Crowdsourcing a More Secure Future
telegram.org
telegram.org
This is great news. Contrast this with other security contests were finding out-of-scope security flaws weren't rewarded.
People in this thread: Good for Telegram, seems arbitrary, disingenuous, just for publicity.
Short of them being in a conspiracy with the researchers, I can't imagine how this is not good news for everyone. Cool it with the hate, people.
There's no hate for Telegram here. There's concern for people's safety. https://news.ycombinator.com/item?id=6949842
This article is good news, precisely because they show how willing they are to improve their service.
EDIT: Of course it's good PR. So what? That's how Google, Apple and most other big companies operate. They don't have to be altruistic to work and create value for people.
Unless it turned out they'd set the whole thing up, which would be different.
That's an important question, really curious to know if the user x7mz steps up to take the reward and if telegram would release any proof of payment (minus any obvious info that would give away the identity of x7mz).
This vulnerability seems to be connected to Diffie-Hellman, right? Even a rudimentary search shows that a MITM is easy on it. I wonder if its even possible that they did not know this one?
In my view, we must integrate this action on the part of Telegram with all of the other things we know about the situation. That's a tall order, because it means integrating this specific action (paying the $100K) with many other topics, such as the various people making claims, their expertise and possible motivations, computer cryptography and computer security, strategies that companies sometimes use to gain access to personal information, the dangers posed by weak cryptography, etc.
Only when all of the facts square with each other will we have a rational basis for trusting Telegram Messenger and the people behind it.
Multiple people that know what they are doing have remarked that the system Telegram has created is a bad idea and it would be much better to use any established protocol. They have also pointed out multiple places where Telegram is committing obvious cryptographic blunders in their protocol.
Telegram decided to pay out $100k under contest rules that are weaker than known plaintext attacks. If they wanted to actually improve their security they would switch to a more secure protocol that doesn't require a server to actively participate in the conversation. I guess if they want to hemorrhage money via the hubris that is their crypto contest they should just keep on as they are.
They have pointed out multiple places where Telegram MAY BE committing blunders, namely their internal server - server communication MIGHT be susceptible to MITM attacks. It's not the same thing.
I've been using TextSecure for a while (as everyone on HN ruthlessly suggests) but guess how many encrypted texts I've sent? 0. That's because they have no iOS app and very few Android users.
There are two problems when it comes to creating a good, secure messaging app: strong, proven security and popularity! Hopefully Telegram either solves both or forces TextSecure to solve the latter.
They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.
What I applaud is their effort here and I hope it continues and moves in the right direction. This announcement makes it seem like they are in fact moving in the right direction.
Why? Because they're literally paying people to like their product? This developer who found the bug wasn't even trying to get any money. He was, by his own admission, a cryptography newbie who happened to be looking over their protocol and found a serious bug. Now they're throwing money at him. How is that in any way a good thing?
I don't think this statement is reasonable. Are you suggesting that they gave the 100k reward out because they wanted the recipient to like their product?
>Now they're throwing money at him. How is that in any way a good thing?
I think bug bounty programs have a track record of efficacy. Do you disagree?
Sometimes negativity is not bias.
The fact is that it is highly inappropriate to have a new, completely unvetted cryptographic protocol in a context where people are relying on it to provide actual security, and they are flat-out ignoring advice from talented and knowledgable people.
After all, Matasano's tptacek obviously did spend some of his time inspecting and criticizing Telegram this week. However, he overlooked the 100K vulnerability that was later discovered by a Russian guy who considers himself a newbie in cryptography.
The other reason that makes me somewhat reluctant to spend money on hiring Matasano is the recent RSA-gate (and the strange role of tptacek in it).
But you somehow expected tptacek to inspect and criticize Telegram with such scrutiny that he finds all of the problems pro bono? That's ridiculous.
It is unfair to imply incompetence on tptacek's part given only that he spent some finite amount of time looking at your protocol and did not find the nonce vulnerability. It is also unfair to say that he didn't find any vulnerabilities despite the potential for a 100k reward as the potential for such a reward (outside of your specific contest) had not been stated clearly.
If you do in fact have evidence that tptacek was involved in RSA's deal with the NSA, you should state your accusations explicitly and provide that evidence. If you do not, I think the accusation is inappropriate and certainly counterproductive.
That said, I very much appreciate the resources you are donating to open source crypto software. It is undeniable that the potential for a 100k reward will send a lot of eyes to your source code. I would encourage you to also consider hiring a security firm (US based or otherwise) and to consider how your comments will affect public perception of Telegram.
Oh, and the vuln was outside your contest. You gave him 100k, instead of the 200k because of that. No one knew that you'd pay out if they found something outside your competition. So saying that people here looked at it but missed that vuln because they didn't claim the reward is disingenuous -- it was outside the contest.
Nice ad hominem though. smh.
In the software that you said was secure?
I don't know whether user sillysaurus2 is connected to Matasano or not but... oh boy... this does come across as a shameless ad for that company.
Considering that they just raised 28mil and that CM is pretty much defacto for older androids, there is a very good chance that this might work.
They have a long way to go before anyone here trusts them but perhaps we could be more positive and constructive?
You find DanBC's comment interesting. It explains why there's been a general tone of negativity towards Telegram's security product. https://news.ycombinator.com/item?id=6949842
Insanely complex software bugs go for less.
even if people are being unfair with these criticisms, what telegram should focus on is to make their designs more secure, and ignore all this publicity. if they truly believe in the "importance of keeping the [system] open", then they should understand that all this publicity (good or bad) is insignificant - especially as they say they have rich guys backing them, so they're not relying on public opinion influencing investors.
it's very easy to make statements like "Together we can make Telegram unbreakable"; harder to turn this into a reality. the current round of attention is a red herring, both for Telegram and for us commenters. let's give them a year and see what it's like after that.
Why is that? This latest revelation should give less faith in Telegram, not more.
Building an encrypted IM service with bad crypto is like investing in blacksmiths in the early 1900s.
... which is fixed by a better client. That requires skills, but different ones from designing a new crypto protocol.
Given the PR efforts of the telegram people, they might actually be better XMPP+OTR+TextSecure+... client implementers than crypto designers (and maybe even better client implementers than most of the people who build clients right now since the situation _is_ bad).
huh?
You can't measure how secure something is by looking at how much money has been invested in it.
Push notifications also work fine there, except on iOS they don't contain any message data, just "You have a new message", probably because server doesn't know what's inside encrypted message. Although havent tried their android client.
I don't think anybody has suggested that they aren't client side encrypted, only that the way in which the encryption is used renders it ineffective.
Basically, when setting up a secret chat the two parties use something called a Diffie-Hellman key exchange to agree on a secret encryption key without eavesdroppers being able to tell what the key is. However, the parties can't tell whether they've securely agreed on a key with the right person - the Telegram server could do a man-in-the-middle attack by doing the other side of the DH key exchange with each party itself so that it knows all the keys, and then decrypt log, and re-encrypt all the messages between them. The fairly standard solution Telegram uses is to allow both parties to manually check that they agreed on the same keys - with normal Diffie-Hellman, this is enough to ensure no-one has MITMed the connection. Unfortunately, their protocol is modified from normal DH in a way that makes this check useless. The server can launch a MITM attack that causes both parties to agree on the same key, so they think they've securely agreed on a key that no-one else has when the server's got a copy too and is decrypting all their messages.
Q: How secure is Telegram?
Very secure. We are based on the MTProto protocol (see description and advanced FAQ), built by our own specialists, employing time-tested algorithms, to make security compatible with high speed delivery and reliability. At this moment, the biggest security threat to your Telegram messages is your mother reading over your shoulder. We took care of the rest.
While Telegram may be on the way to a secure future it is not there yet and the FAQ needs to be less certain before I can applaud them.
Edit: Actually I think the FAQ been toned down a bit but I think some acknowledgement of how new the protocol is and the risks associated with that should be mentioned.
On a side note, I am still not sure, if i will ever use this app. This is primarily because, I act on the internet in the same fashion as i do in real life. I won't do anything online, what I can't do in real life. Hence I don't and perhaps would never need an app like this.
As for sending someone 'secret' message, I always whisper that in the ears. It's an old fashioned trick but has proven to be most secured.
For me it is the same with my chat messages. If someone reads one or two, I don't mind: they aren't very sensitive. But I don't like it if someone can find everything I've ever written.
People over the internet, are little too much over-sensitive. I am not implying 'Privacy' has no value, but we have taken this issue bit too far over the 'internet'.
A prime example of so-called 'anonymity' over the internet is 4chan, you pretty much know what sort site that is.
I am not implying it's an illegal website, but frankly, anonymity mostly leads to creepy, drugs (silkroad), and everything else considered wrong and bad, than something good which is pretty rare. Snowden is an exception, but again, he committed a crime for a good cause. Most people however commit a crime for every possible wrong reasons.
Don't people who run bug bounties publish their reward structure beforehand?
To be clear, this bug was enough to compromise the security of every Telegram secret chat session. I can't think of a more serious issue.
Worse, it's the kind of flaw you'd expect someone subtly sabotaging the protocol to create. It's a small, superficially plausible modification that turns an apparently secure scheme into something completely broken. Yet if they'd made that modification in the obvious way - by combining the nonce and Diffie-Hellman result with a secure hash function - it wouldn't have caused the problem; for the vulnerability to exist the nonce has to be handled in a very particular way.
But you're right - they should have a clear reward structure.
(Of course they won't formulate it that way in the post)
I always get a bit annoyed when apps use the phone number as the primary identifier.
As somebody that just moved to another country, I now end up with a situation where I can either decide to lose my German whatsapp friends or not being discovered by my American whatsapp friends.
I would love to see the ability to get some sort of ID number and then being able to register more than 1 phone number with it.
We believe in fast and secure messaging that is also 100% free. Therefore Telegram is not a commercial project. It is not intended to sell ads, bring revenue or accept outside investment.
If Telegram runs out of money, we'll invite our users to donate or add non-essential paid options.
Yeah, but where does there money come from?
[1] http://telegram.org/faq#q-who-are-the-people-behind-telegram [2] http://en.wikipedia.org/wiki/Pavel_Durov
Contact people that are actually in the crypto community and go the normal route. Once their betters tell them to love you there is actually nothing that you could do to make them stop.