Once Celebrated in Russia, Programmer Pavel Durov Chooses Exile
nytimes.com
nytimes.com
Beyond doubts with the protocol itself, I think the more important consideration is that most people never use it. Telegram is not encrypted by default. Users have to create a special "secret chat" with contacts that is ephemeral, and some Telegram clients don't even support that mode. Last I checked, there was no way to have group "secret chats" in any client at all.
The result is a situation where many users seem to think that Telegram is somehow secure by default, when it definitely isn't. Telegram even stores plaintext copies of everyone's entire message history on the server for multi-device sync.
I think what Telegram is doing right now is dangerous, and potentially another Lavabit in the making. I'd like to see them incorporate a modern end to end encryption protocol, and enable it by default.
To be transparent, I work on TextSecure and am involved with the WhatsApp end-to-end encryption project.
TextSecure-enabled WhatsApp beats Telegram on a pure engineering level; we don't even need to reach politics to prefer it.
In contrast, observing the network traffic, debugging the application, and examining the decompiled binary will tell you exactly what's going on.
This cannot be caught by observing the network traffic and it is really hard to catch by reversing or tracing the binary. Especially if the compromise is not an outright srand(0), but an algorithmic weakness. Then, even if it is found, then it's virtually impossible to determine whether it was benign or deliberate. Now further consider the implications if an app uses a 3rd party PRNG such as those supplied by the operating system or the hardware or if it gets its PRNG seed data from an inherently untrusted sources (such as the OS).
I mean ... the source code being open is obviously irrelevant to the security of a pre-built binary and the adherence to the open specs is not much of an assurance either, because of the PRNG angle. In practical terms it really means that you have to have trust in a product vendor. Period. Because there is always a way for them to screw you over and to get away with it.
People can give you whatever source code they want. That doesn't meant it's the same as what's running in production. While this is tin-foil-hat paranoia, when it comes to encryption software in this post-snowden world it is definitely more reliable to reverse-engineer the binary & network traffic than to just believe the provided source-code to encryption in a popular social app. Or compile the app from source that has been verified by trusted people. Definitely not believing that a binary blob running on your hardware is the same as the provided source.
That said, it's also good to ask for source code so later on when reverse-engineering shows something different you've now caught the offending party in a lie; which is something good to have on record to refer to later on.
So you are telling me if you had the source code you would not be able to verify the code and also use the code to fully verify the expected behavior of the binary?
https://whispersystems.org/blog/a-whisper/
(Just replace "Whisper" with "Signal" :)
Because the widely used chat app I happen to be using does that for all communications without any special direction from me. I didn't even know they were encrypted, it just happened!
Isn't that a pretty dangerous assertion in itself? It's a private company running private servers that you have no control over and no ability to tell whether or not an external entity has accessed your data.
FTFY
As far as you know. Why would they publicise it if they did? How can you prove they've not been forced to?
Also if you look at the forums about justice and advocates etc you can see that Microsoft provides user data but not Google or Facebook (except very big and obvious crimes). But Microsoft, oh it is like your best enemy. So my point is that you will hear it (except spying) if it is a legal request.
Really? In their FAQ [1] they state:
> ordinary chats use client-server/server-client encryption and are stored securely encrypted on our servers
What's your source?
https://core.telegram.org/methods#working-with-messages
...where's the encryption on message histories? There is none. If the data is encrypted server-side, it's with keys that live on the servers. In other words, the encryption provides no value and the servers are "trusted." The point of end to end encryption is not to have to trust servers.
http://www.metropolismag.com/December-2013/Rooms-with-a-View...
http://fortune.com/2014/03/27/see-you-at-the-4-oclock-standu...
https://blog.theidealists.com/rad-spaces/rad-spaces-conferen...
http://indohomedesign.net/great-googles-office-in-pittsburgh...
You'd be hard-pressed to go around Valley and find a company that does not feature an incredibly inventive conference space. Even IBM's Almaden location has some.
If you look at his previous company VK. It is by far a superior experience to Facebook, given how intuitive, fast and sleek it is. Images load 3 times as fast and has many features which FB does not have. I use daily to keep in touch with my friends in Belarus, Ukraine and Russian. I only wish more of my friends used it. He has an incredible eye for design and product.
When people refer to VK being a clone of Facebook. This is innovation. Did Facebook invent the idea of Social Networking? It must be extremely annoying to be constantly referred to as "Russia’s Mark Zuckerberg" and having VK being constantly compared to FB.
Here he has had a brilliant opportunity for a fresh start, freedom to create something better than before and I'm sure he will take advantage of it.
As Steve Jobs put it. "Getting fired from Apple was the best thing that could have ever happened to me. The heaviness of being successful was replaced by the lightness of being a beginner again, less sure about everything. It freed me to enter one of the most creative periods of my life." Steve Jobs, 2005"
Everyone should look forward for what is to come with Telegram. There is some really great technological innovations going on. They've invented a new protocol(https://core.telegram.org/techfaq) and have a great API to utilise this technology(https://core.telegram.org/).
I'm sure you'll like it. Check it out: http://www.telegram.org
The 'clone' label comes mainly from the fact that the site was originally a copy of FB right down to the colour scheme. The two sites have diverged significantly since then, of course, but if you'd removed the logos and presented the two sites to someone in the first couple of years, they would have been hard pressed to pick them apart.
VK is also remarkably popular in Russia, etc, because of the massive amounts of copyrighted music and film material stored on the site that Durov steadfastly refused to remove. It helps with your popularity when one of those 'many features which FB does not have' is an unlimited stock of pirated content accessible for free....
The employee responded to say that money wasn't his motivation. Instead, it was the idea of creating and building stuff.
To prove his point, he threw the bonus money out of the window in paper planes.
This could imply that money really wasn't/isn't the motivation.
Maybe, this was slightly foolish given the media's/public interpretation. I don't think this act had a "douchebag" intention.
Any other douche incidents aside from these money paper planes?
From the link, this paragraph was cringe-worthy:
> We use SHA1 for integrity check The SHA1 in question is for raw unencrypted data. The message key is SHA1-dependent. Note that the AES key and iv depend on that SHA1.
Glad to see they're using this super-secure "SHA1" hash function for integrity checking and that everything else is dependent on it. In a few years they could even brag about how they're using SHA1 for longer than Microsoft!
I agree with the first part of your comment, but I really don't see the link with the future of some garbage crypto app.
And they call it a Facebook clone because it was a direct copy of the Facebook UI, and while Facebook has innovated and polished, VK has been stuck in the same decade-old look and feel.
It may be faster to use in Russia because of geographical proxmity, but I assure you it is nowhere near as Facebook is from North America.
Click on the image.
What are your HTTPS settings?
Facebook defaults to HTTPS, VK does not.
It's riddled with childporn and sick/illegal stuff like that.
Is that's your definition of "superior experience"?
It's a crappy Facebook clone,always has been and always will.
One could say the same about the internet in general, but that hasn't stopped you or I from using it.
"... but that hasn't stopped I from using it."
"... but that hasn't stopped me from using it."
This way it's easy to see which one is right.
Wait, what? Is that what police in Russia normally do? This would never, ever happen in the United States. LAPD actually even has a "Wrong Doors Unit" which goes around repairing broken down doors when the cops raid the wrong address.[0]
[0] http://www.dailynews.com/20080316/repairs-help-rebuild-lapds...
[1] And let's be clear, we're talking about the US here, not the entire fucking West - brutal American LEO tactics are most decidedly not par for the course in the West.
If they didn't have a warrant, I would think they would have a plan if consent was not given to enter -- getting punked out when intimidation was your goal is a pretty embarrassing result.
"[General] Zhukov had always been notified about meetings so this impromptu one worried him. The night before the meeting, three men came to Zhukov’s home for a random search, but they had no warrant. Zhukov threatened to use weapons, forcing them off his property. After they left, he did not sleep the entire night, fearful of the next morning."
https://huhtaj.wordpress.com/scholarly-writing/power-struggl...
He pulled a rifle against NKVD functionaires and they walked away. Was it THAT soft under Stalin's regime? No, it's just toying. Cat and mouse. It's about sending a message: we can get you any time we want, even if you're a world famous general or Russian Zuckerberg etc.
American, or, in general, Western commentators often don't understand this type of moves because they belong to a different political vocabulary, so to speak. "Hah! They even had no warrant, how amateurish of them" - no, that's the POINT.
This could likely be part of some behind-the-scenes "negotiations" between Kremlin and the owner of VK...
Police brutality and abuse in the West (or probably anywhere, for that matter) is a fact of life, but this is not the same thing.
You have to open door for them.
However I'm not a lawyer and that might not be valid anymore.
Great quote.
AFAIK, independent from that Stalin was also responsible for a lot of deaths of people of USSR (at least http://en.wikipedia.org/wiki/Joseph_Stalin "a total of about 2.9 million officially recorded victims in these categories") But these acts don't cancel one another by any logic.
http://en.wikipedia.org/wiki/Gulag#mediaviewer/File:Gulag_Pr...
I'm wondering if that can be qualified as "mean". Doesn't look like a nice thing to do. I also can't see what was the motivation other than "Look, I'm rich".
The employee responded to say that money wasn't his motivation. Instead, it was the idea of creating and building stuff.
To prove his point, he threw the bonus money out of the window in paper planes.
This could imply that money really wasn't/isn't the motivation.
Maybe this was slightly foolish given the media's/public interpretation. I don't think this act had a "mean" intention.
It certainly wasn't "mean". But given the hardships many people in Russia (who don't happen to be petrochemical, banking, and/or internet oligarchs) face, it went well beyond "slightly foolish."
Thanks, that seems like a valid explanation.
That's pretty much the polar opposite of "private".
There was a contest held by Pavel, with $200k prize who will break this "weak security". No one succeeded.
But this falls into the narrative that "Russia bad, America good".
How do you think the Russian media spins stories about Facebook's and Google's co-operation with US intelligence?
Can you? With the Patriot Act?
The fact is that the US gobertment can talk to any worker of any company of the US and blackmail her into doing whatever they want. If this person tells anybody, he goes to jail.
"You don't have to choose between "revolutionary hero" and "let the government do whatever they want with your company and your users", at least not in North America. In a country like Russia it may be different."
You mean like Lavabit?: https://lavabit.com/
It is possible to disagree with police without being outright antagonistic to them.
Funny, when I read about the $3500 part I was surprised at how little he asked for. My impression from various HN threads[0][1] is that someone of Levison's caliber could easily fetch $200 per hour.