Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

201–210 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#201
post #94

Earlier quoted context omitted.

And it's amazing to me that any Telegram coverage on HN is met with extremely hostile reactions. All they did was not invent the best encryption in the world... like you, me, and 99.9% of the world. Mortal sin, right? So please stick to facts and what can be reasonably proven, please. The rest is meaningless noise and mindless hate. The author himself admits it's much more likely this was an amateurish mistake than s…

I don't think anybody's hating on the authors of Telegram - just that it's not one of the better options today.

I am not sure I can agree with that either (unless your definition is "does it strictly adhere to end-to-end encryption standards", in which I'll agree with you that it's not the best).

Last I used Riot/Elements (the app the uses the Matrix network), I almost pulled my hair out. It was slow and buggy. Felt like I was using an alpha version of a software from the late 90s.

Telegram and WhatsApp are two very positive outliers in a sea of very bad messaging apps IMO.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#202

Earlier quoted context omitted.

>They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. Off The Record showed up in 2004 and was used over multiple instant messaging systems. OpenPGP was used over various IM systems before that...

Well, if you go that far lol. I remember OTR on Pidgin and Adium back in the days. Not sure I'd consider these third party tacked on solutions e2ee messaging app that can e2e encrypt your chat. OpenPGP doesn't come with email and OTR doesn't come with GTalk.

OTR did come with other apps. OpenPGP was a documented XMPP extension.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#203

Earlier quoted context omitted.

The situation is (slightly) ambiguous. It looks like a backdoor. Anyone competent writing that code would be doing so because they wanted the backdoor. But there's no reason to assume Telegram's authors are competent unnecessarily, and competence in UI design doesn't imply competence in security. And it's also a rather obvious-looking backdoor, anyone competent would presumably try to hide it better. Then again, the…

Oh, I am not firmly claiming that it's not a backdoor. It very well might be! But that's what mostly what I was saying (granted, I got worked up at one point because the blind stereotyping puts a black mark on HN's reputation in my eyes) is that indeed the situation is ambiguous and both possibilities are [mostly] equally likely.

The author disagrees they're equally likely. They seem more qualified than you.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#204

Earlier quoted context omitted.

Why does Telegram make all important security features opt-in?

Ergonomics. The HN crowd is really quick to forget that many users have no patience to setup several passwords and/or keys after installing an app. You and I discussed quite a bit already and we can't agree on many things -- but I can still see where Telegram's team is coming from in their security decisions. A balance between ergonomics and security has to be struck if you want wide adoption. We likely both abhor ho…

Everyone would shut up about Telegram if they stopped making misleading security claims.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#205

Earlier quoted context omitted.

I don’t get it, this claim should be fairly easy to prove by reverse engineering the app.

Then why has nobody done it? F.ex. Google's Project Zero?

You mean, why has nobody found WhatsApp is actually not E2E encrypted? Could it be it's because it's actually E2E encrypted? Your evidence to the contrary is no evidence at all and now you're asking why p0 hasn't found evidence of your position either. It's a very odd line of argument.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#206
post #194

Earlier quoted context omitted.

"[flagged]". I'm a HN noob, is there a way to see it? Or what did it say?

Set "show dead" to "yes" in your profile.

Oh, thanks, I thought it's only needed for it to show up at all.

That's very yikes indeed

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#207

Earlier quoted context omitted.

MitM means Man-in-the-Middle, unless otherwise specified. There's no ambiguity. You just copied that list from Wikipedia. PitM is much more confusing because only a few weirdos use that.

Are you sure? I'm not a cryptogrpher and I think neither are you while Filippo Valsorda is indeed a serious cryptographer. And yes, I copied that list from Wikipedia because people is genuinely trying to replace the word without altering the abbreviation.

Yes I am sure.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#208
post #65

And obligatory reference to Backdoored Streebog cipher : https://eprint.iacr.org/2016/071 https://www.sstic.org/media/SSTIC2019/SSTIC-actes/RussianSty... The backdoor was hidden in the plain sight: the s-box was said to be randomly picked, but years long evasive answers of authors about cryptographic properties of the box made people to think that there was something really not right with it. If not for that specific…

Is there a layman version of this? Something non cryptographers can grasp?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#209
post #94

Earlier quoted context omitted.

I don't think anybody's hating on the authors of Telegram - just that it's not one of the better options today.

I am not sure I can agree with that either (unless your definition is "does it strictly adhere to end-to-end encryption standards", in which I'll agree with you that it's not the best). Last I used Riot/Elements (the app the uses the Matrix network), I almost pulled my hair out. It was slow and buggy. Felt like I was using an alpha version of a software from the late 90s. Telegram and WhatsApp are two very positive o…

This whole thread is about security. That your priorities differ from other commenters doesn't make the criticisims "mindless hate" (and, again, not directed at individuals, just that we think the product and service is garbage from a security perspective. Don't conflate the creation with the creators)

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#210
post #65

And obligatory reference to Backdoored Streebog cipher : https://eprint.iacr.org/2016/071 https://www.sstic.org/media/SSTIC2019/SSTIC-actes/RussianSty... The backdoor was hidden in the plain sight: the s-box was said to be randomly picked, but years long evasive answers of authors about cryptographic properties of the box made people to think that there was something really not right with it. If not for that specific…

Is there a layman version of this? Something non cryptographers can grasp?

here is a quote:

> designers of Streebog and Kuznyechik purposefully hid a structure in this component. This structure is very strong, very uncommon and interacts in a non-trivial way with the other main component of Streebog.

> In light of these results, we urge security professionals to avoid these algorithms.

It's like this: imagine some government released plans for super-secure safe, and for some reason, deep in those plans, there is an instruction to make an 1/4" hole in the door, at the specific exact position. There is no justification or explanation for this hole, just a mention that it must be present or the safe is not going to be certified.

So people wonder why it was placed on the plan. If there were a good reason, why not tell it? Perhaps NSA/FSB has some new method to crack safes, and this hole is needed for it? Better be careful, and avoid using that specific safe model.

Post reply on HN