Live data from Hacker News

$300k for Cracking Telegram Encryption

telegram.org

61–70 of 94 posts

Re: $300k for Cracking Telegram Encryption

#61
post #3

Obligatory: https://www.schneier.com/crypto-gram-9812.html $300,000 isn't a whole lot more than it would cost to get n entire novel cryptosystem for a complex application built out of idiosyncratic components assessed professionally. They should just retain Riscure or Rambus to do that for them instead of the PR stunt. Previous thread about Telegram on HN, featuring Moxie Marlinspike: https://news.ycombinator.com/ite…

See https://news.ycombinator.com/item?id=6931457 as well.

> They should just retain Riscure or Rambus to do that for them instead of the PR stunt.

I'd love to go back through either of the previous threads and count to see how many people were saying "well, if no one can successfully win the challenge, they can use the money for a security audit!" like they are right now.

Telegram is pretty clearly a bad player that should be avoided.

Re: $300k for Cracking Telegram Encryption

#62
post #9
post #6

I give them, or anyone, credit for trying to create a secure messenger. It is not easy. However, I just wish they would release the source code to their clients and server. They have not. That would go a long way.

Both OTR (ChatSecure on your phone) and TextSecure are good options. Telegram is not a good option.

Doesn't TextSecure use some non-conventional cryptographic constructs, too?

It's just that I heard some concerns about key exchange (that triple Diffie-Hellman exchange) not having a formal security proof, although I'm completely incompetent to evaluate whenever those were valid concerns or just some chatter.

Re: $300k for Cracking Telegram Encryption

#63
post #9

Earlier quoted context omitted.

Both OTR (ChatSecure on your phone) and TextSecure are good options. Telegram is not a good option.

Unfortunately, those are not real alternatives to Telegram. Telegram is meant to be a WhatsApp replacement. WhatsApp thrives because in many places, SMS costs are prohibitive (so TextSecure is not an option). In addition, it requires no registration and doesn't rely on external services (so ChatSecure is also out of the question).

Then use WhatsApp!

Re: $300k for Cracking Telegram Encryption

#64
post #3

Obligatory: https://www.schneier.com/crypto-gram-9812.html $300,000 isn't a whole lot more than it would cost to get n entire novel cryptosystem for a complex application built out of idiosyncratic components assessed professionally. They should just retain Riscure or Rambus to do that for them instead of the PR stunt. Previous thread about Telegram on HN, featuring Moxie Marlinspike: https://news.ycombinator.com/ite…

Also relevant since the way the clients compare keys is sha-1: https://www.schneier.com/blog/archives/2012/10/when_will_we_... "211 * 28.4 = 219.4 ~ $700K by 2015" The cost of brute forcing the answer is greater than the prize for the contest. "This can happen if a security check is failed, or in the case that the first 128 bits of the SHA-1 of the newly created encryption key don‘t match on both parties’ clients whe…

So, given the contest would "succeed" (or "fail", depending on the viewpoint) with no one getting the prize, the only thing we could be more or less certain of, is that no one would likely consider cracking Telegram under given conditions for $300K in 2 months. Or maybe I'm missing something.

Re: $300k for Cracking Telegram Encryption

#65
post #9

Earlier quoted context omitted.

Both OTR (ChatSecure on your phone) and TextSecure are good options. Telegram is not a good option.

Doesn't TextSecure use some non-conventional cryptographic constructs, too? It's just that I heard some concerns about key exchange (that triple Diffie-Hellman exchange) not having a formal security proof, although I'm completely incompetent to evaluate whenever those were valid concerns or just some chatter.

Are you comparing the Axolotl key ratchet Trevor Perrin designed to the 1980s throwback block cipher mode Telegram uses?

Re: $300k for Cracking Telegram Encryption

#67
post #32
post #25

Earlier quoted context omitted.

and what else I can do with your bank account besides send you money?

You'd think nothing, but people have failed attempting to prove this before. > "But Clarkson admitted he was "wrong" after he discovered a reader had used the details to create a £500 direct debit to the charity Diabetes UK." http://news.bbc.co.uk/2/hi/7174760.stm

Though the Direct Debit guarantee gives an automatic right to a no-questions asked instant refund.

Not even having a provably validly signed mandate protects merchants against a refund (merchants recourse is small claims court), so while it's a nuisance, and while some people do get de-frauded by not paying attention to their statements, the article overstates things: If he "lost" money it'll be because he chose not to demand a refund.

Re: $300k for Cracking Telegram Encryption

#68

Earlier quoted context omitted.

Also relevant since the way the clients compare keys is sha-1: https://www.schneier.com/blog/archives/2012/10/when_will_we_... "211 * 28.4 = 219.4 ~ $700K by 2015" The cost of brute forcing the answer is greater than the prize for the contest. "This can happen if a security check is failed, or in the case that the first 128 bits of the SHA-1 of the newly created encryption key don‘t match on both parties’ clients whe…

So, given the contest would "succeed" (or "fail", depending on the viewpoint) with no one getting the prize, the only thing we could be more or less certain of, is that no one would likely consider cracking Telegram under given conditions for $300K in 2 months. Or maybe I'm missing something.

Yep. Unless there is a bug in the bot or their implementation isn't as described, no one will crack it so its a very safe bet for them.

This contest basically admits its crackable for more than $300k as well. They even reduced the number of bits for a collision. :/

Re: $300k for Cracking Telegram Encryption

#69
post #3

Obligatory: https://www.schneier.com/crypto-gram-9812.html $300,000 isn't a whole lot more than it would cost to get n entire novel cryptosystem for a complex application built out of idiosyncratic components assessed professionally. They should just retain Riscure or Rambus to do that for them instead of the PR stunt. Previous thread about Telegram on HN, featuring Moxie Marlinspike: https://news.ycombinator.com/ite…

See https://news.ycombinator.com/item?id=6931457 as well. > They should just retain Riscure or Rambus to do that for them instead of the PR stunt. I'd love to go back through either of the previous threads and count to see how many people were saying "well, if no one can successfully win the challenge, they can use the money for a security audit!" like they are right now . Telegram is pretty clearly a bad player that…

They use 128bits of a SHA-1 key in 2014. I'd say its pretty clear their security is a gimmick only.

https://konklone.com/post/why-google-is-hurrying-the-web-to-...

From the contest: "This can happen if a security check is failed, or in the case that the first 128 bits of the SHA-1 of the newly created encryption key don‘t match on both parties’ clients when this stage is completed (this corresponds to Paul and Nick comparing the key visualizations for the Secret Chat in their Telegram apps)."

Post reply on HN