While it is very generous, I doubt they would give a sum like that if it wasn't for the publicity. I'm sure news like this can help their image quite a lot in their target audience (security-aware computer people).
Crowdsourcing a More Secure Future
61–70 of 95 posts
Re: Crowdsourcing a More Secure Future
#62Earlier quoted context omitted.
I applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.
Not sure hiring a US security firm is a safer approach than crowdsourcing using the power of the global community. After all, Matasano's tptacek obviously did spend some of his time inspecting and criticizing Telegram this week. However, he overlooked the 100K vulnerability that was later discovered by a Russian guy who considers himself a newbie in cryptography. The other reason that makes me somewhat reluctant to s…
Re: Crowdsourcing a More Secure Future
#63Earlier quoted context omitted.
Really? The fact that they addressed security concerns with "they're bullshit, here, we'll prove it - break out system!" and then had to pay out nearly immediately convinced you they're awesome?
Yes it does. Show me another non-profit Open Source (mostly) IM service that invests this heavily in seamless encryption and I'll change my opinion. The weakness that they found could have easily been brushed off as non-exploitable, yet they didn't, instead encouraging more security experts to become involved by paying out immediately.
You can't measure how secure something is by looking at how much money has been invested in it.
Re: Crowdsourcing a More Secure Future
#64Earlier quoted context omitted.
I applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.
Not sure hiring a US security firm is a safer approach than crowdsourcing using the power of the global community. After all, Matasano's tptacek obviously did spend some of his time inspecting and criticizing Telegram this week. However, he overlooked the 100K vulnerability that was later discovered by a Russian guy who considers himself a newbie in cryptography. The other reason that makes me somewhat reluctant to s…
Re: Crowdsourcing a More Secure Future
#65If Telegram is a non-commercial project, who is funding this bounty?
Re: Crowdsourcing a More Secure Future
#66Bravo Son! you have earned respect for your this deed. Appreciated. On a side note, I am still not sure, if i will ever use this app. This is primarily because, I act on the internet in the same fashion as i do in real life. I won't do anything online, what I can't do in real life. Hence I don't and perhaps would never need an app like this. As for sending someone 'secret' message, I always whisper that in the ears.…
If someone takes a photo in the street, and you are in the photo, then you will probably not mind. But if someone follows you around everyday and takes thousands of photos, then that is slightly creepy. For me it is the same with my chat messages. If someone reads one or two, I don't mind: they aren't very sensitive. But I don't like it if someone can find everything I've ever written.
People over the internet, are little too much over-sensitive. I am not implying 'Privacy' has no value, but we have taken this issue bit too far over the 'internet'.
A prime example of so-called 'anonymity' over the internet is 4chan, you pretty much know what sort site that is.
I am not implying it's an illegal website, but frankly, anonymity mostly leads to creepy, drugs (silkroad), and everything else considered wrong and bad, than something good which is pretty rare. Snowden is an exception, but again, he committed a crime for a good cause. Most people however commit a crime for every possible wrong reasons.
Re: Crowdsourcing a More Secure Future
#67Earlier quoted context omitted.
I don't mean to sound snide, but judging from your comment history on Telegram related posts, are you really the right person to determine what "reasonable effort" means in this context? Every single post you make is biased negatively towards Telegram. What I applaud is their effort here and I hope it continues and moves in the right direction. This announcement makes it seem like they are in fact moving in the right…
This announcement makes it seem like they are in fact moving in the right direction. Why? Because they're literally paying people to like their product? This developer who found the bug wasn't even trying to get any money. He was, by his own admission, a cryptography newbie who happened to be looking over their protocol and found a serious bug. Now they're throwing money at him. How is that in any way a good thing?
I don't think this statement is reasonable. Are you suggesting that they gave the 100k reward out because they wanted the recipient to like their product?
>Now they're throwing money at him. How is that in any way a good thing?
I think bug bounty programs have a track record of efficacy. Do you disagree?
Re: Crowdsourcing a More Secure Future
#68I always get a bit annoyed when apps use the phone number as the primary identifier.
As somebody that just moved to another country, I now end up with a situation where I can either decide to lose my German whatsapp friends or not being discovered by my American whatsapp friends.
I would love to see the ability to get some sort of ID number and then being able to register more than 1 phone number with it.
Re: Crowdsourcing a More Secure Future
#69Earlier quoted context omitted.
This announcement makes it seem like they are in fact moving in the right direction. Why? Because they're literally paying people to like their product? This developer who found the bug wasn't even trying to get any money. He was, by his own admission, a cryptography newbie who happened to be looking over their protocol and found a serious bug. Now they're throwing money at him. How is that in any way a good thing?
>they're literally paying people to like their product I don't think this statement is reasonable. Are you suggesting that they gave the 100k reward out because they wanted the recipient to like their product? >Now they're throwing money at him. How is that in any way a good thing? I think bug bounty programs have a track record of efficacy. Do you disagree?
Re: Crowdsourcing a More Secure Future
#70Earlier quoted context omitted.
I don't think you actually read the article. This article is good news, precisely because they show how willing they are to improve their service. EDIT: Of course it's good PR. So what? That's how Google, Apple and most other big companies operate. They don't have to be altruistic to work and create value for people.
> precisely because they show how willing they are to improve their service. Multiple people that know what they are doing have remarked that the system Telegram has created is a bad idea and it would be much better to use any established protocol. They have also pointed out multiple places where Telegram is committing obvious cryptographic blunders in their protocol. Telegram decided to pay out $100k under contest r…
They have pointed out multiple places where Telegram MAY BE committing blunders, namely their internal server - server communication MIGHT be susceptible to MITM attacks. It's not the same thing.