Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

81–90 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#81

Earlier quoted context omitted.

But is it really that unlikely that it's a misguided attempt to increase entropy? The fact that a cryptographer might scoff and laugh at the proposition doesn't mean that a normal programmer couldn't fall victim to that illusion? In any case -- yes. Both things are likely and you made a strong point for the "malice" side. Still, it makes me wonder why would Durov run from Russia if he was willing to backdoor Telegram…

I don't think "people who design a cryptosystem" and "people who send randomness from the server" overlaps a lot, yeah. I don't see how anyone remotely familiar with cryptography would think that sending randomness from an untrusted party is a good idea. It's this bad.

Well, a bug I filed to Telegram eventually got closed on petty bureaucratic grounds (wrong repo but nobody moved the issue [I did copy it to the right repo], then X months without action etc.) so this might say something about the average competence and motivation of their technical staff. :)

Thanks for being one of the few to discuss constructively in this sub-thread. It's much appreciated.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#82

Earlier quoted context omitted.

From the article: > Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. How else would you interpret it?

Hanlon’s Razor says to never assume malice where stupidity suffices as an explanation. The only way I read this sentence is to say that Hanlon’s Razor applies here, in-spite of how malicious the bug looks.

Same for me. While others argue that it's "obvious" that the author believes much more strongly that this find is a backdoor and not a dumb mistake (a very easy one to make for a non-cryptographer programmer), I am still unconvinced.

Would be curious to read a statement from Telegram's team though -- not that any team would ever admit to putting a backdoor...

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#83
post #69
post #55

Does anyone have any inside info on this? If we don't assume malice, what is the reason Telegram is rolling its own non-standard crypto like this? Were there no widely publicized E2E protocols that would fit the bill at the time Telegram was being developed? (i.e. was it started before Signal had become known, or does that protocol have limitations that Telegram found unacceptable?) Or did the team have someone in ch…

If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…

They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. This was a time when WhatsApp was found using a plaintext protocol, and right after the Snowden revelations. They did move the needle a bit at the right time.

One of the most vocal critics was Moxie, who later founded Signal. It's ironic that 7 years after Snowden and Telegram, Signal the supposed more secure and privacy focused messaging app still has yet to gain any sizable foothold in the market. I think that says a lot about both Telegram and Signal's product strategies.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#84

Earlier quoted context omitted.

I don't think "people who design a cryptosystem" and "people who send randomness from the server" overlaps a lot, yeah. I don't see how anyone remotely familiar with cryptography would think that sending randomness from an untrusted party is a good idea. It's this bad.

Well, a bug I filed to Telegram eventually got closed on petty bureaucratic grounds (wrong repo but nobody moved the issue [I did copy it to the right repo], then X months without action etc.) so this might say something about the average competence and motivation of their technical staff. :) Thanks for being one of the few to discuss constructively in this sub-thread. It's much appreciated.

No problem, your reply did show that you wanted to discuss but was frustrated, so I just continued the discussion.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#85
post #69
post #55

Does anyone have any inside info on this? If we don't assume malice, what is the reason Telegram is rolling its own non-standard crypto like this? Were there no widely publicized E2E protocols that would fit the bill at the time Telegram was being developed? (i.e. was it started before Signal had become known, or does that protocol have limitations that Telegram found unacceptable?) Or did the team have someone in ch…

If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…

I think Textsecure[1], the predecessor of Signal, is even older (2010)

And Wikipeida also says that the first version of the Signal Protocol is from 2013[2]

[1] https://en.wikipedia.org/wiki/TextSecure [2] https://en.wikipedia.org/wiki/Signal_Protocol

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#86
post #71
post #61

Earlier quoted context omitted.

No amount of effort to validate their protocol will make Telegram trustworthy. Telegram does not encrypt most conversations, you cannot compare it to Signal. In regards to actually validating the protocol, the OP addresses this >The current consensus seems to be that the latest version is not broken in known ways that are severe or relevant enough to affect end users, assuming the implementation is correct. That is a…

> Telegram does not encrypt most conversations, you cannot compare it to Signal. I wish people will stop repeating this nonsense. Just because they don't do end to end encryption by default, doesn't mean they don't encrypt, which implies messages are sent in plaintext. There are plenty of reasons why they did what they did, and these questions are all available publicly in their FAQ or the founder's Telegram channel.…

Do you really consider an "encrypted conversation" if you just do TLS to a central server that has everything in plaintext? Is Facebook Messaging encrypted messaging? Because that's the kind of thing we already had before this wave of apps and Telegram is marketed within this new wave but doesn't have any more security than what the previous wave already had, even if you trust their homegrown protocol.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#87
post #33
post #30

One thing that always puzzled me about telegram was seeing maps being loaded from yandex when sharing locations with friends

I think it uses Google by default because Google Maps is the best in almost all regions. It gives you an option to change Maybe Yandex in Russia only?

For me it was using Yandex in Denmark

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#88

Earlier quoted context omitted.

WhatsApps cloud backup on Android sits on Google drive by default. It is encrypted with a per user key known to WhatsApp. That means for a third party to access the chats, they need Google to hand over the data, and Facebook to hand over the key. The logical next step to add would be for Google to additionally encrypt the data with the users logon password or something derived from it. Google won't do this anytime so…

WhatsApp backups are a bit of an anti-feature, as I found out while trying to ditch the app after the recent policy update. 1) The backup can only be made to Google drive, you cannot create a manual backup to a location of your chosing 2) The backup is created in a secret folder that cannot be accessed by the user 3) The backup is deleted if you delete your account. (not much of a backup, eh?) 4) You can only create…

WhatsApp also creates (encrypted) backups in the WhatsApp/Databases folder on your internal storage. Aside from a single line displaying the time of the last local backup in the backup settings it's not really well-documented though.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#89

Earlier quoted context omitted.

WhatsApp backups are a bit of an anti-feature, as I found out while trying to ditch the app after the recent policy update. 1) The backup can only be made to Google drive, you cannot create a manual backup to a location of your chosing 2) The backup is created in a secret folder that cannot be accessed by the user 3) The backup is deleted if you delete your account. (not much of a backup, eh?) 4) You can only create…

I can't find any source for this 12MB limit? Backups I've restored (Android) seen to contain all media although I haven't checked in detail.

That point was talking about the "Export Chat" function (which creates a medialess text file), not the backup function.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#90
post #77

Earlier quoted context omitted.

I would consider it... if I ever see any other criticism in HN besides "they don't have massively peer- and pro-reviewed encryption" and very childish snark with zero facts interspersed. What's this "Telegram behaviour"? Seriously, enlighten me -- this is not a snark. I've been following HN Telegram threads for a long time and I've only seen the two things I mentioned above. It's really puzzling, especially in a worl…

Telegram positions itself as a secure messenger but does not encrypt most conversations, that's simply dishonest on their part. Until they start to clearly communicate to their users that "Hey! This conversation is not encrypted" they deserve nothing but negativity. Multiple official Telegram clients do not even support the "secret chats". Right from their own website https://telegram.org/ >Private >Telegram messages…

As far as being able to put a timer on a message and see it disappear for both sides, how do you know that the "self-destructing" messages claim is a lie? Genuinely curious, I am likely missing something.

> This is a lie, you can even pull someones telegram message history by sim swapping them FFS.

Well, the mobile telecoms still have no solution for SIM swapping and most software uses SIMs as a way to uniquely identify users. I've heard of -- and used -- messengers like Signal and Matrix and the added inconvenience for not using a SIM is definitely off-putting even for me as a techie. So I can't blame Telegram or any other app for using SIM identification -- it's flawed, that's well-known in the tech community, but I suppose somebody made the call to risk this because they wanted adoption and didn't want to make onboarding too hard?

---

I can agree on a generally somewhat misleading marketing being a reason for negativity. Even a functioning backdoor might still mean that messages are safe from most hacker attacks though; the backdoor is only used on demand (it's infeasible to use it all the time, that would take too much server resources and would put the onus on the eavesdroppers to provide extra infrastructure I think?) and the unencrypted data is served to whoever asked for it behind closed doors. That does not mean that any hacker can get their hands on it though, right?

But even a somewhat misleading marketing can't explain the violent reaction of most of HN when Telegram is mentioned -- at least it can't explain it to me. There's so much popular and very shady software out there and somehow Telegram eats all the flak while many other software packages receive very generous benefits of the doubt.

Post reply on HN