Live data from Hacker News

Crowdsourcing a More Secure Future

telegram.org

31–40 of 95 posts

Re: Crowdsourcing a More Secure Future

#31
post #23

The developer who found the potential weakness has earned a reward of $100,000. We have contacted him to find out how he would like to collect his prize. This is great news. Contrast this with other security contests were finding out-of-scope security flaws weren't rewarded. People in this thread: Good for Telegram , seems arbitrary , disingenuous , just for publicity . Short of them being in a conspiracy with the re…

On it's own, it's great news. In context of everything Telegram have said and done before, it's not hard to come to the conclusion of 'disingenuous' or 'just for publicity'. A company that launches a crypto challenge which can only be for publicity / marketing purposes, gets called out on it and then starts handing out cash to anyone who finds a bug looks like a company that doesn't really know what they're doing.

Re: Crowdsourcing a More Secure Future

#32

These latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. I have one question that doesn't seem to be covered anywhere (FAQ, Google): What about Offline messages? I'd like to be able to send encrypted messages even when people are offline - on smartphones it could make use of push notifications, on the Desktop it would just wait until the cl…

Why? They just announced that one of the main advertised features of their IM software - the secret chat functionality - was so badly broken that it was worse than not having it at all. It provided absolutely no protection against them eavesdropping on their users, yet those users were chatting under the illusion that they were secure against such eavesdropping. Worse, it seems like the Telegram developers consider this to be a theoretical problem rather than an actual compromise because you can trust them not to spy on you.

Re: Crowdsourcing a More Secure Future

#33

These latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. I have one question that doesn't seem to be covered anywhere (FAQ, Google): What about Offline messages? I'd like to be able to send encrypted messages even when people are offline - on smartphones it could make use of push notifications, on the Desktop it would just wait until the cl…

Really? The fact that they addressed security concerns with "they're bullshit, here, we'll prove it - break out system!" and then had to pay out nearly immediately convinced you they're awesome?

Yes it does. Show me another non-profit Open Source (mostly) IM service that invests this heavily in seamless encryption and I'll change my opinion. The weakness that they found could have easily been brushed off as non-exploitable, yet they didn't, instead encouraging more security experts to become involved by paying out immediately.

Re: Crowdsourcing a More Secure Future

#34
post #27

Earlier quoted context omitted.

I don't think you actually read the article. This article is good news, precisely because they show how willing they are to improve their service. EDIT: Of course it's good PR. So what? That's how Google, Apple and most other big companies operate. They don't have to be altruistic to work and create value for people.

It's an impressive sum of money. Have you considered they're doing this for marketing purposes, not out of concern for people's security?

So what? They're still doing it.

Unless it turned out they'd set the whole thing up, which would be different.

Re: Crowdsourcing a More Secure Future

#35
post #32

These latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. I have one question that doesn't seem to be covered anywhere (FAQ, Google): What about Offline messages? I'd like to be able to send encrypted messages even when people are offline - on smartphones it could make use of push notifications, on the Desktop it would just wait until the cl…

Why? They just announced that one of the main advertised features of their IM software - the secret chat functionality - was so badly broken that it was worse than not having it at all. It provided absolutely no protection against them eavesdropping on their users, yet those users were chatting under the illusion that they were secure against such eavesdropping. Worse, it seems like the Telegram developers consider t…

That's interesting, I didn't interpret the news this way. I haven't seen secret chat functionality mentioned anywhere yet - I was assuming that secret chat shouldn't be affected by these nonce messages since the secret key shouldn't touch their servers according to their documentation. Do you have any source on this?

Re: Crowdsourcing a More Secure Future

#36

These latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. I have one question that doesn't seem to be covered anywhere (FAQ, Google): What about Offline messages? I'd like to be able to send encrypted messages even when people are offline - on smartphones it could make use of push notifications, on the Desktop it would just wait until the cl…

These latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. Why is that? This latest revelation should give less faith in Telegram, not more.

See my replies to makomk and ceejayoz.

Re: Crowdsourcing a More Secure Future

#37

Earlier quoted context omitted.

Really? The fact that they addressed security concerns with "they're bullshit, here, we'll prove it - break out system!" and then had to pay out nearly immediately convinced you they're awesome?

Yes it does. Show me another non-profit Open Source (mostly) IM service that invests this heavily in seamless encryption and I'll change my opinion. The weakness that they found could have easily been brushed off as non-exploitable, yet they didn't, instead encouraging more security experts to become involved by paying out immediately.

Investing heavily is meaningless if you're investing badly.

Building an encrypted IM service with bad crypto is like investing in blacksmiths in the early 1900s.

Re: Crowdsourcing a More Secure Future

#38
post #27

Earlier quoted context omitted.

Cool it with the hate, people. There's no hate for Telegram here. There's concern for people's safety. https://news.ycombinator.com/item?id=6949842

I don't think you actually read the article. This article is good news, precisely because they show how willing they are to improve their service. EDIT: Of course it's good PR. So what? That's how Google, Apple and most other big companies operate. They don't have to be altruistic to work and create value for people.

> precisely because they show how willing they are to improve their service.

Multiple people that know what they are doing have remarked that the system Telegram has created is a bad idea and it would be much better to use any established protocol. They have also pointed out multiple places where Telegram is committing obvious cryptographic blunders in their protocol.

Telegram decided to pay out $100k under contest rules that are weaker than known plaintext attacks. If they wanted to actually improve their security they would switch to a more secure protocol that doesn't require a server to actively participate in the conversation. I guess if they want to hemorrhage money via the hubris that is their crypto contest they should just keep on as they are.

Re: Crowdsourcing a More Secure Future

#39

Good for Telegram. I haven't downloaded and installed their App yet, but I applaud their effort at putting out a secure chat app that everyone can use. I've been using TextSecure for a while (as everyone on HN ruthlessly suggests) but guess how many encrypted texts I've sent? 0. That's because they have no iOS app and very few Android users. There are two problems when it comes to creating a good, secure messaging ap…

I applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.

Not sure hiring a US security firm is a safer approach than crowdsourcing using the power of the global community.

After all, Matasano's tptacek obviously did spend some of his time inspecting and criticizing Telegram this week. However, he overlooked the 100K vulnerability that was later discovered by a Russian guy who considers himself a newbie in cryptography.

The other reason that makes me somewhat reluctant to spend money on hiring Matasano is the recent RSA-gate (and the strange role of tptacek in it).

Re: Crowdsourcing a More Secure Future

#40

Earlier quoted context omitted.

I applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.

I don't mean to sound snide, but judging from your comment history on Telegram related posts, are you really the right person to determine what "reasonable effort" means in this context? Every single post you make is biased negatively towards Telegram. What I applaud is their effort here and I hope it continues and moves in the right direction. This announcement makes it seem like they are in fact moving in the right…

If you don't think "hire people that know what they are doing with crypto" is better advice than "have a contest that doesn't even prove security under known plaintext attacks and pay out $100k to someone who finds a MITM attack to prove you're serious", you're actually not qualified to determine who the right person to determine "reasonable effort" is. I know I sound like a complete jerk, but that's just the honest truth.

The fact is that it is highly inappropriate to have a new, completely unvetted cryptographic protocol in a context where people are relying on it to provide actual security, and they are flat-out ignoring advice from talented and knowledgable people.

Post reply on HN