6 ms·
What I find interesting is that this article is very recent, however the calculations on Crypto are not up to date. MtProto has had some big changes some time a
by x092 8y ago
What I find interesting is that this article is very recent, however the calculations on Crypto are not up to date. MtProto has had some big changes some time ago already:
- SHA-256 is used instead of SHA-1;
- Padding bytes are involved in the computation of msg_key;
- msg_key depends not only on the message to be encrypted, but on a portion of auth_key as well;
- 12..1024 padding bytes are used instead of 0..15 padding bytes in v.1.0.
See https://core.telegram.org/mtproto/description https://core.telegram.org/mtproto/description
- Fnoord 8y agoNone of these changes are big enough; it is still homebrew crypto. If there's issues with cryptography standards you can be sure your OS (such as your Linux distribution) lost CIA in one way or another. Whereas with MTProto, if that is broken, only your Telegram chats lose CIA. Which raises the question why not use standards?
- x092 8y agoThey were, actually. MtProto v2 satisfies IND-CCA now as opposed to what the blog post claims: https://core.telegram.org/techfaq#what-about-ind-cca https://core.telegram.org/techfaq#what-about-ind-cca
- raverbashing 8y agoSo Signal and others are not "homebrew crypto"? That criticism is fair a lot of times, but every higher level crypto construction is going to be unproven for a while until checked. It's not like they were inventing their own hash function and stream cypher.
- tptacek 8y agoSignal is the best-studied multiparty secure messaging protocol; there are academic papers that provide formal analyses. Trevor and Moxie won the Levchin Prize at Real World Crypto for Signal Protocol; the Levchin steering committee is a "Who's Who" of cryptographers, as are the other winners of the prize. No, Signal is not "homebrew crypto".
- raverbashing 8y agoWhat would be a good definition of Homebrew crypto? Sure, if I put some primitives together (even if I had a good knowledge of how to do it) in a closed product and nobody evaluates it (and I add a label like "military security") that's Homebrew, no questions. But all systems are born "in secret" (at least for a short while). Unless the definition involves appeal to authority.
- tptacek 8y agoObviously, the term is a straightforward appeal to authority.
- raverbashing 8y agoWhich is sometimes unjustly described as fallacious, though even the best can make mistakes.
- tptacek 8y agoHopefully we agree on the authority here. But I jumped the gun on my response a little as well, because my argument isn't simply an appeal to authority; for instance, you can just go read the formal analyses of Signal Protocol and evaluate them for yourself. Maybe IEEE EuroS&P was wrong to accept the paper!
- acdha 8y agoThe fact that they spent so long using SHA-1 after it’d is a red flag for their hand-rolled crypto. They had no legacy install base but were deploying new services while the rest of the industry was deprecating it – even the U.S. federal government was ahead on that.