17 ms·
The Most Backdoor-Looking Bug I’ve Ever Seen
- vbezhenar 6y agoThe most backdoor-looking feature for me in supposedly encrypted systems are cloud backups. They are “optional” yet most users will agree (especially when given software constantly nags about it until you give up) and their backups will leak both sides of conversations, despite all end-to-end encryption attempts.
- londons_explore 6y agoWhatsApps cloud backup on Android sits on Google drive by default. It is encrypted with a per user key known to WhatsApp. That means for a third party to access the chats, they need Google to hand over the data, and Facebook to hand over the key. The logical next step to add would be for Google to additionally encrypt the data with the users logon password or something derived from it. Google won't do this anytime soon for business reasons.
- garmaine 6y ago> That means for a third party to access the chats, they need Google to hand over the data, and Facebook to hand over the key. National intelligence agencies (plural) would already have both.
- londons_explore 6y agoTrue, but it still makes the attack surface much smaller - employees of neither company could steal your data. Your data is now protected by the intersection of the companies privacy policies rather than the union of them.
- beagle3 6y agoIt used to be that way. But then, one day, Google announced that WhatsApp backups (a) no longer count towards your quota, and (b) are no longer encrypted. There are two beneficiaries of this change: 1) Intelligence and law enforcement agencies, which now have direct access to WhatsApp history for everyone who uses cloud backup (99.9% of users, if not 100%), without the need to 0day any specific phones, risk detection, or even have those phones on except occasionally. 2) Google, who can now mine your private conversations, metadata, etc. (At a tiny storage cost for Google, for which they are likely compensated by the NSA)
- paranoidrobot 6y ago> encrypt the data with the users logon password or something derived from it This leads to inability to restore a backup if you forget your password and need to reset it. That's going to lead to screams/tears from a lot of folks who don't realise those implications.
- sdflhasjd 6y agoWhatsApp backups are a bit of an anti-feature, as I found out while trying to ditch the app after the recent policy update. 1) The backup can only be made to Google drive, you cannot create a manual backup to a location of your chosing 2) The backup is created in a secret folder that cannot be accessed by the user 3) The backup is deleted if you delete your account. (not much of a backup, eh?) 4) You can only create per-channel exports, but this won't export the entire chat, it will export up to ~12MB of recent media, and ignore the rest, silently. WhatsApp would only share the last 40 messages of a 4-year-old chat because the last few messages contained a few images.
- londons_explore 6y agoI believe there is still an (undocumented, unofficial) way to backup to the SD card. The backup is still encrypted tho, and can only be restored to the same whatsapp account as created it.
- ycombinete 6y agoInteresting. I just created a 900MB backup of a chat history, on my iOS WhatsApp, that appears to have all messages and all data.
- tinus_hn 6y agoBeing an iOS device it probably doesn’t ‘backup’ to Google Drive so this story may not apply
- ycombinete 6y agoyeah, on ios whatsapp backs up the data to icloud
- jsmith99 6y agoI can't find any source for this 12MB limit? Backups I've restored (Android) seen to contain all media although I haven't checked in detail.
- keyme 6y agoI've posted this here before. > It is encrypted with a per user key known to WhatsApp. This is no longer true! For a few years now. The backup is stored on Google Drive in plain text. https://faq.whatsapp.com/android/chats/about-google-drive-backups/?lang=fb https://faq.whatsapp.com/android/chats/about-google-drive-ba...
- FiloSottile 6y agoThat page doesn't say that, and "tied to the phone number" sounds like they will only give you the key if you can authenticate via SMS. Do you have a better cite or did you check directly recently?
- londons_explore 6y ago> authenticate via SMS It's now "authenticate via SMS and pin (if enabled), or authenticate via SMS and wait 7 days (if pin enabled)"
- beagle3 6y agohttps://github.com/B16f00t/whapa https://github.com/B16f00t/whapa (among other tools) appears to download it from Google without requiring any key from facebook or a rooted device. I haven't tried this specific tool yet (or others recently) but it was definitely possible in the past without requiring any key from FB/WA.
- keyme 6y agoYou can extract it yourself. https://github.com/YuriCosta/WhatsApp-GD-Extractor-Multithread https://github.com/YuriCosta/WhatsApp-GD-Extractor-Multithre... I do not vouch for this repo, but it gets the job done. The only creds required are your Google account creds. No per-user whatsapp keys necessary.
- FiloSottile 6y agoThat's disappointing, thank you for the link.
- 6y ago
- moepstar 6y agoThis is something i don't understand (at least for me/my use case): Are historic chats that important to have them backed up? To me, if there's anything of value, i'll save it via other means...
- greatgib 6y agoFor me, chat history has a huge value. How many times things looks like meaningless when they are said but have a lot of values at a later date? For example, sometimes you wonder, "when was it that time when XXX event happened". Or "I remember that one day someone told me that he had the same problem as me, but who was it and what was his solution?" Otherwise, we are used to share thousands of links and snippets with my friends that we usually discuss. A lot of time, after a very long time (sometimes years), for some reason we remember that something or link about a topic was discussed long time ago, and then it is convenient to look into the history with keywords to find back the links and what was said at that time!
- Aerroon 6y agoSure, but wouldn't you want to have control over these backups yourself? Not only do you get increased privacy from it, you also won't be in for a nasty surprise when the service decides to remove old logs/stop doing business.
- Erlich_Bachman 6y agoAn average user doesn't commonly want to have control over anything themselves :P.
- joe-collins 6y agoI disagree. They'd love to have control, but that control requires tech sophistication that none of the current tooling adequately elides.
- 6y ago
- thelrjwpet777 6y agoAmateurs.
- londons_explore 6y agoIf any clients had been logging that nonce, we could retrospectively catch any person in the middle. Far too few services do strategic logging of data useful to catch attackers like this. Many attackers won't attack if they know traces will be left which can point to them.
- Taek 6y agoThe more I work with production systems, the more I appreciate healthy logs. We've solved at least a dozen big issues this past year with "just scan the logs and rebuild the historical data, we can pretend like we were monitoring that issue the whole time".
- rorykoehler 6y agoYou run debug level logging on prod?
- peteretep 6y ago“debug level” and “prod level” logs are pretty arbitrarily drawn lines from organisation to organisation. If they’re intentionally running that logging level on prod, it’s prod level
- dboreham 6y agoNot the OP, but: kind of, yes. Enough logging for someone with access to the source code to stand a good chance of reverse engineering what happened (code trace) when something goes wrong, without having the user reproduce. This capability is built into the product and involves significant development effort in itself.
- sneak 6y agoIt's amazing to me that people still consider Telegram a legitimate contender in choosing a messenger. This blog post is far too charitable.
- davidgerard 6y agowell, any messaging service, you're only on it for the people. Certainly the only reason I use Telegram is a few favourite chat groups. The problem with Telegram's crypto is that Nikolai Durov is super-smart - he has two Ph.Ds in mathematics - but he thinks he's smarter than everyone else in the world put together, so Telegram roll their own crypto all the time, and keep being a worked example of why "don't roll your own crypto" is a saying.
- pdimitar 6y agoAnd it's amazing to me that any Telegram coverage on HN is met with extremely hostile reactions. All they did was not invent the best encryption in the world... like you, me, and 99.9% of the world. Mortal sin, right? So please stick to facts and what can be reasonably proven, please. The rest is meaningless noise and mindless hate. The author himself admits it's much more likely this was an amateurish mistake than some man-in-the-middle conspiracy. Did you make it until the end of the article?
- saagarjha 6y agoI don’t think your paraphrase is an accurate representation of the article.
- pdimitar 6y agoFrom the article: > Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. How else would you interpret it?
- saagarjha 6y ago“This looks like a backdoor but if I think really hard maybe I can consider it to be incompetence?” Neither is a good look for a security team, of course.
- paveldurov 6y agoAnother libelous post by US government affiliated "cryptographer". Perhaps next we will see other familiar faces chipping in like tptacek from matasano ) Impossible to succeed at this level without making a few enemies.
- 4gotunameagain 6y ago> because an attacker capable of intercepting the messages could simply establish two separate sessions with the two parties, carrying out a PitM attack Really. That's our new problem now? That it's a person in the middle and not a man in the middle? Plus it goes against the narrative that men are the source of all evil in this world ;)
- tarasmatsyk 6y agoTL;DR A TG server was sending a "salt" to clients in order to randomize keys (telegram claim) when in fact the "salt" turned out useless in terms of encryption and the only reasonable explanation for the "nonce" was using it as a backdoor to perform MITM attack. You decide whether it was done intenionally or because of lack of sleep/understanding PS. an original author got 100k$ for finding/exposing a potential backdoor.
- jbj 6y agoOne thing that always puzzled me about telegram was seeing maps being loaded from yandex when sharing locations with friends
- ffpip 6y agoI think it uses Google by default because Google Maps is the best in almost all regions. It gives you an option to change Maybe Yandex in Russia only?
- Yetanfou 6y agoI never share my location with anyone other than by telling them in normal language than I am at some specific location ("the ferry terminal at Marstrand" or something like that). I don't give the few apps I still use - I try to use self-hosted web services where possible - access to location data, other than those which need it to function (OsmAnd~ etc.). To use some WWII-related terms, "Feind hört mitt" (seen om german-language equipment, it means "the enemy is listening in"), "En svensk tiger" (a Swede stays silent (so that the enemy can't listen in)) or, more tangentially related "loose lips sink ships".
- m12k 6y agoDoes anyone have any inside info on this? If we don't assume malice, what is the reason Telegram is rolling its own non-standard crypto like this? Were there no widely publicized E2E protocols that would fit the bill at the time Telegram was being developed? (i.e. was it started before Signal had become known, or does that protocol have limitations that Telegram found unacceptable?) Or did the team have someone in charge with a bit of not-invented-here-syndrome that was just gung-ho on rolling their own no matter what? (wouldn't be the first time something like that has happened). And has any effort been made to validate the protocol, despite being a bit weird, so we might eventually trust it as much as Signal?
- FDSGSG 6y agoNo amount of effort to validate their protocol will make Telegram trustworthy. Telegram does not encrypt most conversations, you cannot compare it to Signal. In regards to actually validating the protocol, the OP addresses this >The current consensus seems to be that the latest version is not broken in known ways that are severe or relevant enough to affect end users, assuming the implementation is correct. That is about as safe as leaving exposed wires around your house because they are either not live or placed high enough that no one should touch them.
- wyuenho 6y ago> Telegram does not encrypt most conversations, you cannot compare it to Signal. I wish people will stop repeating this nonsense. Just because they don't do end to end encryption by default, doesn't mean they don't encrypt, which implies messages are sent in plaintext. There are plenty of reasons why they did what they did, and these questions are all available publicly in their FAQ or the founder's Telegram channel. Whether you agree with the trade-off or their explanations is up to you, but facts are facts.
- pedrocr 6y agoDo you really consider an "encrypted conversation" if you just do TLS to a central server that has everything in plaintext? Is Facebook Messaging encrypted messaging? Because that's the kind of thing we already had before this wave of apps and Telegram is marketed within this new wave but doesn't have any more security than what the previous wave already had, even if you trust their homegrown protocol.
- baybal2 6y agoAnd obligatory reference to Backdoored Streebog cipher : https://eprint.iacr.org/2016/071 https://eprint.iacr.org/2016/071 https://www.sstic.org/media/SSTIC2019/SSTIC-actes/RussianStyleRandomness/SSTIC2019-Article-RussianStyleRandomness-perrin_bonnetain.pdf https://www.sstic.org/media/SSTIC2019/SSTIC-actes/RussianSty... The backdoor was hidden in the plain sight: the s-box was said to be randomly picked, but years long evasive answers of authors about cryptographic properties of the box made people to think that there was something really not right with it. If not for that specifically putting aim at the s-box, there would have been no chance anybody found that. 3 years later, and Perrin's paper comes, and it is discovered that almost a new domain of math is buried in that s-box. Nobody yet discovered what unusual math properties of that s-box do, but nobody now doubts it being a backdoor of some kind.
- baobabKoodaa 6y agoThis story is eerily reminiscient of the s-box in DES, except in that case there was no backdoor, the researchers had simply discovered a novel attack method, crafted their s-box to protect against that method, and then kept the attack unpublished for decades: > The eight S-boxes of DES were the subject of intense study for many years out of a concern that a backdoor (a vulnerability known only to its designers) might have been planted in the cipher. The S-box design criteria were eventually published (in Coppersmith 1994) after the public rediscovery of differential cryptanalysis, showing that they had been carefully tuned to increase resistance against this specific attack. Biham and Shamir found that even small modifications to an S-box could significantly weaken DES. https://en.wikipedia.org/wiki/S-box https://en.wikipedia.org/wiki/S-box
- Qub3d 6y agoI find it such a shame that such amazing mathematical research was pumped into ultimately producing such a backward-minded result. At the very least I suppose we will be able to glean more knowledge out of it in the end.
- hnews_account_1 6y agoIs there a layman version of this? Something non cryptographers can grasp?
- baobabKoodaa 6y ago> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.
- adsche 6y agoGood. (At the risk of stating the obvious: Changing commonly established things is how progress works.)
- s5ma6n 6y agoOk, I will bite. Why is it good? What benefit does it achieve other than confusing people. It is also a good reminder that how things were before. One should not forget the past and things accomplished by many efforts. How is it different than 1984's newspeak or the idea of 'changing the history? Why not choose an approach similar to this (first link I found about Warner Bros' approach): https://twitter.com/stilkov/status/506324544177836032 https://twitter.com/stilkov/status/506324544177836032
- dash2 6y agoThe downside is the cost to communication. I didn't know what a PitM was. After a bit I guessed it was Person, i.e. man in the middle, but I wasn't sure that it didn't mean something else. I'm not sure how big the gain is here. Are people really going to read "man in the middle" and assume that no woman could ever do this?
- baobabKoodaa 6y agoAlso: where are the people who were offended by "man-in-the-middle"? Can you point to a single non-man who was offended that the evil-doer in this example was identified as a man? Or can you point to a single man who was offended for the same reason?
- mcbits 6y agoThere are people who object to all gender-neutral uses of "man", probably more from the belief that it perpetuates bias than from personally taking offense.
- tpush 6y agoIf the dead comment by user ‘paveldurov’ is the actual Pavel Durov, then I just found extremely solid reasons never to go near Telegram. Yikes.
- s5ma6n 6y agoWhere can we see this comment? Here at HN or the post itself? I could not see any comments with 'paveldurov'.
- tpush 6y agoSet ‘showdead’ in your profile to yes and scroll down the comments to the end.
- s5ma6n 6y agoThank you for the explanation!
- pseudalopex 6y agohttps://news.ycombinator.com/item?id=25726879 https://news.ycombinator.com/item?id=25726879
- technion 6y ago> Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. I don't think people give credit for just how deep this actually does cut. On one project I worked on, which stored obscenely sensitive information, their product manager gave a speech about password security and told us he had a better algorithm than bcrypt. You couldn't explain why this was a bad idea - he wasn't taking feedback. When it landed, I found the botched the algorithm so this "sql injection detection code" basically changed every character to a ' mark. You just needed the right number in a password and it would always match. So I logged a bug, used it to push that they just use bcrypt, I got a big story about how he knows exactly what he was doing and he would fix the bug. It was "fixed" for a few days. Apparently what happened was, the developer didn't know how to use git properly and copied an older file on top the repo and brought the bug back. After it was known, disclosed, and every one was told it was fixed. The algorithm turned out to only handle a-z, and every other character was left in place. So I went though this again. Same speech about incredibly great design. They could have easily snuck a backdoor in because I never looked at 90% of the code, but this ongoing nonsense was 100% Hanlon's razor.
- LorenPechtel 6y agoYup, when you get bosses dictating algorithms such bugs are likely.
- jonmal 6y agoIt amazes me that Telegram is still a contender.
- pdimitar 6y ago- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Telegram is mentioned, as it always happens: Check. --- I am not shilling for Telegram. I have no reason to. I can switch to Signal with my most important contacts in the space of one hour if I wanted to. I never invested any money in them either. I won't get sad if they get nuked from orbit tomorrow. But it's really baffling how non-constructive most Telegram HN coverage is, both articles and comments. Sure, they have no bulletproof end-to-end encryption of messages. So, like 99.9% of all apps on all app stores then? Some generic marketing on the homepage using vaguely non-accurate language ("secure chats")? So, again, like 99.9% of the apps that have a page and put marketing lingo on them? What's so uniquely awful about Telegram? It's legitimately intriguing how hostile HN gets at the mention of Telegram. There might be some interesting sociological study hidden there somewhere.
- ryanlol 6y ago> What's so uniquely awful about Telegram? Telegram puts its users in danger by lying to them. They claim to be a secure, encrypted messenger but do not actually encrypt chats. Then there’s the backdoor... >I am not shilling for Telegram :)
- pdimitar 6y agoWell, sue them. I don't think all other messengers save for maybe Matrix and Signal are any better. Even better, make a messenger that does encrypt chats. Make it paid. Prove its end-to-end encryption properties. I'll buy it and advocate for it to my friends and family. In any case, the constant hate is (a) very tiring and (b) very uncharacteristic for HN.
- ryanlol 6y agoWhy are you so bothered by Telegram receiving some well deserved criticism? It’s weird. There are lots of posts on HN I don’t care about, but I don’t think I’ve ever had the urge to make comments like yours. > In any case, the constant hate is (a) very tiring and (b) very uncharacteristic for HN. There are people who trust their life and liberty on these apps, I don’t think the “hate” towards Telegram is inappropriate at all. And actually, I think that most of the time the HN community is far too positive about Telegram. Usually I see comments criticizing it get downvoted. Funny, no?
- cies 6y ago> Most backdoor looking bug While a backdoor is not a bug but a feature, it helps to disguise a backdoor as a bug (i.e. plausible deniability). I know of one instance (in MS Windows) where the backdoor feature was not even hidden so much: https://en.wikipedia.org/wiki/NSAKEY https://en.wikipedia.org/wiki/NSAKEY That's why we need opensource. It's a hedge against tyranny.
- ryanlol 6y agoThe NSAKEY backdoor claim should be trivial to prove with a debugger, until someone does so I think we can safely dismiss it as a lie. It’s been two decades, and nobody has been able to explain how it would’ve been used.
- cies 6y agoI beg to differ. This stuff is called reverse engineering and it's all but trivial.
- ryanlol 6y agoThe debugging symbols and most of the source is out there, this really isn’t a particularly difficult task. If you can’t do this, then you certainly aren’t qualified to claim that such a backdoor exists.
- gizmore 6y agoHow to give points for a good post?
- loraa 6y agoPerson in the middle attack. FMLM