Remember how that was, like, five days ago?
Remember how that was, like, five days ago?
RIP Telegram (2013-2013).
This whole thing has been interesting to follow because it seems this same thing happens every time someone make macho Crypto-claims. From seeing how confident the Telegram team was to reading all the detractors who were so ready to criticize. It's an interesting dynamic in the Crypto community.
RIP Telegram (2013-2013).
omg made me lol super hardThis is HN, and we don't make posts like that.
1) Every Bitcoin thread
2) Every NSA/Snowden thread
Source (cough): I've been around for 6.3 years, am in the top 40 users in terms of net karma, and am actually very frustrated with the unfortunate turn the community has taken in the past 12-18 months. And am considering leaving, which makes me sad.
That said, I'm pretty sure my highest karma (~50) comment was a joke about Tau Day back in 2008. Soooooooo.
All I was saying is perhaps if pg et all decreased whatever threshold they have set for account ghosting, that we may see less of these pointless comments in the future.
That behavior certainly doesn't add anything to the site.
Telegram is very young project and it has bugs for sure. Some guy found potential issue in protocol and developers committed to fix it soon. There is no information that any messages were revealed due to this bug but Telegram should go away and developers should do something else.
Whatsapp is less secure then Telegram but I have not seed “Whatsapp RIP” messages. Not so hard to save videos in snapchat but no one propose to close the application. About a year ago YAML vulnerability was found but no one proposed dhh to stop development and focus on race driver career.
I think that we need more competition for TextSecure.
Terms of bug bounty are very hard to satisfy even with bad protocol but Durov seems decided to play safe with such amount of money. Guy that found problem in MTproto doesn’t win money according to conditions of the bug bounty because message is not decrypted.
Disclaimer: I don’t have any affiliation with telegram besides living in the same city as telegram developers.
So, let's put it this way: Was it ok of them to lie through their teeth to users? If so, then that's a sad state of marketing. If not, then what are you proposing here?
- military-grade encryption – true
- world's most secure protocol – I’d consider this statement as false, I don’t know what they mean by most secure and what protocols were considered. May be messengers available at app store, better to ask them
Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition?
Why do you think that they lie more then TextSecure advocates? Each of these messengers is safe to passive listening. But unsecure to similar degree if user downloads them from app store and runs on hardware and software that could be easily patched. Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app and that every other app should be thrown out.
I've written about this pretty extensively: https://www.hnsearch.com/search#request/all&q=by%3Asillysaur...
It's an interesting contrast in cultures that you phrase it like "Why do you think Telegram lies more than TextSecure advocates?" .... As far as I'm aware, TextSecure advocates haven't lied at all. TextSecure's interest is in security, whereas Telegram's interest seems to be in money and power.
Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app
I just don't know what to say to this. Telegram has been proven insecure, TextSecure hasn't. Telegram isn't designed by cryptographers, TextSecure is. There is absolutely every reason to assume Telegram is broken.
Each of these messengers is safe to passive listening.
This is mistaken because Telegram has been proven vulnerable to MITM attacks. Even after they patch this latest security problem, it would be very unwise to trust them.
> I just don't know what to say to this. Telegram has been proven insecure, TextSecure hasn't. Telegram isn't designed by cryptographers, TextSecure is. There is absolutely every reason to assume Telegram is broken.
Textsecure is designed by cryptographers, and hasn't been broken yet, but that doesn't mean that it is secure. People need to risk assess when they're using any software.
> If you want to be secure from the NSA, use TextSecure [...]. It's really that simple.
That claim is far too confidant! If you want to be secure from NSA you need to do many things - have a look at the specifications for buildings that handle secret documents for example, as well as just using a piece of well designed but relatively untested software.
Most people do not have nearly enough operational discipline to withstand investigation by well funded government agencies. Merely using this software is not enough.
That claim is far too confidant! If you want to be secure from NSA you need to do many things - have a look at the specifications for buildings that handle secret documents for example, as well as just using a piece of well designed but relatively untested software.
That's why I removed it 15 seconds after I wrote it. But perhaps it could be downgraded to "if you want to live in a world where it's very difficult for governments to vacuum up all your data by default, then use TextSecure, because it's the first step towards that." Telegram offers no such protection since it's vulnerable to MITM attacks (even after they fix this one).
>TextSecure's interest is in security, whereas Telegram's interest seems to be in money and power
I can't read minds or even their messenger logs so I can't comment what is their interest but I'd be interested to know why you think so
> TextSecure completely safe app
Just wrong. How could you call something "completely safe" or bug free?
>Each of these messengers is safe to passive listening >This is mistaken because Telegram has been proven vulnerable to MITM attacks
How Telegram is prone to passive listening?
I didn't say TextSecure is completely safe. I said Telegram has been demonstrated to be broken.
Telegram is prone to passive listening because their design doesn't prevent it. There's nothing stopping someone from MITM'ing every Telegram secret chat when it's first initiated. It's in the design.
Their contest means nothing, because due to the way the contest is designed, it's impossible to MITM or other side channel attacks like timing attacks. These are the real attack vectors, yet the format of the contest prevents anyone from employing them.
Yes you do. "TextSecure completely safe app" was copied from your message before you or someone else edited it. I've not typed it but copied exact phrase from your message.
Is there a cause-effect relationship I'm missing here?
> Just wrong. How could you call something "completely safe" or bug free?
Where did he say that "TextSecure [was a] completely safe app"?
Why are you misrepresenting his words?
He said TextSecure was not proven insecure (As was Telegram). That does not mean or imply that it is safe or secure.
What's unsafe and unproductive is when bozos jump in the pool, apparently ignorant or otherwise misrepresentative of the reality of how difficult it is to create a correct solution -- and confidently declare their implementations to be trustable.
If the messaging on Telegram had been, the world needs a secure messaging solution and we're committed to building it starting with this thing which we think is pretty good for XYZ, nobody would be objecting. Instead, these guys presented themselves as having solved a problem which is known to be difficult, and moreover using an unlikely method.
I would suggest they hire security consultats to check the security in a first stage. Review by third parties is the best method to avoid things we overlooked. The prize shoud be for after all these consultancy options have been exhausted.
As a side node I see there is still a lot of room to improve automatic translation. It's difficult to understand in some places.
In the crypto world, projects like Telegram have popped up over and over again. A new protocol, designed by non cryptographers, that turns out to be heavily insecure. I wish that wasn't the case, but that is why people have reacted the way that we have. This is literally life and death, so it pays to be cautious.
I hope Telegram learn from all this, and go and get audited and tested by reputable experts. Then, fix all the issues raised. Then release their apps to the public, when they are proven secure. Until that time I personally will not trust their application.
Whatsapp never claimed to keep your chat secure. Telegram did. Many people offered gentle advice to Telegram, and they ignored it.
Maybe it's a cultural thing? Not just domains-of-expertise (mathematicians going into crypto) but international?
Most advices to telegram developers at previous HN discussion were to stop doing crypto and do something else. I would not consider them as “gentle advices”. The only help from the community to their application is the bug report x7mz user from habrahabr site.
And guess what, hate isn't always wrong.
The guy gets $100 000:
https://vk.com/wall-52630202_7858
You may want to check before you post.
Apart from that I can't check Durov's posts that from the future. My post was written before Durov's announcement.
No, you just stood on the sideline and waited for somebody to fail so you could come down off your branch and peck at the corpse.
Indeed, there is a lesson here. Don't expect anybody to pat you on the back when you put it all on black and win. Because, sure as shit, they'll be there to kick it in your face when you lose.
How embarassing for telegram if what he says is true.
This excerpt was taken from the google translate version of the article.
Crypto is hard to get right, that doesn't mean anyone shouldn't even bother trying.
Likewise, building a hot new secure messaging app with existing well-analyzed, battle-tested cryptographic schemes is generally going to be welcomed.
If you try to do both at once, you're building your application on shaky, untested cryptographical foundations. Cryptographers would similarly probably warn you not to base your application on a new cipher someone else announced at a cryptography conference last week - give it a bit of time for others to analyze it and spot any flaws it might have before you entrust anything sensitive to it.
I could go and try to play around with real time systems for flying planes, it still wouldn't make sense for me to sell you the "safest" plane in the world without going through the proper steps to get such system certified beforehand.
Failure is celebrated -- if you make an effort, and try, and you fail, and you learn, and you share what you learned, people care.
But when you (Telegram, not you, XorNot) have a bad idea, and people smarter than you patiently explain why its broken, and you try to buffalo and bluster and bullshit past them, and your product's entire purpose is to provide a security, then your product is worse than a buggy tool; it's worse than not using the product at all. It's the modern-day equivalent of patent-medicine snake oil, and it hurts people.
Because it is dangerous to everyone when non-crypto guys call themselves crypto guys.
Note: This is not so much in response to thom's comment, but rather the criticism of jimmytucson's comment (which actually has some substance).
They overlooked some security weakness and didn't see it. They didn't do it on purpose like the NSA. In their eyes, the protocol was perfectly secure and most of it is of course.
The only way to avoid this self judgment bias is to use review by other people.
That there is exactly the problem. There is no reason to believe the protocol is secure, and when looking at crypto you start from the assumption that it's "maybe broken", not "perfectly secure". Assuming that some new crypto is secure is hubris.
Pavel previously set up contests with monetary rewards about half the same value for developing a mobile VK app for iOS, Android and WP.
It's not a gamble—it is really an expensive way to find holes. What I don't understand is why they don't hire a crypto consultant instead.
What you have here is homeopathy.
Telegram's response was basically, "LOL. We know better cuz' we got binders full of mathematicians and I'm not listening unless you win our rigged contest designed purposefully to instill a false sense of security in our customers."
Cryptographic software isn't developed the same way as ordinary software. A normal program is launched with tons of bugs and gets fixed over the course of years. Custom crypto solutions should not be delivered to customers in a similar state without explicitly telling them that it hasn't been proven secure.
They also didn't put 200k on the table for anyone that could break it. They put 200k on the table for anyone that could break it in a very specific way that proves nothing.
They used a combo of known bad and unproven stuff in weird ways and then claimed it was the best thing ever, which is just crazy.