> people are looking to block it instead of silently explore its flaws
This is not a good heuristic for determining if security failures are "purported."
In point of fact, Telegram is widely lampooned by every self-respecting professional cryptographer who has written about it. There's nothing "purported" about Telegram's security failures - they are empirically demonstrable, and have been exposed through multiple cryptanalytic reviews.[1][2]
Frankly, I don't think I've ever seen anyone defend Telegram here on HN who actually has professional crypto experience (whether academia or industry), or any other similar proxy for credibility in the field. The popular contention is that (poor, harmless) Telegram is plagued by a persistent astroturfing campaign perpetrated by the likes of Moxie Marlinspike and Thomas Ptacek in order to elevate Signal's status. That's:
1) not true, in my opinion (though to be fair at least one of those people is obviously biased); and
2) irrelevant, because we have the benefit of empirical rigor to instruct our opinions of secure messaging systems. We don't need to rely on infosec ideologues on HN or Twitter.
Telegram is very much like climate change. There is a widespread consensus among the informed (read: academic and professional cryptographers) that Telegram's security failures exist, and that these failures are empirically demonstrable. At the same time, there is a controversy led almost entirely by the uninformed (read: non-cryptographers) that denies Telegram's security failures and undermines attempts at demonstrating them through accusations of shilling or misdirection.
To put it very succinctly: there are no valid arguments that Telegram has an optimal security model from the perspective of cryptanalysis and cryptographic design best practices.
____________________________________________________________
1. https://www.alexrad.me/discourse/a-264-attack-on-telegram-an...
- Using some kind of crypto with multiple keys
- These keys are located in multiple independent datacenters in independent jurisdictions
According to what I read this was supposed prevent leaking of user data just by bribing/coercing/etc or suing any Telegram employee or datacenter provider.
As I've mentioned before I don't use Telegram for security, I use it because
1. Facebook failed its Whatsapp acquisition so badly
2. It is way more user friendly
Also keep in mind that when I left WhatsApp for Telegram WhatsApp still didn't have e2e.
Telegram has some well known theoretical security flaws - its been well documented as such.
But from a practical point its more secure than most of what it replaced - SMS and Facebook Messenger. I use telegram as a cross platform iMessage - if iMessage was cross platform there wouldnt be much room for for telegram - if WhatsApp had a desktop client, same deal - if Signal was more user friendly (it also launched without a desktop client) - same deal.
In short, Telegram is good enough for the purposes that people are using it for - once MProto has been breached - then I'll be concerned - but right not all the attacks are theoretical, and not practical.
There's not a single actual practical vulnerability in the second paper. http://telegra.ph/mtproto-security-01-17
And the first one is outdated.
http://www.reuters.com/article/us-iran-cyber-telegram-exclus...
People have written academic papers about how bad Telegram's underlying crypto is.
Can't do it? That must mean there are no exploits for Firefox.
There are qualified security research teams that develop targeted exploit implementations for exotic and very impactful vulnerabilities. They do not need (or want) to publish the exploits because a) that's a valuable product and intellectual property and b) turnkey weaponization reduces the half life of the vulnerabilities (and therefore income potential).
The people who publish exploit implementations generally do so because they have no interest in seeing the vulnerability flourish and because they would rather have industry fame than a short term payday. If you want to improve your credibility in the security industry, identifying high-impact security vulnerabilities (i.e. CVE worthy) is enough. If you want to earn money by dealing in vulnerabilities, you generally want to develop exploits for them (or give them away for relative pennies on the dollar).
This is a roundabout way of saying that the absence of easily available exploits does not mean that software is secure. On the contrary, it could be an extremely high value target. There are different incentives at play - on one hand, merely releasing details of a vulnerability is enough for recognition, while the most lucrative payments go to weaponized vulnerabilities.
If I were to, say, identify a series of two or three vulnerabilities that can be theoretically chained to achieve remote code execution on an iOS device, I could do one of two things with that. I could report it to Apple and receive up to $200k, per their recently developed disclosure program. I could also sell this for 2 - 5 times that much with a complete exploit. The first option is a great payday and comes with (effectively) never needing to interview again. The second option results in a much better payday (life-changing, perhaps) with essentially no recognition.
If you can consistently churn those out, the second option is probably better if you're optimizing for wealth. But realistically speaking neither party is exceptionally incentivized to publish an exploit that you could just find and download.
Just because others are also vulnerable to the same failings doesn't absolve Telegram of responsibility. Don't claim to be a secure platform if your security is easily circumvented.
Also by default Telegram sends confirmation messages to previously verified clients instead of by sms.
Secure messaging is hard, most people when producing secure messaging will produce poor secure messaging - it doesn't mean they've been compromised by a government.
It's one thing to get some security wrong because its "hard." It's another to not fix those problems when people explain how and why you did something wrong.
RSA encryption is theoretically breakable by quantum computers, but people still use it and gonna be using it until someone break it.
When private firms hand over data or introduce backdoors on behalf of their gov't, the gov't now has political cover and it's easy to make the bad guy the firm the bad guy.
"We just asked for the data, and they complied." v. "We came, We saw, We stole your data"