5 ms·
As another HN user pointed out Telegram does not store messages in plaintext: https://news.ycombinator.com/item?id=41348228 https://news.ycombinator.com/item?id
by intunderflow 2y ago
As another HN user pointed out Telegram does not store messages in plaintext: https://news.ycombinator.com/item?id=41348228 https://news.ycombinator.com/item?id=41348228
- tptacek 2y agoThat user seems to be misinformed, and appears to be discussing client-server encryption, not end-to-end encryption. That's unsurprising, because, among the many decisions Durov has made that have baffled cryptographers, attempting to confuse users about the implications of E2E vs. client-server encryption is one of the most notorious.
- jiiam 2y agoJust to be clear, are you saying that his claim > Telegram uses the MTProto 2.0 Cloud algorithm for non-secret chats[1][2]. > In fact, it uses a split-key encryption system and the servers are all stored in multiple jurisdictions. So even Telegram employees can't decrypt the chats, because you'd need to compromise all the servers at the same time. is false? If so can you cite a source? (The claim is just a summary of the FAQ https://www.telegram.org/faq#q-do-you-process-data-requests https://www.telegram.org/faq#q-do-you-process-data-requests)
- mr_mitm 2y agoYes. An employee can impersonate a user by registering a device in their name and intercepting the confirmation code and then read all non secret chats and private groups of that user. At least one employee must have the ability to intercept the code. (Unless the user has 2fa enabled, but that is not the default configuration.) There are probably easier ways if we knew more about how the administrate their infrastructure.
- jiiam 2y agoMaybe? When you login from a new device you're asked to provide an OTP so maybe there is at least that layer of protection and, hopefully, requires some circumvention at the application code level. However I think the real question is: even if that's possible, can law enforcement compel Durov or an employee to do so?
- jiiam 2y agoEDIT: I just want to clarify that I don't believe the claim that an employee can intercept the validation code
- saurik 2y agoThere existed one server which sent the code, so whomever administrated that server could trivially have intercepted it by just modifying the software running there to copy/log it to them.
- jiiam 2y agoThis could be extremely unfeasible. For example the code could be generated by a third party and encrypted before arriving on a server controlled by telegram and sent to the user. Or it could be generated inside a nitro enclave. Sure ultimately someone could modify the server code somewhere to log the code or any other specific message before it gets encrypted, but at this point we are talking about inserting a backdoor.
- JumpCrisscross 2y ago> can law enforcement compel Durov or an employee to do so? The E2E encrypted comms are a red herring. There is plenty on Telegram that is public, plaintext and presumably illegal. If Telegram refused to respond (note: not bend over and comply, just respond) to French legal requests in respect of plaintext criminal behaviour the way any other company would and should, that’s somewhat damning. If Durov went above and beyond and interacted with that content, his goose—as the author put it—is cooked.
- codedokode 2y ago
- emptysongglass 2y agoThat user and the user you are replying to are not misinformed. They are perfectly correct. Telegram does not store messages in plaintext. Period. No matter how shrill the cries from Moxie Marlinespike and his adherents, E2EE is not the only form of encryption. MTProto 2.0 is fully documented and everything the user linked described is true.
- tptacek 2y agoNothing in the comment linked upthread is at all relevant to the analysis of Telegram we are discussing.
- emptysongglass 2y agoYou don't get to make a false claim and then handwave it away. You made the claim and you were given evidence otherwise. This was not a case of a user confusing encryption in transit, as you claim.
- tptacek 2y agoNo false claim was made, and nothing in that thread was relevant to the analysis of this story or on this thread. I'm very comfortable leaving it there, and that the people who will take my word on none of this mattering are the only ones I need to care about. Do not use Telegram.
- emptysongglass 2y agoThe person you replied to wrote, > As another HN user pointed out Telegram does not store messages in plaintext: https://news.ycombinator.com/item?id=41348228 https://news.ycombinator.com/item?id=41348228 Telegram does not store messages in plaintext. Your claim: > That user seems to be misinformed, and appears to be discussing client-server encryption, not end-to-end encryption Is categorically false. You do not get to redefine what encryption is. That is not your right. You've been corrected repeatedly. If you continue to insist you have not made a false claim, you are then lying.