Live data from Hacker News

Telegram’s Cryptanalysis Contest

cryptofails.com

41–50 of 138 posts

Re: Telegram’s Cryptanalysis Contest

#41
post #24

Earlier quoted context omitted.

An expert on trees: This oak is probably diseased. It has discolorations on some of the leaves and the bark is much looser than normal. I think it should be thoroughly investigated or perhaps just cut it down to be safe. kayoone, knowing nothing of trees: "some strong claims in there for not really proving that the tree is indeed diseased."

And you obviously know that i know nothing of on the subject?

From your comment everyone can immediately surmise that you lack the practical knowledge of using cryptography for real world applications that people like tptacek and moxie have.

They are known experts and have been quite clear on the questionable nature of Telegram's choice of cryptographic primitives and their composition. Their objection is not 'this is obviously broken'. Their objection is 'this does not obviously work and there are some red flags'. This blog post merely mirrors that objection.

The crucial point is that the past has shown that no proof of brokenness is required. In cryptography, if it doesn't obviously work, it is probably broken, because it is incredibly hard to get right and because an incredible amount of money and effort is available to find the tiniest crack. You are dealing with criminals and governments who have deep pockets. Either you prove it works or you assume it doesn't work. The proof is missing.

Re: Telegram’s Cryptanalysis Contest

#43

I think people should keep quiet if they cant break their system. What good is a cryptographer, if its only good for pointing fingers?

Did you read the blog post? This is precisely what the OP is saying, that the contest is flawed. They are basically saying if you can break my new fancy lock you win but you can only see the lock over the webcam and not touch it.

Re: Telegram’s Cryptanalysis Contest

#44
post #33

Earlier quoted context omitted.

I disagree You are allowed access to the encrypted data. In a real attack you may, depending on the circumstances, only have access to that (at first, at least). Probably more like "you aren't allowed to destroy any locks or doors to enter the house". Hard, but much different than staying 200m from the house.

> In a real attack you may, depending on the circumstances, only have access to that (at first, at least). You misunderstand the whole deal. When imagining different potential attacks on your house you can't go laying down rules that the burglars have to follow. What if there are special circumstances (that you weren't aware of) that allows the burglars to bypass your restrictions under certain conditions? You plan f…

"When imagining different potential attacks on your house you can't go laying down rules that the burglars have to follow"

Of course. But everything is limited and for each scenario there's a specific chance that will happen. Some RSA key sizes are breakable if you can put a lot of computing power behind.

For example, a house may not be built to withstand tanks, so there's your limitation.

On the other hand, there's a huge likelihood someone will walk past your house and see the door ajar, or try to open it.

So, again, everybody is right to secure against KPA, CPA, etc, BUT don't forget that there may be something easier, and yes, if it resists the deeper attacks it's probably safe against capture of cyphertext.

"But we all see how foolish that would be. You plan for the worst case scenario and hash+salt your passwords"

Sure. But in practice the plaintext + strong DB security may be safer "overall" than a hash + salt on a MySQL with the credentials forgotten in some config.php somewhere.

(It's not an excuse to not hash the passwords, though)

Re: Telegram’s Cryptanalysis Contest

#45
post #32

Earlier quoted context omitted.

Yep. So far it was more like "Please please don't use Telegram. Please please use TextSecure.".

So you didn't understand the article here then? There's no shame on that, crypto is complex and requires study. But please don't dismiss well written and well thought-out critiques like this one just because you didn't understand the arguments.

Talking down to people helps nobody. If I were a random potential user and read what you wrote, my reaction would not be polite, and I would probably feel polarized against your recommendation out of spite.

The problem isn't that potential users are lacking anything. It's that nobody on our side of the table has communicated clearly and succinctly. https://news.ycombinator.com/item?id=6941007

Re: Telegram’s Cryptanalysis Contest

#46
post #32

Earlier quoted context omitted.

So you didn't understand the article here then? There's no shame on that, crypto is complex and requires study. But please don't dismiss well written and well thought-out critiques like this one just because you didn't understand the arguments.

Talking down to people helps nobody. If I were a random potential user and read what you wrote, my reaction would not be polite, and I would probably feel polarized against your recommendation out of spite. The problem isn't that potential users are lacking anything. It's that nobody on our side of the table has communicated clearly and succinctly. https://news.ycombinator.com/item?id=6941007

I'm not talking down, it's clear that the commenter hadn't understood the article. And there really is no shame in that.

Further, your linked comment seems to be exactly what they're complaining about - Textmate good, Telegram bad. It doesn't explain why and why turns out to be quite hard to explain succinctly.

Re: Telegram’s Cryptanalysis Contest

#47
post #36

Earlier quoted context omitted.

Well create metadata resistant protocol that communicates on set intervals of time with set length of random data when there is no real payload. This could be done on TLS with little or no effort. The math behind the crypto is strong enough. No need to harden it further. Every client sends and receives 16KB blob every 30 seconds - this way you could prevent analysis that you are communicating with someone. You could…

It seems like there is a 'No-Free-Lunch' tradeoff between bandwidth efficiency and traffic analysis resistance.

I prefer the later to the former in a heartbeat.

Re: Telegram’s Cryptanalysis Contest

#48
post #32

Earlier quoted context omitted.

Yep. So far it was more like "Please please don't use Telegram. Please please use TextSecure.".

So you didn't understand the article here then? There's no shame on that, crypto is complex and requires study. But please don't dismiss well written and well thought-out critiques like this one just because you didn't understand the arguments.

Oh, wow, and people complain about Telegram team's attitude. Don't be so vulnerable, please. Take the critics easy.

As for the article, it's well written, but most of the points had been answered in Telegram FAQ or comments on HN. And yet they come up again and again. Not all, most.

Re: Telegram’s Cryptanalysis Contest

#49

I wish there was an article that succinctly conveys to potential users why Telegram is snakeoil and why TextSecure is the real deal.

That would be nice. But, for what it's worth: don't use Telegram. It's a mess. TextSecure was built much, much more carefully.

Re: Telegram’s Cryptanalysis Contest

#50

With all the publicity TextSecure is getting from all this Telegram Debacle, I am beginning to suspect telegram isn't even a real company, and just a very elaborate publicity stunt by Moxie and the rest of the TextSecure team!! :P

By the comments it seems that most of the active haters of Telegram are TextSecure team. Yes, they want publicity and funding - and who doesn't?
Post reply on HN