If an insecure protocol with an insecure implementation can send messages that others can't read, how is it insecure?
If an insecure protocol with an insecure implementation can send messages that others can't read, how is it insecure?
With regards this counter-challenge. The crypto here is known to be poor. If this counter-challenge cannot be broken, then it shows that the challenge issued by Telegram is no proof of security.
SO in short,
* we don't know if no one can read the Telegram-encyphered messages,
* the challenge provides effectively zero evidence that it's secure,
* Telegram will proclaim loudly that no one has broken their crypto,
* non-specialists will be fooled by this.
If I haven't answered your question, perhaps you could be more explicit as to what you're not understanding.
> If this counter-challenge cannot be broken, then it shows that the challenge issued by Telegram is no proof of security.
The contest framework is identical to Telegram’s (no MITM perspective, no known plaintext, no chosen plaintext, no chosen ciphertext, no tampering, no replay access, etc)
eg. You aren't using Wifi, your network is fully secured, no one has access to any router along the way, etc.
Lets put it this way, if you're using Telegram / MarlinSpikeGram and you and I are in the same coffeeshop I can read your messages.