Live data from Hacker News

$300k for Cracking Telegram Encryption

telegram.org

71–80 of 94 posts

Re: $300k for Cracking Telegram Encryption

#71
post #3

Obligatory: https://www.schneier.com/crypto-gram-9812.html $300,000 isn't a whole lot more than it would cost to get n entire novel cryptosystem for a complex application built out of idiosyncratic components assessed professionally. They should just retain Riscure or Rambus to do that for them instead of the PR stunt. Previous thread about Telegram on HN, featuring Moxie Marlinspike: https://news.ycombinator.com/ite…

It's fairly obvious that Telegram enjoys the challenge of designing their own crypto. The chances of them outsourcing the design are zero, because it will simply kill all the fun.

That's not too dissimilar to suggesting hiring an ISO-certified shop to redo your beautiful hand-optimized assembly code in an industry-standard Java. It's a simplification, but I'm pretty sure a large chunk of HN can relate to how much of a killjoy letting others do the interesting parts is.

In the end all these not-so-subtle backstabs and innuendos that they are just a bunch of annoying f#cking amateurs is counter-productive. They won't be using SSL and $300K is not enough to run their custom crypto through an audit that will be good for all the "experts". Besides, the main issue with the Telegram is not their crypto, is not the contests, it's the fact that they got off the wrong foot with the public applied crypto community. In theory, they should be fixing that, but in reality they don't seem to give a flying f#ck about it, which to me actually looks more like a show of a backbone rather than of an ignorance.

Ultimately they want the same thing as this Moxie person. They want less surveillance. Now pray tell why they should have their head repeatedly dunk in a toilet bowl every time their project gets a mention?

Re: $300k for Cracking Telegram Encryption

#72
post #38

When I see contests like this, my first thought always goes to "But do they really have the money to pay me if I figured it out." For big prize payout contests, I'd get a lot more serious if they provided proof that the funds were waiting in escrow until end-date/winner. But I'm probably unnecessarily suspicious of the depth of a startup's pockets...

Even ignoring that $300k isn't that much for most companies, there's insurance for big prize payouts where you'd pay the expected % time you'd have to pay out times the prize amount, plus a vig for the insurance provider.

Re: $300k for Cracking Telegram Encryption

#73
post #63

Earlier quoted context omitted.

Unfortunately, those are not real alternatives to Telegram. Telegram is meant to be a WhatsApp replacement. WhatsApp thrives because in many places, SMS costs are prohibitive (so TextSecure is not an option). In addition, it requires no registration and doesn't rely on external services (so ChatSecure is also out of the question).

Then use WhatsApp!

Telegram allows you to use the same account on multiple devices, which is the main reason why I use it. It's also independent of Facebook, which many people don't trust.

Re: $300k for Cracking Telegram Encryption

#74
If no one wins the contest, it proves nothing.

But contests like this are a bad idea for another reason: people will hoard bugs instead of disclose, sometimes for years. For example, the Pwn2Own contest boosted the discovery and disclosure of bugs in browsers for the first few years, but now companies have co-opted it into a marketing event. They sit on exploits in order to win two or three years from now.

I noticed a bug in one of the Telegram clients when the first contest was announced, but it wouldn't have qualified. Now the reward has tripled, and the scope expanded. As the user base grows, the reward will go up again (and again), and I'm sure no one will claim the bug since real experts have better things to do, so maybe it's smart to wait, maybe not...

Telegram, and other projects thinking of doing this: think small. In the lottery model, there is one big winner; you should prefer a model with many (smaller) winners. Pay for patches that improve the quality of the code base, fix compiler warnings, improve documentation, etc. Many grains of sand will sink a ship.

Re: $300k for Cracking Telegram Encryption

#75
post #65

Earlier quoted context omitted.

Doesn't TextSecure use some non-conventional cryptographic constructs, too? It's just that I heard some concerns about key exchange (that triple Diffie-Hellman exchange) not having a formal security proof, although I'm completely incompetent to evaluate whenever those were valid concerns or just some chatter.

Are you comparing the Axolotl key ratchet Trevor Perrin designed to the 1980s throwback block cipher mode Telegram uses?

Yes and no.

I have no idea whenever and how broken IGE is. I heard, nobody even cared to evaluate that. Boils down to "no formal proofs (but likely to be broken)".

At the same time, I heard the concern there are no security proofs on the key exchange and it may have issues. Since as a commoner I can't evaluate it any further than this, so boils down to "no formal proofs (although hoped to be fine)", too.

Those are surely different cases. I'm just concerned over what I use (TextSecure), though.

Re: $300k for Cracking Telegram Encryption

#76
post #65

Earlier quoted context omitted.

Are you comparing the Axolotl key ratchet Trevor Perrin designed to the 1980s throwback block cipher mode Telegram uses?

Yes and no. I have no idea whenever and how broken IGE is. I heard, nobody even cared to evaluate that. Boils down to "no formal proofs (but likely to be broken)". At the same time, I heard the concern there are no security proofs on the key exchange and it may have issues. Since as a commoner I can't evaluate it any further than this, so boils down to "no formal proofs (although hoped to be fine)", too. Those are su…

If it makes you feel any better, after the paper published last week, it looks like TextSecure is the closest of all the messaging applications to any kind of formal proof.

Re: $300k for Cracking Telegram Encryption

#77
The comments here are showing me that this contest is a good idea, because everyone is talking about Telegram. It doesn't matter that they're mostly saying they don't trust it. Without the contest, most people wouldn't even have heard of this app in the first place.

Re: $300k for Cracking Telegram Encryption

#78
post #3

Obligatory: https://www.schneier.com/crypto-gram-9812.html $300,000 isn't a whole lot more than it would cost to get n entire novel cryptosystem for a complex application built out of idiosyncratic components assessed professionally. They should just retain Riscure or Rambus to do that for them instead of the PR stunt. Previous thread about Telegram on HN, featuring Moxie Marlinspike: https://news.ycombinator.com/ite…

It's fairly obvious that Telegram enjoys the challenge of designing their own crypto. The chances of them outsourcing the design are zero, because it will simply kill all the fun. That's not too dissimilar to suggesting hiring an ISO-certified shop to redo your beautiful hand-optimized assembly code in an industry-standard Java. It's a simplification, but I'm pretty sure a large chunk of HN can relate to how much of…

> It's fairly obvious that Telegram enjoys the challenge of designing their own crypto. The chances of them outsourcing the design are zero, because it will simply kill all the fun.

Great! I like to scribble out sponge functions while eating lunch. I've made a few toy stream ciphers. Crypto is fun as all hell, and it's a great way to learn things!

But novelty isn't really a good thing when it comes to actually depending on crypto. You want something that's been well studied by lots of smart people. To paraphrase Schneier (I believe), anyone can design an encryption process that they can't break - the real challenge is keeping the people who are smarter than you from breaking it as well.

Novelty is an _extremely_ bad reason to design and deploy cryptography.

> They want less surveillance. Now pray tell why they should have their head repeatedly dunk in a toilet bowl every time their project gets a mention?

Because the applied crypto community points out issue after issue after issue with their product and is met with variations of "nuh uh, it's fine!"

Bad crypto is worse than no crypto because either way the NSA is watching you, but when you use no crypto you're at least forced to admit to yourself that your adversary has you in their crosshairs.

Re: $300k for Cracking Telegram Encryption

#79
I have different opinions about Telegram.

I like how Telegram is truly cross-platform with the clients being open source and available on every platform. They usually look great and are simple to use, which is why Telegram is the only non-whatsapp IM that more than 3 of my contacts use. It also works with multiple devices connected*, which is another pro against many other IMs.

What I dislike is that even though Telegram advertises their messages as "private" and "heavily encrypted" on their landing page, secure chats are NOT the default, do not work in group chats and do not work across multiple devices. I am aware that this requires encryption for every recipient, but that shouldn't be an issue. TextSecure actually came up with a great solution [1] for this. What I also do not understand is why they are rolling their own crypto. They say it's for speed and stability [2], but don't provide any facts or measures. The fact that the server is closed source and the founders coming from VK (a russian Facebook alternative) doesn't make this any better.

All in all I consider Telegram a great alternative to WhatsApp, but I wouldn't rely on it for secure messaging.

1: https://whispersystems.org/blog/private-groups/

2: https://core.telegram.org/techfaq#q-why-are-you-not-using-x-...

Re: $300k for Cracking Telegram Encryption

#80

The comments here are showing me that this contest is a good idea, because everyone is talking about Telegram. It doesn't matter that they're mostly saying they don't trust it. Without the contest, most people wouldn't even have heard of this app in the first place.

It's worth noting that the contest caused people here to talk about how Telegram's model of security and their approach to testing that security have flaws.

But as is shown by the fact that they are running this contest, plenty of people who are not here see the contest and believe it is an indication of the trust they should have in Telegram. Otherwise, they wouldn't have run another contest after the response on HN to the last one.

The contest is a bad idea because for the people who don't see our discussion here, they will be tempted to trust their sensitive data to Telegram. For lots of people around the world, that trust could put them at risk of serious harm.

Post reply on HN