The most backdoor-looking bug I've ever seen (2021)
words.filippo.io
words.filippo.io
It’s really a showcase of how very high IQ and outstanding mathematical abilities mix with a distrust of existing technologies and a lack of expert intuition coming from more normal industry experience.
Just try implementing MTProto, or at least read the low-level docs, and you’ll see for yourself. Crypto isn’t the weirdest part. The whole thing is an attempt to define a binary protocol in terms of grandiose mathematical concepts most of which didn’t even end up ever used in the actual protocol. And there’s zero thought given to what’s actually important, making a bullet-proof syncing between server and client states (and that results in numerous bugs to this day).
Can’t discount malice, but I don’t believe that’s the case.
I assumed that after a few years and some success, Telegram would get more serious about this and replace its crypto with something better (maybe Signal protocol) in the same way that WhatsApp did. I also thought they'd eventually back up their privacy claims by deploying default end-to-end encryption for non-broadcast chats. After all that's the trend everywhere: even Facebook Messenger is now encrypted! But Telegram never, ever did this. They kept on making loud claims to be a privacy-preserving messenger, but they never added real privacy.
The most backdoor-looking bug I’ve ever seen (2021) - https://news.ycombinator.com/item?id=30013192 - Jan 2022 (77 comments)
Discussed at the time:
The Most Backdoor-Looking Bug I’ve Ever Seen - https://news.ycombinator.com/item?id=25726068 - Jan 2021 (208 comments)
Cryptography Dispatches: The Most Backdoor-Looking Bug I’ve Ever Seen - https://news.ycombinator.com/item?id=25721990 - Jan 2021 (1 comment)
Technically I try to boycott everything with too strong of a connection to any of the so-called CRINK nations (ie. China, Russia, Iran, North Korea.) Its hard to enforce it perfectly. But where its easy enough for me to do, I do.
The only chats that use their e2ee protocol are the ones that use the secret chat functionality which almost no one uses.
The whole fucking thing should die in a fire.
I was responding to this. But in most cases people will end up using the things that their communities use. I don't care much for reddit yet I am on reddit almost every day
Discord has that whole thing with "servers" (should really be called communities) and I found it a little complicated for that use case.
Discord itself calls them "guilds" internally. :)
Well, not everything. I dream of a world where Signal forks the UI layer from Telegram and then just does their thing.
(Who knows, the chat input might just finally focus when I tab back to the fucking window if they do that.)
1. It does not support end-to-end-encrypted (E2EE) group chat at all.
2. It does not enable E2EE chat by default.
3. "Secret Chat" (the only E2EE encrypted chat) experience is deliberated nerfed, it's not available on PC / Web and can only be initiated with a buried-in-dot-menu option in phone ap.
4. It had multiple weird 0-click attack surface in the past. [0]
In addition, Telegram always prefers usability over privacy, it does not do tradeoff, more like 100% usability 0% privacy. Users like this, but I don't know what to think about it.
[0] Signal isn't any better on this though, they refused to add an option to disable their video/audio call stack for those who don't use it to do attack-surface reduction.
Seems like a red flag.
This wasn't a shortcut, they added extra complexity to to the protocol.
"nonce was there to protect clients with weak random number generators. "
This is such a basic cryptographic fail that one has to assume either the telegram team is incompetent or they were introducing a backdoor. Given that the excuse is so weak, one tends to assume the latter. I get rolling one's one crypto is hard, but this is a such an easily caught fundamental error that those are the options, and neither is good.
See Durov’s (Telegram founder) recent announcement regarding Signal.
> A story shared by Jack Dorsey, the founder of Twitter, uncovered that the current leaders of Signal, an allegedly “secure” messaging app, are activists used by the US state department for regime change abroad
> Unlike Telegram, Signal doesn’t allow researchers to make sure that their GitHub code is the same code that is used in the Signal app run on users’ iPhones. Signal refused to add reproducible builds for iOS, closing a GitHub request from the community. And WhatsApp doesn’t even publish the code of its apps, so all their talk about “privacy” is an even more obvious circus trick .
I don't use either but if the article isn't completely made up this does at least look super incompetent and not just like picking on random things about the other messenger.
If you want to suggest this is an improper "press war" hit piece you need a lot more to back that up.
MTProto is weird and countless choices made in its design are bizarre with no clear rationale. Throwing in confusing and cryptographically unnecessary steps with thin rationalizations is par for the course.
Its authors have specifically chosen an approach that all but guarantees lots of “innocent mistakes”.
> This is the story of a bug…
I don’t really understand why pointing any of these things out would be relevant, but sure.
The article is not a scientific paper, but even in those, if you know how to read them, you’ll find authors saying “this is very weird”, albeit in different words.
That argument seems like false balance.
One of the two is peer-reviewed and is participating in productive exchange with academic industry security specialists; the other is reinventing the wheel and tapering over the numerous resulting red flags with a huge marketing budget.
Their respective public statements simply do not have the same weight.
> Unlike Telegram, Signal doesn’t allow researchers to make sure that their GitHub code is the same code that is used in the Signal app run on users’ iPhones
This is technically impossible on iOS due to its app distribution model. If Telegram claims anything else, that’s concerning.
Signal is a very open company and the protocol has had extensive scrutiny, and has a history of making good choices, like minimising the data they hold and defaulting to E2EE, as well as being hated by approximately all governments.
Telegram is extremely opaque, deliberately conflates various security things, doesn't default to encrypting anything, doesn't support encrypted group chats, has been hacked several times, and is extremely tolerated by very repressive regimes.