest is meaningless noise and mindless hate. The author himself admits it's much more likely this was an amateurish mistake than s…

I don’t think your paraphrase is an accurate representation of the article.

From the article:

> Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought.

How else would you interpret it?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#28

Earlier quoted context omitted.

I don’t think your paraphrase is an accurate representation of the article.

From the article: > Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. How else would you interpret it?

“This looks like a backdoor but if I think really hard maybe I can consider it to be incompetence?”

Neither is a good look for a security team, of course.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#29
post #25

Earlier quoted context omitted.

And it's amazing to me that any Telegram coverage on HN is met with extremely hostile reactions. All they did was not invent the best encryption in the world... like you, me, and 99.9% of the world. Mortal sin, right? So please stick to facts and what can be reasonably proven, please. The rest is meaningless noise and mindless hate. The author himself admits it's much more likely this was an amateurish mistake than s…

>All they did was not invent the best encryption in the world. They shipped a backdoor. It's pretty clear that Telegram is actively malicious. They haven't been caught again? They probably realized that the front door of not encrypting chats was sufficient. >The author himself admits it's much more likely this was an amateurish mistake than some man-in-the-middle conspiracy This is not at all what the author is sayin…

> Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought.

Unless you have another interpretation of the Hanlon's Razor, it seems that he is saying this is a mistake and not a backdoor.

> They shipped a backdoor.

Did they? Might be. I am 50/50 about it, people do dumb mistakes with self-rolled crypto all the time and that's a sad reality. But who knows, it might be the first try to embed a backdoor.

My point is: being too sure one way or the either makes you biased. I err on the side of incompetence but I am open to the possibility that it was a first sloppy attempt at backdooring Telegram. Sadly we have no proof of either, so we speculate based on what's available.

Post reply on HN