Live data from Hacker News

$300k for Cracking Telegram Encryption

telegram.org

51–60 of 94 posts

Re: $300k for Cracking Telegram Encryption

#51
post #44

Earlier quoted context omitted.

" The best products/systems/protocols/algorithms available today have not been the subjects of any contests, and probably never will be." No? Doesn't this fit the definition of a contest? http://en.wikipedia.org/wiki/Advanced_Encryption_Standard_pr... Yes, the fairness of the contest plays an important part, and a fair context where only the algorithm is analysed goes a long way. "Just because no one wins a contest d…

No, you're playing a semantic game with the word "contest" here. The AES competition was a tournament designed to select the best candidate from a collection of ciphers submitted by the world's best cryptographers. The Twofish bounty was a bounty that guaranteed payment to the best technical critique of a very specific, well-defined cryptographic primitive.

> "The AES competition was a tournament designed to select the best candidate from a collection of ciphers submitted by the world's best cryptographers."

Fair enough. And the focus is exclusively on the algorithm (which is good).

> "The Twofish bounty was a bounty that guaranteed payment to the best technical critique of a very specific, well-defined cryptographic primitive"

"the best technical critique" is still subjective.

Re: $300k for Cracking Telegram Encryption

#52
post #44

Earlier quoted context omitted.

No, you're playing a semantic game with the word "contest" here. The AES competition was a tournament designed to select the best candidate from a collection of ciphers submitted by the world's best cryptographers. The Twofish bounty was a bounty that guaranteed payment to the best technical critique of a very specific, well-defined cryptographic primitive.

> "The AES competition was a tournament designed to select the best candidate from a collection of ciphers submitted by the world's best cryptographers." Fair enough. And the focus is exclusively on the algorithm (which is good). > "The Twofish bounty was a bounty that guaranteed payment to the best technical critique of a very specific, well-defined cryptographic primitive" "the best technical critique" is still sub…

It guaranteed payment. It didn't try to prove a negative. It started from the presumption that there would be solid critiques.

Re: $300k for Cracking Telegram Encryption

#54
post #47
post #5

Maybe restating the obvious, but why don't they pay out the 300k to some professional pen testers or cryptography auditors and publish the results. At least then they would have a shot at validity in this area.

They could do that: Pay $300k for professionals to maybe or maybe not find something, and get limited PR Or, what they do now: Get good PR and if someone manages to win the competition, it means they found flaws which the pros would, hopefully, also have found. If no one wins, they can then use the $300k to get pros on it. Win-win if you ask me.

> Win-win if you ask me.

For the company, maybe.

If you're a user of their half-baked crypto you're playing a high stakes game with a partner that isn't actually interested in keeping you safe.

Re: $300k for Cracking Telegram Encryption

#55
post #52

Earlier quoted context omitted.

> "The AES competition was a tournament designed to select the best candidate from a collection of ciphers submitted by the world's best cryptographers." Fair enough. And the focus is exclusively on the algorithm (which is good). > "The Twofish bounty was a bounty that guaranteed payment to the best technical critique of a very specific, well-defined cryptographic primitive" "the best technical critique" is still sub…

It guaranteed payment . It didn't try to prove a negative. It started from the presumption that there would be solid critiques.

How many comments were received/payed?

There's an undated article https://www.schneier.com/twofish-contest.html pointing to a dead link

Re: $300k for Cracking Telegram Encryption

#56

Earlier quoted context omitted.

Moxie's blogpost about it http://www.thoughtcrime.org/blog/telegram-crypto-challenge/

Some other good overviews: http://www.cryptofails.com/post/70546720222/telegrams-crypta... http://unhandledexpression.com/2013/12/17/telegram-stand-bac...

See the discussion below between Telegram and the author of the post. A lot of good information there.

Re: $300k for Cracking Telegram Encryption

#57

This contest is only valid if they provide access to their servers and databases. They will never prove, this way, that Telegram cannot crack itself.

Well:

  ...this time contestants can not only monitor traffic, but also act as the Telegram server and use active attacks

Re: $300k for Cracking Telegram Encryption

#58
post #9
post #6

I give them, or anyone, credit for trying to create a secure messenger. It is not easy. However, I just wish they would release the source code to their clients and server. They have not. That would go a long way.

Both OTR (ChatSecure on your phone) and TextSecure are good options. Telegram is not a good option.

Unfortunately, those are not real alternatives to Telegram. Telegram is meant to be a WhatsApp replacement.

WhatsApp thrives because in many places, SMS costs are prohibitive (so TextSecure is not an option). In addition, it requires no registration and doesn't rely on external services (so ChatSecure is also out of the question).

Re: $300k for Cracking Telegram Encryption

#59
post #6

I give them, or anyone, credit for trying to create a secure messenger. It is not easy. However, I just wish they would release the source code to their clients and server. They have not. That would go a long way.

The majority of Telegram's source code seems to be released as free software: https://telegram.org/apps (scroll down)

No. Download the iOS app for instance. It is very very old to what is available in the app store. So thee is no way to really verify the client either today.

Re: $300k for Cracking Telegram Encryption

#60
post #9
post #6

I give them, or anyone, credit for trying to create a secure messenger. It is not easy. However, I just wish they would release the source code to their clients and server. They have not. That would go a long way.

Both OTR (ChatSecure on your phone) and TextSecure are good options. Telegram is not a good option.

Not really. Sure, they may be more secure, but their user experience is really bad compared to Telegram.
Post reply on HN