Live data from Hacker News

Telegram’s Cryptanalysis Contest

cryptofails.com

21–30 of 138 posts

Re: Telegram’s Cryptanalysis Contest

#21

Earlier quoted context omitted.

Yeah, it's like saying "oh but the attack possibilities are so limited" to then proceed to mention how all the components can't bear the load of the bridge. Well, if that piece of steel can so obviously not hold those 10000 tons of concrete given the corrosion over the next 30 years, it should be trivial to break it even with their limitations. It has been shown that SHA1 is broken - it's just that experts in the fie…

It looks to me the SHA1 part is the least of their worries. Yes, the pillar may corrode in 30 years, but the load is actually on a smaller and frailer pillar

And yet, the fact that a bridge design contains a pillar that any expert expects to collapse after 30 years might tell you something about the designer's competence and thus about the viability of the whole design.

This is not so much about showing how to break their system, but about showing how their design methodology is likely to produce an unreliable system - because that (a) is much easier to do than actually breaking a system and (b) precisely because of that is how cryptographers usually work and (c) it is actually known to be possible to build systems that are more likely to be and to stay secure, so there is no point in compromising reliability for implementability.

Re: Telegram’s Cryptanalysis Contest

#23

I wish there was an article that succinctly conveys to potential users why Telegram is snakeoil and why TextSecure is the real deal.

Yesterday's article A Crypto Challenge For The Telegram Developers was a good analysis on why Telegram's challenge fails to prove anything.

Re: Telegram’s Cryptanalysis Contest

#24
post #12

Some strong claims in there for not really proving that the protocol is indeed "terrible".

An expert on trees: This oak is probably diseased. It has discolorations on some of the leaves and the bark is much looser than normal. I think it should be thoroughly investigated or perhaps just cut it down to be safe. kayoone, knowing nothing of trees: "some strong claims in there for not really proving that the tree is indeed diseased."

And you obviously know that i know nothing of on the subject?

Re: Telegram’s Cryptanalysis Contest

#27

Is there a reason why all fad "secure" products lately default to custom protocols and exotic solutions instead of using well tested and trusted solutions? Designing a protocol so that is does not leak is very hard.

Unique Selling Point

Well create metadata resistant protocol that communicates on set intervals of time with set length of random data when there is no real payload. This could be done on TLS with little or no effort. The math behind the crypto is strong enough. No need to harden it further.

Every client sends and receives 16KB blob every 30 seconds - this way you could prevent analysis that you are communicating with someone. You could learn a lot just from the size and frequency of packets in a normal chat program.

Re: Telegram’s Cryptanalysis Contest

#28
post #24

Earlier quoted context omitted.

An expert on trees: This oak is probably diseased. It has discolorations on some of the leaves and the bark is much looser than normal. I think it should be thoroughly investigated or perhaps just cut it down to be safe. kayoone, knowing nothing of trees: "some strong claims in there for not really proving that the tree is indeed diseased."

And you obviously know that i know nothing of on the subject?

With respect, at first glance it seems that way. The burden of proof lies with the claim to security, not the claim of insecurity.

Re: Telegram’s Cryptanalysis Contest

#29

I wish there was an article that succinctly conveys to potential users why Telegram is snakeoil and why TextSecure is the real deal.

Yesterday's article A Crypto Challenge For The Telegram Developers was a good analysis on why Telegram's challenge fails to prove anything.

[deleted]

Re: Telegram’s Cryptanalysis Contest

#30
post #28
post #24

Earlier quoted context omitted.

And you obviously know that i know nothing of on the subject?

With respect, at first glance it seems that way. The burden of proof lies with the claim to security, not the claim of insecurity.

The contest actually puts the burden of proof on the "claim of insecurity" side.
Post reply on HN