3 ms·
Didn't Telegram challenge this rule as well? > * Never roll your own crypto Afaik, discovered practical vulnerabilities like [1], [2] were patched, and the rest
by aschatten 6y ago
Didn't Telegram challenge this rule as well?
> * Never roll your own crypto
Afaik, discovered practical vulnerabilities like [1], [2] were patched, and the rest are theoretical, like [3].
> Using Symmetric Encryption in the Database: When you write data to the database, use a function like encryption_algorithm(data,key). Likewise, when you read data, use a function like decryption_algorithm(data,key). If the attacker can read your backend code, obviously he/she can decrypt your database.
I think the author misclassified this method. An actual encryption is not obscurity. It would be, sort of, if the key is stored in code. But when a proper key management is in place, it's a solid approach.
[1] https://news.ycombinator.com/item?id=6948742 https://news.ycombinator.com/item?id=6948742
[2] https://web.archive.org/web/20181118154823/https://www.alexrad.me/discourse/a-264-attack-on-telegram-and-why-a-super-villain-doesnt-need-it-to-read-your-telegram-chats.html https://web.archive.org/web/20181118154823/https://www.alexr...
[3] https://eprint.iacr.org/2015/1177.pdf https://eprint.iacr.org/2015/1177.pdf