Earlier quoted context omitted.
WhatsApps cloud backup on Android sits on Google drive by default. It is encrypted with a per user key known to WhatsApp. That means for a third party to access the chats, they need Google to hand over the data, and Facebook to hand over the key. The logical next step to add would be for Google to additionally encrypt the data with the users logon password or something derived from it. Google won't do this anytime so…
WhatsApp backups are a bit of an anti-feature, as I found out while trying to ditch the app after the recent policy update. 1) The backup can only be made to Google drive, you cannot create a manual backup to a location of your chosing 2) The backup is created in a secret folder that cannot be accessed by the user 3) The backup is deleted if you delete your account. (not much of a backup, eh?) 4) You can only create…
The Most Backdoor-Looking Bug I’ve Ever Seen
51–60 of 222 posts
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#52Earlier quoted context omitted.
>All they did was not invent the best encryption in the world. They shipped a backdoor. It's pretty clear that Telegram is actively malicious. They haven't been caught again? They probably realized that the front door of not encrypting chats was sufficient. >The author himself admits it's much more likely this was an amateurish mistake than some man-in-the-middle conspiracy This is not at all what the author is sayin…
> Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. Unless you have another interpretation of the Hanlon's Razor, it seems that he is saying this is a mistake and not a backdoor. > They shipped a backdoor. Did they? Might be. I am 50/50 about it, people do dumb mistakes with self-rolled crypto all the time and that's a sad reality. But who knows, it mi…
It just sounds like the author simply doesn't want to get sued, after all it's generally impossible to prove that a backdoor is actually a backdoor.
>people do dumb mistakes with self-rolled crypto all the time
I've seen a plenty of those, this one just happens to look rather different than the typical implementation mistakes you see. There's no possible reason for this code to exists except to allow Telegram to decrypt secret chats.
In the end, we've got nothing to gain and a plenty lose by giving Telegram the benefit of the doubt.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#53Earlier quoted context omitted.
And it's amazing to me that any Telegram coverage on HN is met with extremely hostile reactions. All they did was not invent the best encryption in the world... like you, me, and 99.9% of the world. Mortal sin, right? So please stick to facts and what can be reasonably proven, please. The rest is meaningless noise and mindless hate. The author himself admits it's much more likely this was an amateurish mistake than s…
I don’t think your paraphrase is an accurate representation of the article.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#54Earlier quoted context omitted.
So, give me your definition of Hanlon's Razor then (mentioned at the end of the article by the author).
The author is saying "maybe things that look A WHOLE LOT like malice are actually incompetence". It's pretty clear that he thinks it's a backdoor, even though he basically says "maybe in actually wrong, but I really don't think so".
I am no cryptography expert. I judge by all the times I've seen programmers imagine they could do professional cryptography by themselves. Literally every time they fail. Thus, in my eyes it is more likely that Telegram's coders fell victim to the same illusion.
But I am not denying that it's possible it's the [beginnings of a] backdoor. The whole sub-thread is (a) my opinion on what's more likely and (b) calling out people who act snarky, offer no facts and demonstrate general negative bias.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#55Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#56Earlier quoted context omitted.
And it's amazing to me that any Telegram coverage on HN is met with extremely hostile reactions. All they did was not invent the best encryption in the world... like you, me, and 99.9% of the world. Mortal sin, right? So please stick to facts and what can be reasonably proven, please. The rest is meaningless noise and mindless hate. The author himself admits it's much more likely this was an amateurish mistake than s…
Nothing about my comment could reasonably be described as "extremely hostile". You seem to be exposing a bias.
If by calling out people who break HN's guidelines I am exposing a bias then okay, I am exposing a bias then.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#57Earlier quoted context omitted.
I don’t think your paraphrase is an accurate representation of the article.
From the article: > Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. How else would you interpret it?
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#58Earlier quoted context omitted.
I've posted this here before. > It is encrypted with a per user key known to WhatsApp. This is no longer true! For a few years now. The backup is stored on Google Drive in plain text. https://faq.whatsapp.com/android/chats/about-google-drive-ba...
That page doesn't say that, and "tied to the phone number" sounds like they will only give you the key if you can authenticate via SMS. Do you have a better cite or did you check directly recently?
I haven't tried this specific tool yet (or others recently) but it was definitely possible in the past without requiring any key from FB/WA.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#59Earlier quoted context omitted.
The author is saying "maybe things that look A WHOLE LOT like malice are actually incompetence". It's pretty clear that he thinks it's a backdoor, even though he basically says "maybe in actually wrong, but I really don't think so".
Sure, sadly that's how human languages betray us. Plus, him emphasising "a whole lot" doesn't make it a fact. I am no cryptography expert. I judge by all the times I've seen programmers imagine they could do professional cryptography by themselves. Literally every time they fail. Thus, in my eyes it is more likely that Telegram's coders fell victim to the same illusion. But I am not denying that it's possible it's th…
It's really, really fishy.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#60Earlier quoted context omitted.
> Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. Unless you have another interpretation of the Hanlon's Razor, it seems that he is saying this is a mistake and not a backdoor. > They shipped a backdoor. Did they? Might be. I am 50/50 about it, people do dumb mistakes with self-rolled crypto all the time and that's a sad reality. But who knows, it mi…
If someone says "so this guy killed himself with three shots in the back, but maybe that's a common method of suicide" doesn't mean you think it's suicide. It's a turn of phrase to accentuate how much you don't think it was suicide.
As said in another comment, I am no cryptography expert. I simply argue against the very visible negative bias against Telegram which is accentuated even more by very childish snarks on almost any Telegram HN thread. That gets to me and it's not how HN should be.
I never argued that my opinion is a fact. I said how I arrived at my opinion and debate with people whether that's plausible or not [based on limited info]. The rest can be proven/rebuked by specialists.