Live data from Hacker News

Crowdsourcing a More Secure Future

telegram.org

81–90 of 95 posts

Re: Crowdsourcing a More Secure Future

#81
post #34

Earlier quoted context omitted.

It's an impressive sum of money. Have you considered they're doing this for marketing purposes, not out of concern for people's security?

So what? They're still doing it. Unless it turned out they'd set the whole thing up, which would be different.

With respect, I think what you are suggesting would only complicate the evaluation of this complex situation. Dropping relevant context and focusing only on a specific action is not the way to reach a rational conclusion.

In my view, we must integrate this action on the part of Telegram with all of the other things we know about the situation. That's a tall order, because it means integrating this specific action (paying the $100K) with many other topics, such as the various people making claims, their expertise and possible motivations, computer cryptography and computer security, strategies that companies sometimes use to gain access to personal information, the dangers posed by weak cryptography, etc.

Only when all of the facts square with each other will we have a rational basis for trusting Telegram Messenger and the people behind it.

Re: Crowdsourcing a More Secure Future

#82
Q: How are you going to make money out of this?

We believe in fast and secure messaging that is also 100% free. Therefore Telegram is not a commercial project. It is not intended to sell ads, bring revenue or accept outside investment.

If Telegram runs out of money, we'll invite our users to donate or add non-essential paid options.

Yeah, but where does there money come from?

Re: Crowdsourcing a More Secure Future

#83
post #82

Q: How are you going to make money out of this? We believe in fast and secure messaging that is also 100% free. Therefore Telegram is not a commercial project. It is not intended to sell ads, bring revenue or accept outside investment. If Telegram runs out of money, we'll invite our users to donate or add non-essential paid options. Yeah, but where does there money come from?

Pavel Durov[1]. Net worth $260MM[2].

[1] http://telegram.org/faq#q-who-are-the-people-behind-telegram [2] http://en.wikipedia.org/wiki/Pavel_Durov

Re: Crowdsourcing a More Secure Future

#84
post #81
post #34

Earlier quoted context omitted.

So what? They're still doing it. Unless it turned out they'd set the whole thing up, which would be different.

With respect, I think what you are suggesting would only complicate the evaluation of this complex situation. Dropping relevant context and focusing only on a specific action is not the way to reach a rational conclusion. In my view, we must integrate this action on the part of Telegram with all of the other things we know about the situation. That's a tall order, because it means integrating this specific action (pa…

Don't get me wrong, I lean towards the "Telegram's security is a joke and the contest is even more so" camp. I was commenting solely on the specific issue: that if someone uncovers a flaw in your software and you pay out in order to get some good publicity, the fact remains that you've still done a good thing by paying out.

Re: Crowdsourcing a More Secure Future

#85

What I don't understand is: where do they get the money from if their intention is to be "free forever"? Are they funded by a non-profit incubator? Why is it that a "new" app spends relatively much money on white-hat hacking bonuses? What do they get out of this other than a deemed secure application?

[deleted]

Re: Crowdsourcing a More Secure Future

#86

Good for Telegram. I haven't downloaded and installed their App yet, but I applaud their effort at putting out a secure chat app that everyone can use. I've been using TextSecure for a while (as everyone on HN ruthlessly suggests) but guess how many encrypted texts I've sent? 0. That's because they have no iOS app and very few Android users. There are two problems when it comes to creating a good, secure messaging ap…

I applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.

I suspect that many students of the Matasano Crypto Challenge would have caught this bug.

Re: Crowdsourcing a More Secure Future

#87

Earlier quoted context omitted.

Investing heavily is meaningless if you're investing badly. Building an encrypted IM service with bad crypto is like investing in blacksmiths in the early 1900s.

The question whether their Crypto is bad is still out IMO - these recent findings still don't seem to be that big of a deal to me - as with all other IM services I have to trust the service provider for their integrity - yet here I have an alternative provided by a non-profit organization with some scientific credentials that offer an open API - as opposed to Skype, WhatsApp, Facebook et al. We currently use Skype fo…

> provided by a non-profit organization

huh?

Re: Crowdsourcing a More Secure Future

#88
post #70

Earlier quoted context omitted.

> precisely because they show how willing they are to improve their service. Multiple people that know what they are doing have remarked that the system Telegram has created is a bad idea and it would be much better to use any established protocol. They have also pointed out multiple places where Telegram is committing obvious cryptographic blunders in their protocol. Telegram decided to pay out $100k under contest r…

> They have also pointed out multiple places where Telegram is committing obvious cryptographic blunders in their protocol. They have pointed out multiple places where Telegram MAY BE committing blunders, namely their internal server - server communication MIGHT be susceptible to MITM attacks. It's not the same thing.

Step 1 in security: Assume that every connection is untrusted. Now think of their model; does it hold up in that situation?

Re: Crowdsourcing a More Secure Future

#89

Good for Telegram. I haven't downloaded and installed their App yet, but I applaud their effort at putting out a secure chat app that everyone can use. I've been using TextSecure for a while (as everyone on HN ruthlessly suggests) but guess how many encrypted texts I've sent? 0. That's because they have no iOS app and very few Android users. There are two problems when it comes to creating a good, secure messaging ap…

Just fyi - last week Cyanogenmod started pushing out WhisperPush/Textsecure to Cm11(kitkat). I now have whisperpush by default on my phone.

Considering that they just raised 28mil and that CM is pretty much defacto for older androids, there is a very good chance that this might work.

Re: Crowdsourcing a More Secure Future

#90
post #68

Slightly off-topic, but here it goes: I always get a bit annoyed when apps use the phone number as the primary identifier. As somebody that just moved to another country, I now end up with a situation where I can either decide to lose my German whatsapp friends or not being discovered by my American whatsapp friends. I would love to see the ability to get some sort of ID number and then being able to register more th…

I read somewhere that moxie is planning that feature for TextSecure.
Post reply on HN