Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

71–80 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#71
post #61
post #55

Does anyone have any inside info on this? If we don't assume malice, what is the reason Telegram is rolling its own non-standard crypto like this? Were there no widely publicized E2E protocols that would fit the bill at the time Telegram was being developed? (i.e. was it started before Signal had become known, or does that protocol have limitations that Telegram found unacceptable?) Or did the team have someone in ch…

No amount of effort to validate their protocol will make Telegram trustworthy. Telegram does not encrypt most conversations, you cannot compare it to Signal. In regards to actually validating the protocol, the OP addresses this >The current consensus seems to be that the latest version is not broken in known ways that are severe or relevant enough to affect end users, assuming the implementation is correct. That is a…

> Telegram does not encrypt most conversations, you cannot compare it to Signal.

I wish people will stop repeating this nonsense. Just because they don't do end to end encryption by default, doesn't mean they don't encrypt, which implies messages are sent in plaintext.

There are plenty of reasons why they did what they did, and these questions are all available publicly in their FAQ or the founder's Telegram channel. Whether you agree with the trade-off or their explanations is up to you, but facts are facts.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#72

Earlier quoted context omitted.

It looks a whole lot more likely to me that this is a backdoor, as they added their own thing to a very standard algorithm (the easy and better thing to do would have been to not add anything), and all that thing did was mess with the key exchange. It's really, really fishy.

But is it really that unlikely that it's a misguided attempt to increase entropy? The fact that a cryptographer might scoff and laugh at the proposition doesn't mean that a normal programmer couldn't fall victim to that illusion? In any case -- yes. Both things are likely and you made a strong point for the "malice" side. Still, it makes me wonder why would Durov run from Russia if he was willing to backdoor Telegram…

I don't think "people who design a cryptosystem" and "people who send randomness from the server" overlaps a lot, yeah. I don't see how anyone remotely familiar with cryptography would think that sending randomness from an untrusted party is a good idea. It's this bad.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#73
post #64

Earlier quoted context omitted.

I suppose I missed his sarcasm then. Happens pretty easily over text. As said in another comment, I am no cryptography expert. I simply argue against the very visible negative bias against Telegram which is accentuated even more by very childish snarks on almost any Telegram HN thread. That gets to me and it's not how HN should be. I never argued that my opinion is a fact. I said how I arrived at my opinion and debat…

Have you considered that perhaps Telegram deserves that negative bias due to their own behavior?

I would consider it... if I ever see any other criticism in HN besides "they don't have massively peer- and pro-reviewed encryption" and very childish snark with zero facts interspersed.

What's this "Telegram behaviour"? Seriously, enlighten me -- this is not a snark. I've been following HN Telegram threads for a long time and I've only seen the two things I mentioned above.

It's really puzzling, especially in a world where a ton of very public and everyday software has much more flaws than Telegram. The whole very directed and non-HN-esque hate towards it does stands out.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#74
post #10

It's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger. This blog post is far too charitable.

> It's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger.

It's still likely better than WeChat FB Messenger in terms of privacy. You just get to choose the devil, and some consider Russia no worse than Facebook (and all that it represents) or China.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#75
post #52

Earlier quoted context omitted.

> Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. Unless you have another interpretation of the Hanlon's Razor, it seems that he is saying this is a mistake and not a backdoor. > They shipped a backdoor. Did they? Might be. I am 50/50 about it, people do dumb mistakes with self-rolled crypto all the time and that's a sad reality. But who knows, it mi…

>Unless you have another interpretation of the Hanlon's Razor, it seems that he is saying this is a mistake and not a backdoor. It just sounds like the author simply doesn't want to get sued, after all it's generally impossible to prove that a backdoor is actually a backdoor. >people do dumb mistakes with self-rolled crypto all the time I've seen a plenty of those, this one just happens to look rather different than…

Well, sure. It's very possible indeed. I am still wondering why though -- Durov fled Russia, settled in UAE and then backdoored Telegram? Don't know. If a conspiracy becomes too complex then we all know what the other razor law says, right (Occam's)?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#76

Earlier quoted context omitted.

WhatsApps cloud backup on Android sits on Google drive by default. It is encrypted with a per user key known to WhatsApp. That means for a third party to access the chats, they need Google to hand over the data, and Facebook to hand over the key. The logical next step to add would be for Google to additionally encrypt the data with the users logon password or something derived from it. Google won't do this anytime so…

WhatsApp backups are a bit of an anti-feature, as I found out while trying to ditch the app after the recent policy update. 1) The backup can only be made to Google drive, you cannot create a manual backup to a location of your chosing 2) The backup is created in a secret folder that cannot be accessed by the user 3) The backup is deleted if you delete your account. (not much of a backup, eh?) 4) You can only create…

I can't find any source for this 12MB limit? Backups I've restored (Android) seen to contain all media although I haven't checked in detail.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#77
post #64

Earlier quoted context omitted.

Have you considered that perhaps Telegram deserves that negative bias due to their own behavior?

I would consider it... if I ever see any other criticism in HN besides "they don't have massively peer- and pro-reviewed encryption" and very childish snark with zero facts interspersed. What's this "Telegram behaviour"? Seriously, enlighten me -- this is not a snark. I've been following HN Telegram threads for a long time and I've only seen the two things I mentioned above. It's really puzzling, especially in a worl…

Telegram positions itself as a secure messenger but does not encrypt most conversations, that's simply dishonest on their part. Until they start to clearly communicate to their users that "Hey! This conversation is not encrypted" they deserve nothing but negativity.

Multiple official Telegram clients do not even support the "secret chats".

Right from their own website https://telegram.org/

>Private

>Telegram messages are heavily encrypted and can self-destruct.

This is a lie.

>Secure

>Telegram keeps your messages safe from hacker attacks.

This is a lie, you can even pull someones telegram message history by sim swapping them FFS.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#78

Earlier quoted context omitted.

Well, that's how probabilities work and I am not seeing your rephrasing as adding anything valuable to that discussion. Unless you put concrete % numbers on both sides then your replace is identical with the original.

Oh, please, this is not a math inequality where we compare with numbers. It is plain to any English speaker that what was written in the article and how you represented it differ significantly in the confidence that they communicate. As such, your continued insistence that there is no major difference between the two comes off as extremely poor faith.

You might be missing that many people here might not be native English speakers. As such, being crystal clear on what the author believes might be beneficial. Just putting "hey I might be wrong" in the end of an article is just word-padding and since I assumed the author doesn't do that, I entertain the possibility they mentioned seriously.

...Bad faith? Most of HN has bad faith when it comes to Telegram. This place devolves to Reddit / 9GAG levels of childishness when Telegram is mentioned.

I think that's quite fascinating and it's a strange outlier. Yes -- strange, as in "not justified". They did nothing more wrong than a ton of other, much more widely used software, yet any mention of Telegram on HN brings about a big bandwagon of haters. Why do you think that is?

Post reply on HN