This is an interesting line from the github readme. And I applaud for being humble. This is something which seemed lacking when I read about dapps (etherium) -- people rarely talked about having low trust on contracts written by somebody else.
This is an interesting line from the github readme. And I applaud for being humble. This is something which seemed lacking when I read about dapps (etherium) -- people rarely talked about having low trust on contracts written by somebody else.
Ricochet was audited in 2016: https://twitter.com/torproject/status/699668346921332737
And since then things have moved forward only very slowly, but I do not see this as a sign of the project being abandoned more like that there aren't enough people to maintain it.
FWIW the @torproject still endorses ricochet for now: https://twitter.com/torproject/status/1073322441836036096
(Though perhaps @torproject meant to link to this Ricochet IM product and not @Ricochet...?)
But yes looks like the tweet is @ the wrong account.
Can you provide more context about this, or somewhere I can read about this please? Very curious.
If more than 1 person knows something it's no longer a secret. Likewise if 2 people know about the existence of a 0day it's no longer a 0day.
...
Why should I burn a 0day? Who will pay me for it? I'm not stupid and I don't participate in the responsible disclosure circle jerk.
TG is snakeoil: If you use it for anything more serious than hiding an affair from your spouse high chance you get burnt. Especially wanna be terrorists ought to stay clear.
TG is one giant weird machine: You'll notice quickly if you play with it. There very likely many 0days in TG and for sure LE has access to it too. So finding something isn't even a statistical outlier.
People who think that responsible disclosure must be practiced are just parroting the corporate bullshit. Bug bounties hunters are the Uber drivers of InfoSec. Poor fuckers that are pressed into a system that only benefits the corporate overlords. How about starting with responsible QA instead of moving fast & breaking things?
Either it's pertinent information to be entered into the public record as part of your comment, or it's not.
If it's pertinent information you don't get to say "trust me", you have the responsibility to provide information.
If you cannot do that, then do not say it. You will not convince me with mealy mouthed weasel words.
--
On a more personal note: this comment sounds like the kind of thing I would see on skiddie hacker forums 15 years ago. Please conduct yourself better.
I did not use "responsible disclosure" as commonly defined (apologies for any confusion), simply because I do not think that telling only the creator of the program is responsible - instead I asked you to try and consider disclosing the issue responsibly by making it public to everyone (rather than just Telegram). I consider a disclosure responsible only if both the users and any developers (including these of any forks) are aware of the issue at the same time. I do not think that the way that I personally used the term "responsible" is in any way "corporate bullshit", after all the corporations tend to ask to be the only ones (or the first ones) to learn about the issue.
Please substantiate your claim or don’t make it.
Everytime instant messaging gets talked about here someone has to bring up how unsecure telegram is. Like someone doesn't want people to use telegram...
Unless you can show me a proof of concept, stop already.
a bit rich from a dweeb that retweets Wikileaks conspiracy theories don't you think?
https://gitlab.com/edu4rdshl/blog/raw/master/why-telegram-is...
"However, our survey shows that Telegram has had serious and simple
issues in the protocol (e.g. modified buggy Diffie-Hellman key exchange)
that any knowledgeable security expert could penetrate.
By using the command line interface of Telegram we have been able to
snoop on some of our friends and detect the times when they were conversing
to each other. We believe that this is a serious privacy issue, because it
can be exploited to detect relationships in classroom for example."
see https://courses.csail.mit.edu/6.857/2017/project/19.pdfThis has nothing to do with the security of the protocol.