Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

61–70 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#61
post #55

Does anyone have any inside info on this? If we don't assume malice, what is the reason Telegram is rolling its own non-standard crypto like this? Were there no widely publicized E2E protocols that would fit the bill at the time Telegram was being developed? (i.e. was it started before Signal had become known, or does that protocol have limitations that Telegram found unacceptable?) Or did the team have someone in ch…

No amount of effort to validate their protocol will make Telegram trustworthy. Telegram does not encrypt most conversations, you cannot compare it to Signal.

In regards to actually validating the protocol, the OP addresses this

>The current consensus seems to be that the latest version is not broken in known ways that are severe or relevant enough to affect end users, assuming the implementation is correct. That is about as safe as leaving exposed wires around your house because they are either not live or placed high enough that no one should touch them.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#62
post #33
post #30

One thing that always puzzled me about telegram was seeing maps being loaded from yandex when sharing locations with friends

I think it uses Google by default because Google Maps is the best in almost all regions. It gives you an option to change Maybe Yandex in Russia only?

For me it uses Apple Maps?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#63
post #23

Earlier quoted context omitted.

I've posted this here before. > It is encrypted with a per user key known to WhatsApp. This is no longer true! For a few years now. The backup is stored on Google Drive in plain text. https://faq.whatsapp.com/android/chats/about-google-drive-ba...

That page doesn't say that, and "tied to the phone number" sounds like they will only give you the key if you can authenticate via SMS. Do you have a better cite or did you check directly recently?

You can extract it yourself.

https://github.com/YuriCosta/WhatsApp-GD-Extractor-Multithre...

I do not vouch for this repo, but it gets the job done.

The only creds required are your Google account creds. No per-user whatsapp keys necessary.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#64

Earlier quoted context omitted.

If someone says "so this guy killed himself with three shots in the back, but maybe that's a common method of suicide" doesn't mean you think it's suicide. It's a turn of phrase to accentuate how much you don't think it was suicide.

I suppose I missed his sarcasm then. Happens pretty easily over text. As said in another comment, I am no cryptography expert. I simply argue against the very visible negative bias against Telegram which is accentuated even more by very childish snarks on almost any Telegram HN thread. That gets to me and it's not how HN should be. I never argued that my opinion is a fact. I said how I arrived at my opinion and debat…

Have you considered that perhaps Telegram deserves that negative bias due to their own behavior?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#65
And obligatory reference to Backdoored Streebog cipher : https://eprint.iacr.org/2016/071 https://www.sstic.org/media/SSTIC2019/SSTIC-actes/RussianSty...

The backdoor was hidden in the plain sight: the s-box was said to be randomly picked, but years long evasive answers of authors about cryptographic properties of the box made people to think that there was something really not right with it.

If not for that specifically putting aim at the s-box, there would have been no chance anybody found that.

3 years later, and Perrin's paper comes, and it is discovered that almost a new domain of math is buried in that s-box.

Nobody yet discovered what unusual math properties of that s-box do, but nobody now doubts it being a backdoor of some kind.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#66

Earlier quoted context omitted.

Sure, sadly that's how human languages betray us. Plus, him emphasising "a whole lot" doesn't make it a fact. I am no cryptography expert. I judge by all the times I've seen programmers imagine they could do professional cryptography by themselves. Literally every time they fail. Thus, in my eyes it is more likely that Telegram's coders fell victim to the same illusion. But I am not denying that it's possible it's th…

It looks a whole lot more likely to me that this is a backdoor, as they added their own thing to a very standard algorithm (the easy and better thing to do would have been to not add anything), and all that thing did was mess with the key exchange. It's really, really fishy.

But is it really that unlikely that it's a misguided attempt to increase entropy?

The fact that a cryptographer might scoff and laugh at the proposition doesn't mean that a normal programmer couldn't fall victim to that illusion?

In any case -- yes. Both things are likely and you made a strong point for the "malice" side.

Still, it makes me wonder why would Durov run from Russia if he was willing to backdoor Telegram? Why not remain in Russia and backdoor it while being there? Why the extra trouble? Or maybe he didn't want to backdoor it for Russia but for other nation(s)?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#67

Earlier quoted context omitted.

s/likely/unlikely but possibly/

Well, that's how probabilities work and I am not seeing your rephrasing as adding anything valuable to that discussion. Unless you put concrete % numbers on both sides then your replace is identical with the original.

Oh, please, this is not a math inequality where we compare with numbers. It is plain to any English speaker that what was written in the article and how you represented it differ significantly in the confidence that they communicate. As such, your continued insistence that there is no major difference between the two comes off as extremely poor faith.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#68

Earlier quoted context omitted.

> That means for a third party to access the chats, they need Google to hand over the data, and Facebook to hand over the key. National intelligence agencies (plural) would already have both.

True, but it still makes the attack surface much smaller - employees of neither company could steal your data. Your data is now protected by the intersection of the companies privacy policies rather than the union of them.

It used to be that way. But then, one day, Google announced that WhatsApp backups (a) no longer count towards your quota, and (b) are no longer encrypted.

There are two beneficiaries of this change:

1) Intelligence and law enforcement agencies, which now have direct access to WhatsApp history for everyone who uses cloud backup (99.9% of users, if not 100%), without the need to 0day any specific phones, risk detection, or even have those phones on except occasionally.

2) Google, who can now mine your private conversations, metadata, etc.

(At a tiny storage cost for Google, for which they are likely compensated by the NSA)

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#69
post #55

Does anyone have any inside info on this? If we don't assume malice, what is the reason Telegram is rolling its own non-standard crypto like this? Were there no widely publicized E2E protocols that would fit the bill at the time Telegram was being developed? (i.e. was it started before Signal had become known, or does that protocol have limitations that Telegram found unacceptable?) Or did the team have someone in ch…

If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out their implementation was weird and broken (it has since changed).

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#70

Earlier quoted context omitted.

An average user doesn't commonly want to have control over anything themselves :P.

I disagree. They'd love to have control, but that control requires tech sophistication that none of the current tooling adequately elides.

They surely love to have the possibility (and illusion) of control, they don't actually care much for the control itself.

There are numerous marketing studies that show people are most content when choices are made for them (e.g. in getting a new washing machine), as long as they know (or at least believe) they could have made another choice if they wanted to.

Post reply on HN