Earlier quoted context omitted.
Really? The fact that they addressed security concerns with "they're bullshit, here, we'll prove it - break out system!" and then had to pay out nearly immediately convinced you they're awesome?
Yes it does. Show me another non-profit Open Source (mostly) IM service that invests this heavily in seamless encryption and I'll change my opinion. The weakness that they found could have easily been brushed off as non-exploitable, yet they didn't, instead encouraging more security experts to become involved by paying out immediately.
Crowdsourcing a More Secure Future
51–60 of 95 posts
Re: Crowdsourcing a More Secure Future
#52Earlier quoted context omitted.
Cool it with the hate, people. There's no hate for Telegram here. There's concern for people's safety. https://news.ycombinator.com/item?id=6949842
I don't think you actually read the article. This article is good news, precisely because they show how willing they are to improve their service. EDIT: Of course it's good PR. So what? That's how Google, Apple and most other big companies operate. They don't have to be altruistic to work and create value for people.
Re: Crowdsourcing a More Secure Future
#53Re: Crowdsourcing a More Secure Future
#54Earlier quoted context omitted.
The question whether their Crypto is bad is still out IMO - these recent findings still don't seem to be that big of a deal to me - as with all other IM services I have to trust the service provider for their integrity - yet here I have an alternative provided by a non-profit organization with some scientific credentials that offer an open API - as opposed to Skype, WhatsApp, Facebook et al. We currently use Skype fo…
What's wrong with encrypted Jabber?
Re: Crowdsourcing a More Secure Future
#55Wow...Telegram. The only thing you will ever get from engaging the "public" on forums like HN is heartache. You will never get them to like you...they just aren't that in to you. Contact people that are actually in the crypto community and go the normal route. Once their betters tell them to love you there is actually nothing that you could do to make them stop.
Re: Crowdsourcing a More Secure Future
#56Earlier quoted context omitted.
Really? The fact that they addressed security concerns with "they're bullshit, here, we'll prove it - break out system!" and then had to pay out nearly immediately convinced you they're awesome?
Yes it does. Show me another non-profit Open Source (mostly) IM service that invests this heavily in seamless encryption and I'll change my opinion. The weakness that they found could have easily been brushed off as non-exploitable, yet they didn't, instead encouraging more security experts to become involved by paying out immediately.
Re: Crowdsourcing a More Secure Future
#57What I don't understand is: where do they get the money from if their intention is to be "free forever"? Are they funded by a non-profit incubator? Why is it that a "new" app spends relatively much money on white-hat hacking bonuses? What do they get out of this other than a deemed secure application?
Re: Crowdsourcing a More Secure Future
#58If Telegram is a non-commercial project, who is funding this bounty?
For the original "$200K" bounty, it was stated that it would be paid out in bitcoin. So it's quite possible that the person or organization funding the bounty simply has some old bitcoin laying around, and it cost them next to nothing to get it initially, and it might even be difficult for them to exchange for their preferred fiat currency today. So don't think of it as "Somebody just spent $100K," think of it as "A…
Re: Crowdsourcing a More Secure Future
#59Earlier quoted context omitted.
It's an impressive sum of money. Have you considered they're doing this for marketing purposes, not out of concern for people's security?
So what? They're still doing it. Unless it turned out they'd set the whole thing up, which would be different.
That's an important question, really curious to know if the user x7mz steps up to take the reward and if telegram would release any proof of payment (minus any obvious info that would give away the identity of x7mz).
This vulnerability seems to be connected to Diffie-Hellman, right? Even a rudimentary search shows that a MITM is easy on it. I wonder if its even possible that they did not know this one?
Re: Crowdsourcing a More Secure Future
#60Earlier quoted context omitted.
I applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.
Not sure hiring a US security firm is a safer approach than crowdsourcing using the power of the global community. After all, Matasano's tptacek obviously did spend some of his time inspecting and criticizing Telegram this week. However, he overlooked the 100K vulnerability that was later discovered by a Russian guy who considers himself a newbie in cryptography. The other reason that makes me somewhat reluctant to s…
It is unfair to imply incompetence on tptacek's part given only that he spent some finite amount of time looking at your protocol and did not find the nonce vulnerability. It is also unfair to say that he didn't find any vulnerabilities despite the potential for a 100k reward as the potential for such a reward (outside of your specific contest) had not been stated clearly.
If you do in fact have evidence that tptacek was involved in RSA's deal with the NSA, you should state your accusations explicitly and provide that evidence. If you do not, I think the accusation is inappropriate and certainly counterproductive.
That said, I very much appreciate the resources you are donating to open source crypto software. It is undeniable that the potential for a 100k reward will send a lot of eyes to your source code. I would encourage you to also consider hiring a security firm (US based or otherwise) and to consider how your comments will affect public perception of Telegram.