Live data from Hacker News

Telegram founder: US intelligence tried to bribe us to weaken encryption

news.fastcompany.com

211–220 of 220 posts

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#211
post #15

The ridiculousness of it all is it's unreasonable at its base to try to prevent encryption as a form of safety and security from violence. Sure, you can lock up all communication for privacy reasons, and the government can spend all kinds of resources on trying to control to prevent or circumvent encryption - however it's a waste of resources as it's simply a bandaid. If I wanted to do something violent or evil I/you…

> however a lot is because people's basic needs aren't being met which prevents the higher levels of Maslow's Hierarchy of Needs from being reached and maintained. This is contradicted by a lot of evidence. Terrorists are most commonly middle class members of their society and often well educated. If anything, terrorism is a powerful means of satisfying the higher levels of 'needs', e.g. meaning, purpose, community.

Interesting and perhaps a fair point. We'd have to understand what quality of life being 'middle class' in each society means, what well-educated means, and there will be more factors of course. If you hurt someone enough either directly or indirectly by killing family and friends' family members, that'll definitely start to outweigh the feelings of being in a safe environment - which doesn't simply come from being 'middle class' or well-educated. Safety is the basic need and if you have a world power killing 100,000s of your citizens, your future isn't going to feel safe; I could mention PTSD and the such, though I think that minimizes and simplifies it too much.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#212
post #105

I am not sure about the claim here but the FBI has always been all over cryptography companies and products and this was well before Snowden, Phil Zimmermann (PGP) knows about this. In 2003-2006, we built a service that was a financial system to exchange financial data through various means including AS/2 EDI over HTTP with big companies and the government suppliers such as AAFES (Army and Air Force Exchange). Initia…

Interesting. That strongly implies that RSA has a flaw, which is news to me.

Weren't there reports that the NSA paid RSA to make flawed crypto the default?

https://arstechnica.com/security/2013/12/report-nsa-paid-rsa...

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#213

Earlier quoted context omitted.

> Is that how you prove something - by reading comments on HN? I enjoy the comments of tpacek and ryanlol

I don't think you answered my question.

I don't base my life on them but I think tpacek and ryanlol know more about computer security than I do.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#214
post #89
post #34

Earlier quoted context omitted.

Even "the Internet" was originally a government funded project

and yeah, currently Internet is a spying tool of USA.

And TOR is no longer (was it before, I don't know) a secure tool.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#215

Earlier quoted context omitted.

You can't be more wrong and uninformed. Russia-bashing seems to be a common and accepted theme now. He actually left Russia and his old company because the Russian government tried to censor it (VK) and he refused to do so. So basically he and Putin are in some kind of fight / disagreement. https://en.wikipedia.org/wiki/Pavel_Durov#Dismissal_from_VK

He didn't leave Russia as in "exile", he did leave Russia as in "it's nice to leave somewhere else". Here [1] is a news report about him throwing out someone's phone for trying to make a photo of him in one of Saint-Petersburg's malls. Here [2] is an article from 2014 stating that he's visiting Telegram's office daily. By the way, Telegram's developers sit in the same building as VK's (also in [2]). Durov seems very…

I never stated it was for exile.

but you are right, article 2 talks about him being in Russia some time in early 2014. It also states that one of the reasons to be there was for selling a datacenter. He left shortly after that with the comment that he had no intentions to return to Russia arguing that the country is incompatible with doing internet business.

> Я уехал из России и не собираюсь возвращаться. К сожалению, в данный момент страна не совместима с ведением бизнеса в интернете

As for the office being in the same building as VK's - that is definitely weird. Even though I know that they also have offices in Berlin and London. Same goes for the fact that they also have multiple datacenters around the world for speed and security. There probably is also going to be a DC in Russia. I don't feel like my data is unsafe due to that.

And where did he lie about the location of developers or servers? I'd be very interested in seeing that. With that you could convince me that something fishy is going on.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#217
post #42

Earlier quoted context omitted.

While I certainly not fan of custom-made crypto Telegram is also open source and they at least not pretend there some "end to end encryption" except you actually did key exchange on your own. > Don't suppose this would be one of Putin's patriotic citizen artists spreading fake news do you? You might be missed it, but Pavel lost business he built to Putin's oligarch friend.

the server is closed source

It doesnt matter if server code is proprietary if E2E keys never leave device. And open source server change nothing since you cant verify what code is running on actual production server anyway.

And messages that are not E2E encrypted are unsafe by default.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#218
post #119

Earlier quoted context omitted.

I read the WP article you cited, titled, "The secret American origins of Telegram, the encrypted messaging app favored by the Islamic State". If Telegram isn't that secure, then why are extremists like IS using it over Signal or WhatsApp? I know Telegram has better features for big groups and much better multi-platform support, so is that the reason? I'm legitimately asking without any snark.

You highly overestimate the people who are in position of power. I am talking about politicians, head of terrorist groups, etc. While saying that top politicians are complete idiots is probably wrong - then again maybe not, I am not sure anymore - the fact that H. Clinton, run the most expensive campaign in history, with backing from all major tech corps AND her staff didn't bother to use encryption at any scale, let…

Haha good points. Thankfully savvier viewers and/or just people in general know House of Cards is all show and not realistic even though it acts like it is with its seriousness.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#219

Earlier quoted context omitted.

I read the WP article you cited, titled, "The secret American origins of Telegram, the encrypted messaging app favored by the Islamic State". If Telegram isn't that secure, then why are extremists like IS using it over Signal or WhatsApp? I know Telegram has better features for big groups and much better multi-platform support, so is that the reason? I'm legitimately asking without any snark.

Because they have fallen for the marketing hype and are not secure messaging systems experts? We know some extremists still use SMS which is definitely not secure. Also, is there evidence that extremists aren't using Signal and WhatsApp?

Them falling for the marketing makes sense.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#220
post #167

Earlier quoted context omitted.

That article is false. A large number of people in the security community have spoken out against that article, which had the effect of convincing people in dangerous situations to switch to less secure communication methods. "Security researchers call for Guardian to retract false WhatsApp backdoor story" [1] The Guardian claims they have offered to let Zeynep Tufekci write a rebuttal; according to Tufekci, they hav…

There is absolutely nothing wrong with the article, claiming that it is FUD will not change the fact that WhatsApp can re-send messages encrypted with different keys at will (which makes it ABSOLUTELY USELESS for people who actually care about their privacy). The argument against the article seems to be around "we can trust whatsapp not to abuse their ability", which blows my mind. You should not have to trust anyone…

The Guardian has apologized for the bullshit story that you love, and completely retracted the claim of a "backdoor".

Do you still believe HN users instead of security researchers?

Do you still give security advice based on randos on HN instead of security researchers?

Post reply on HN