Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

31–40 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#31
post #17

If any clients had been logging that nonce, we could retrospectively catch any person in the middle. Far too few services do strategic logging of data useful to catch attackers like this. Many attackers won't attack if they know traces will be left which can point to them.

The more I work with production systems, the more I appreciate healthy logs. We've solved at least a dozen big issues this past year with "just scan the logs and rebuild the historical data, we can pretend like we were monitoring that issue the whole time".

You run debug level logging on prod?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#32

Earlier quoted context omitted.

From the article: > Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. How else would you interpret it?

“This looks like a backdoor but if I think really hard maybe I can consider it to be incompetence?” Neither is a good look for a security team, of course.

Yes, it's not, but my (and his) point stands: it's likely incompetence. It's very biased and uncharitable to immediately assume malice.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#33
post #30

One thing that always puzzled me about telegram was seeing maps being loaded from yandex when sharing locations with friends

I think it uses Google by default because Google Maps is the best in almost all regions. It gives you an option to change

Maybe Yandex in Russia only?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#34

Earlier quoted context omitted.

“This looks like a backdoor but if I think really hard maybe I can consider it to be incompetence?” Neither is a good look for a security team, of course.

Yes, it's not, but my (and his) point stands: it's likely incompetence. It's very biased and uncharitable to immediately assume malice.

>(and his) point stands: it's likely incompetence

That’s not what the post is saying.

> It's very biased and uncharitable

It’s not “very biased”, if you actually look at what Telegram did the balance of probabilities leans heavily towards “backdoor” and not “not backdoor”

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#35
post #34

Earlier quoted context omitted.

Yes, it's not, but my (and his) point stands: it's likely incompetence. It's very biased and uncharitable to immediately assume malice.

>(and his) point stands: it's likely incompetence That’s not what the post is saying. > It's very biased and uncharitable It’s not “very biased”, if you actually look at what Telegram did the balance of probabilities leans heavily towards “backdoor” and not “not backdoor”

So, give me your definition of Hanlon's Razor then (mentioned at the end of the article by the author).

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#36
post #17

Earlier quoted context omitted.

The more I work with production systems, the more I appreciate healthy logs. We've solved at least a dozen big issues this past year with "just scan the logs and rebuild the historical data, we can pretend like we were monitoring that issue the whole time".

You run debug level logging on prod?

“debug level” and “prod level” logs are pretty arbitrarily drawn lines from organisation to organisation. If they’re intentionally running that logging level on prod, it’s prod level

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#37
post #34

Earlier quoted context omitted.

>(and his) point stands: it's likely incompetence That’s not what the post is saying. > It's very biased and uncharitable It’s not “very biased”, if you actually look at what Telegram did the balance of probabilities leans heavily towards “backdoor” and not “not backdoor”

So, give me your definition of Hanlon's Razor then (mentioned at the end of the article by the author).

I think you’re completely missing the nuance in the words surrounding the authors mention of “Hanlon’s razor”.

Besides, look at Pavel Durovs flagkilled reply here. The lady doth protest too much, methinks.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#38
post #37

Earlier quoted context omitted.

So, give me your definition of Hanlon's Razor then (mentioned at the end of the article by the author).

I think you’re completely missing the nuance in the words surrounding the authors mention of “Hanlon’s razor”. Besides, look at Pavel Durovs flagkilled reply here. The lady doth protest too much, methinks.

That's not saying anything of substance unless you offer your own interpretation. "You're wrong" is not a discussion, it's a kick in the gut.

> The lady doth protest too much, methinks.

Solid criticism with well laid-out arguments from you, no doubt.

> Besides, look at Pavel Durovs flagkilled reply here.

Since when do upvote / downvote count mean anything at all about somebody's opinion or statements? (I haven't read the comment though.)

Look, it's obvious you have a beef with Telegram / Durov. But you are not giving any arguments, only snark. That's breaking HN's guidelines last I checked.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#39
post #33
post #30

One thing that always puzzled me about telegram was seeing maps being loaded from yandex when sharing locations with friends

I think it uses Google by default because Google Maps is the best in almost all regions. It gives you an option to change Maybe Yandex in Russia only?

[deleted]

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#40
post #37

Earlier quoted context omitted.

So, give me your definition of Hanlon's Razor then (mentioned at the end of the article by the author).

I think you’re completely missing the nuance in the words surrounding the authors mention of “Hanlon’s razor”. Besides, look at Pavel Durovs flagkilled reply here. The lady doth protest too much, methinks.

I certainly hope that’s not the real Pavel Durov…
Post reply on HN