He found a flaw, they fixed it. The flaw itself is of a kind common to a home-brewed crypto and it was lying on a surface. Saying that Telegram made this mistake on purpose is, if you pardon my French, making shit up.
He found a flaw, they fixed it. The flaw itself is of a kind common to a home-brewed crypto and it was lying on a surface. Saying that Telegram made this mistake on purpose is, if you pardon my French, making shit up.
Yes, they fixed it.
No, you can’t accidentally write code that pulls DH nonces from your server.
>The flaw itself is of a kind common to a home-brewed crypto
You can’t say things like this and then proceed to accuse others of making up shit.
Telegram doesn't have reproducible builds, do they? So if they really wanted to fuck people over, all they had to do is to ship a build that uses predictable PRNG. The vast majority of users will use vendor-supplied binaries, so chances are that for any pair of peers you will be able to fully recover all their secrets and eavesdrop on the traffic. You don't even have to be Telegram to do that. In fact, this works against any protocol... unless client binaries are routinely audited and matched against their source, which is never the case with any of the clients. The only example I am aware of was Zimmerman's PGPfone back in mid-90s.
So, yes, I think that you are seeing things that are not there and it's yet another case of stupidity rather than malice on part of Telegram's devs.
This doesn't really matter that much, the source code isn't very helpful while auditing a RNG.
Most of the time Telegram doesn't even encrypt conversations, yet this is their main selling point.
>So, yes, I think that you are seeing things that are not there and it's yet another case of stupidity rather than malice on part of Telegram's devs.
No. I just don't think it matters whether this was stupidity or malice, sufficiently advanced stupidity is indistinguishable from malice. This was not your typical crypto fail. You suggested that this is a common kind of error, can you point at someone else that did this?
I think it's fair to assume malice in the case of Telegram, their "secure encrypted messaging" application still doesn't even encrypt most conversations.