3 ms·
That's the same as saying that a car model is safe because there have not been any crashes yet with this make and model. No cars are safe because there are indu
by botto 8y ago
That's the same as saying that a car model is safe because there have not been any crashes yet with this make and model. No cars are safe because there are industry standards that a manufacturer is tested to ensure they are following.
Closed source (both in code and implementation) has no place in the security world and anything security related should always be open for anyone to scrutinize.
- GranPC 8y agoFeel free to scrutinize Telegram's crypto and E2E implementation for secret chats. It's open source and you can find it here: https://github.com/tdlib/td https://github.com/tdlib/td
- rvnx 8y agoYep, did it, not going to use Telegram now. Love the unsecure TLRPC objects deserialization that actually makes the native client crash and to not verify what other clients have sent: https://raw.githubusercontent.com/DrKLO/Telegram/e397bd9afdfd9315bf099f78a903f8754d297d7a/TMessagesProj/src/main/java/org/telegram/tgnet/TLRPC.java https://raw.githubusercontent.com/DrKLO/Telegram/e397bd9afdf... and the tons of magic and undocumented numbers in the code: https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/jni/tgnet/Handshake.cpp#L278 https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/...
- empthought 8y agoCrashing in the face of invalid and likely malicious input is a secure approach (fail fast).
- saagarjha 8y agoDepends on whether the crash is intentional :/
- Dolores12 8y agoRSA encryption is potentially exploitable by quantum computing. Still people are using it everywhere.