The Fallacy of Cracking Contests (1998)
schneier.com
schneier.com
If it's mistaken or isn't comprehensive enough, then I'd be relieved if you'd correct it.
It seems like the best possible thing they could do is to hire Matasano to fly out and dig through their whole architecture for flaws. That way they'd either earn tacit approval from the crypto community, or any obvious internal oversights would be exposed (in which case fixing those errors would earn them approval anyway). This contest doesn't seem to achieve those ends.
The message they've been sending is, "We're Telegram, and we're confident we don't need your help." But resisting the ability of governments to rifle through our data must be a community effort to succeed. Telegram is claiming to be a trustworthy hero. But individual heroes are single points of failure, and have historically been far too easy to coerce or circumvent.
There's also nothing stopping Telegram from being malicious (or being coerced), so I'm worried people won't notice if Telegram themselves try to snoop on everyone's messages by e.g. pushing an update which tweaks the protocol just slightly enough to be exploitable. Whereas if TextSecure tried to pull something like that, people would notice.
Of course, since Telegram refuses to give a proof for the security of their home-grown KDF, it seems like it's possible they designed it to be exploitable in some secret way, in order to access people's conversations. A security proof would prevent this possibility, but they don't seem to think it's a big deal. https://news.ycombinator.com/item?id=6918907
In fact, they've been bizarrely evasive on that point. Why design your own KDF? Speed? Then why not use a secure tunable KDF like scrypt? Is it to show off their own genius? Then why haven't they published it for peer review to take credit for their achievement? And why turn down Moxie's offer to join forces and incorporate an existing 10 million userbase? https://news.ycombinator.com/item?id=6915741 ... None of that makes sense, and the only reasonable explanation I can think of is that maybe they're trying something sneaky.
Well, if their own marketing spiel is to be believed, and all the work was done by Mathematicians instead of cryptographers, it's understandable that they'd go and behave like they have. Not out of malice, but ignorance of the accepted practices and modes of behavior that the crypto-community has adopted...often for very good reasons.
Their app is already more popular than TextSecure[1][2] and available for more platforms. Why in the world they should all of a sudden change protocol (and probably lose some features, lose control over changes in the protocol, etc.) and join to a less popular network?
[1] http://www.appannie.com/apps/google-play/app/org.telegram.me...
[2] http://www.appannie.com/apps/google-play/app/org.thoughtcrim...
Is this a well-understood part of these kinds of programs? Even the ones that say "color inside these lines" can be used to say, "Oh, sorry, I didn't know I was outside of the boundaries" if a person ever gets caught trying to get into a bad place.
So you've got all kinds of logs of me trying to break into your system, but as long as I fail I can just pretend like I was going after the bounty you've placed, right?
I'm trying, but failing, to find a recent article about a guy who found a password in a dropbox for another company that had a "hack us" contest, and subsequently was indirectly accused of potentially illegal conduct (they settled on sending him a shirt instead of money).
These are still new enough that a person could mask any legitimate hacking attempts in the guise of "I didn't know I couldn't do that". So you get to be as malicious as you'd like, and no one's going to come after you, lest an Internet mob forms or something.
What are you saying? Does offering cash decrease the chances of cracking?
Any system can be proven secured by such a contest if you limit acceptable attacks to the parts where you know the system is the strongest... but a real attacker will always aim at the weakest part.