Live data from Hacker News

Crowdsourcing a More Secure Future

telegram.org

21–30 of 95 posts

Re: Crowdsourcing a More Secure Future

#21
post #3

Earlier quoted context omitted.

Yes, they did. This was not the goal of the bounty, but was still a serious issue. They couldn't give away the prize for the contest and instead decided on a still quite generous $100,000. http://telegram.org/crypto_contest

This was not the goal of the bounty, but was still a serious issue. To be clear, this bug was enough to compromise the security of every Telegram secret chat session. I can't think of a more serious issue.

Yeah. In essence, it made their nominally end-to-end encrypted secret chat feature no more secure than simply giving the Telegram server operators a plaintext copy of every message you sent and trusting them not to log, read or tamper with it.

Worse, it's the kind of flaw you'd expect someone subtly sabotaging the protocol to create. It's a small, superficially plausible modification that turns an apparently secure scheme into something completely broken. Yet if they'd made that modification in the obvious way - by combining the nonce and Diffie-Hellman result with a secure hash function - it wouldn't have caused the problem; for the vulnerability to exist the nonce has to be handled in a very particular way.

Re: Crowdsourcing a More Secure Future

#22
What I don't understand is: where do they get the money from if their intention is to be "free forever"? Are they funded by a non-profit incubator? Why is it that a "new" app spends relatively much money on white-hat hacking bonuses? What do they get out of this other than a deemed secure application?

Re: Crowdsourcing a More Secure Future

#23
The developer who found the potential weakness has earned a reward of $100,000. We have contacted him to find out how he would like to collect his prize.

This is great news. Contrast this with other security contests were finding out-of-scope security flaws weren't rewarded.

People in this thread: Good for Telegram, seems arbitrary, disingenuous, just for publicity.

Short of them being in a conspiracy with the researchers, I can't imagine how this is not good news for everyone. Cool it with the hate, people.

Re: Crowdsourcing a More Secure Future

#24

These latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. I have one question that doesn't seem to be covered anywhere (FAQ, Google): What about Offline messages? I'd like to be able to send encrypted messages even when people are offline - on smartphones it could make use of push notifications, on the Desktop it would just wait until the cl…

Really? The fact that they addressed security concerns with "they're bullshit, here, we'll prove it - break out system!" and then had to pay out nearly immediately convinced you they're awesome?

Re: Crowdsourcing a More Secure Future

#25
post #23

The developer who found the potential weakness has earned a reward of $100,000. We have contacted him to find out how he would like to collect his prize. This is great news. Contrast this with other security contests were finding out-of-scope security flaws weren't rewarded. People in this thread: Good for Telegram , seems arbitrary , disingenuous , just for publicity . Short of them being in a conspiracy with the re…

Cool it with the hate, people.

There's no hate for Telegram here. There's concern for people's safety. https://news.ycombinator.com/item?id=6949842

Re: Crowdsourcing a More Secure Future

#26

These latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. I have one question that doesn't seem to be covered anywhere (FAQ, Google): What about Offline messages? I'd like to be able to send encrypted messages even when people are offline - on smartphones it could make use of push notifications, on the Desktop it would just wait until the cl…

Messages in secret chats are stored on server until downloaded by recipient. So there is no such problem like in Skype.

Push notifications also work fine there, except on iOS they don't contain any message data, just "You have a new message", probably because server doesn't know what's inside encrypted message. Although havent tried their android client.

Re: Crowdsourcing a More Secure Future

#27
post #23

The developer who found the potential weakness has earned a reward of $100,000. We have contacted him to find out how he would like to collect his prize. This is great news. Contrast this with other security contests were finding out-of-scope security flaws weren't rewarded. People in this thread: Good for Telegram , seems arbitrary , disingenuous , just for publicity . Short of them being in a conspiracy with the re…

Cool it with the hate, people. There's no hate for Telegram here. There's concern for people's safety. https://news.ycombinator.com/item?id=6949842

I don't think you actually read the article.

This article is good news, precisely because they show how willing they are to improve their service.

EDIT: Of course it's good PR. So what? That's how Google, Apple and most other big companies operate. They don't have to be altruistic to work and create value for people.

Re: Crowdsourcing a More Secure Future

#29
post #27

Earlier quoted context omitted.

Cool it with the hate, people. There's no hate for Telegram here. There's concern for people's safety. https://news.ycombinator.com/item?id=6949842

I don't think you actually read the article. This article is good news, precisely because they show how willing they are to improve their service. EDIT: Of course it's good PR. So what? That's how Google, Apple and most other big companies operate. They don't have to be altruistic to work and create value for people.

It's an impressive sum of money. Have you considered they're doing this for marketing purposes, not out of concern for people's security?

Re: Crowdsourcing a More Secure Future

#30

Earlier quoted context omitted.

I applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.

I don't mean to sound snide, but judging from your comment history on Telegram related posts, are you really the right person to determine what "reasonable effort" means in this context? Every single post you make is biased negatively towards Telegram. What I applaud is their effort here and I hope it continues and moves in the right direction. This announcement makes it seem like they are in fact moving in the right…

Their effort here seems mostly to have been PR. Their messaging system still uses a bunch of out of date and weird constructions.

Sometimes negativity is not bias.

Post reply on HN