29 ms·
Telegram - secure, free messaging
- arianvanp 13y agoMore info about their secure protocol is here: http://core.telegram.org/mtproto http://core.telegram.org/mtproto technical description here : http://core.telegram.org/mtproto/description http://core.telegram.org/mtproto/description
- agilebyte 13y agoAwesome Fallout-style icons.
- conroy 13y agoThe important thing to remember is that all Telegram messages are always securely encrypted. The difference between messages in Secret Chats and ordinary Telegram messages is in the encryption type: client-client in case of Secret Chats, client-server/server-client for ordinary chats. Where "securely encrypted" means that the Telegram server has full access to message contents for ordinary chats. All chats should be "Secret Chats", not the other way around.
- giladvdn 13y agoCame here to say this. I also don't understand why "secret chats" can't be kept in the cloud. Why can't they store encrypted messages and give them to me to decrypt when I want to?
- MAGZine 13y agoMy guess is that it's a security thing. Even if they don't know the security key, I would prefer if they kept no record of the message. The real issue is that they could just make a lever that would still store "secret chats," unless if they're being delievered p2p.
- nwh 13y agoBegs the question why there's a difference really.
- techquery 13y agoI guess, that the problem is in encryption key exchange. Cloud chats are easy to synchronize between devices. Secret chats require unique encryption key for each chat.
- salient 13y agoLook into this: https://whispersystems.org/blog/advanced-ratcheting/ https://whispersystems.org/blog/advanced-ratcheting/
- thomasfl 13y agoIf this get popular and the people behind it can be trusted, this could replace sms and e-mail. The iOS, Android and CLI clients are open source, but I they need to open source the backend too. I also like the idea of giving the noun "telegram" a new meaning.
- macalicious 13y agoReplacing SMS I can see, since whatsApp/GroupMe/iMessages/whatsoever is already doing so, but replacing e-mail? Why would it replace e-mail in your opinion? I think IM/chats have a completely different purpose compared to e-mail, which unfortunately is often times used wrongly imho.
- techquery 13y agoWhat is the point for server side open source? You can never trust that this code is launched on the instance which answers to your client' requests. If you don't trust the backend in some particular way, nothing can help you to trust cloud storage. You should better take a look at end-to-end encrypted chats [1]. In theory they don't allow server to get access to any user data, except the fact of sending messages. [1] http://core.telegram.org/api/end-to-end http://core.telegram.org/api/end-to-end
- gprasanth 13y agoIs HTTPS not secure channel for communication between client-server? What is the reason behind using an entirely different protocol for client-server communication[0] over HTTP? [0] - http://core.telegram.org/mtproto http://core.telegram.org/mtproto
- egeozcan 13y agoI also don't get this. If we stopped trusting HTTPS, how are we supposed to make sure that we get an unmodified app from the play store, or the original source code from GitHub in the first place? Am I missing something?
- oakwhiz 13y agoHTTPS is fine, it's just all the x509 surrounding it that people are upset about
- dchest 13y agoNo, it's not fine. Currently the only secure version of TLS is 1.2 with AES-GCM; and it's still not deployed widely.
- timclassic 13y agoCan you provide some more details for this claim? I'm interested.
- dchest 13y agoSure, https://en.wikipedia.org/wiki/Transport_Layer_Security#Attacks_against_TLS.2FSSL https://en.wikipedia.org/wiki/Transport_Layer_Security#Attac... https://community.qualys.com/blogs/securitylabs/2013/03/19/rc4-in-tls-is-broken-now-what https://community.qualys.com/blogs/securitylabs/2013/03/19/r...
- oakwhiz 13y agoI stand corrected
- na85 13y agoFrom their FAQ: >Q: How secure is Telegram? >Very secure. We are based on a new protocol, MTProto, built by our own specialists from scratch, with security in mind. At this moment, the biggest security threat to your Telegram messages is your mother reading over your shoulder. We took care of the rest. Oh good, a bunch of randoms have rolled their own crypto. I stopped reading at this point.
- fwr 13y agoGee, who are these random nobodies? http://telegram.org/faq#q-who-are-the-people-behind-telegram http://telegram.org/faq#q-who-are-the-people-behind-telegram
- dchest 13y agoThese people are "random nobodies" in cryptographic protocol design.
- skion 13y ago"As a result, Telegram is the fastest and most secure messaging system in the world." That's a very bold and yet to be proven statement. Probably any crypto expert would know better than to say that. This paragraph exactly pin points the problem with being a cryptographic nobody. PS. I do like their icon designer.
- yurylifshits 13y agoMTProto's author is Nikolai Durov: http://en.wikipedia.org/wiki/Nikolai_Durov http://en.wikipedia.org/wiki/Nikolai_Durov He is one of most legendary math/programming champions of all time.
- sillysaurus2 13y agoHe's done nothing in crypto, and he's rolled his own protocol. That's historically been recipe for disaster regardless of how many honors you hold. Colin Percival is similarly decorated, along with being a cryptographer (he's the FreeBSD security officer): http://www.daemonology.net/papers/ http://www.daemonology.net/papers/ ... yet even his crypto app Tarsnap was broken for over a year before he noticed, due to a typo during an innocent-looking refactoring change. http://www.daemonology.net/blog/2011-01-18-tarsnap-critical-security-bug.html http://www.daemonology.net/blog/2011-01-18-tarsnap-critical-... And the only reason the critical bug was found is because it was open source. This, as far as I can see, isn't. So we have a perfect storm of problems here: An author who has rolled his own crypto, isn't a cryptographer, and whose product is closed source. Trust Telegram at your peril. It's worth noting that there's an app which already does what Telegram claims to do. It's called TextSecure, and it was written by Moxie Marlinspoke and several other big-name cryptographers: https://whispersystems.org/ https://whispersystems.org/ ... and it's open source: https://github.com/WhisperSystems/TextSecure/ https://github.com/WhisperSystems/TextSecure/ ... and they don't try to roll their own crypto: https://github.com/WhisperSystems/TextSecure/wiki/ProtocolV2 https://github.com/WhisperSystems/TextSecure/wiki/ProtocolV2 These aren't coincidences. It's basic necessity. EDIT: Telegram is open source, so I was wrong about that and it'd be unfair of me not to mention it. But the other observations still apply. Until Telegram is verified to be secure, I don't think it's a good idea to trust it, especially when secure alternatives like TextSecure exist.
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- andor 13y agoLike Threema, they use the PGP model, instead of OTR...
- Tepix 13y agoWhat do you mean exactly? According to the FAQ, Threema offers perfect forward secrecy: Yes, Threema provides forward secrecy on the network connection. Client and server negotiate temporary random keys, which are only stored in RAM and replaced every time the app restarts (and at least once every 7 days). An attacker who has captured the network traffic will not be able to decrypt it even if he finds out the long-term secret key of the client or the server after the fact.
- zcam 13y agoAnd it's based/hosted in the US: will not use.
- kintamanimatt 13y agoOther countries are doing wholesale spying too and analogues to NSLs exist elsewhere, albeit without a gag orders, e.g. RIPA in the UK.
- joosters 13y agoSo many dubious claims on just the front page: * 'delivers messages faster than any other application' - any application? Hmmm. They must be using magic. * 'messages are heavily encrypted and can self-destruct' - but like every system, the self-destruction is not assured since it's impossible to enforce. * 'keeps your messages safe from hacker attacks' - a bold claim. Maybe they do some stuff to protect messages, but it's not the perfect safety that this statement implies.
- techquery 13y agoHave you tried the app? I've moved my top-5 chats from WhatsApp just because of speed! The messages are sent really fast. But if you know any other messenger apps for iOS, which are just about so fast, I'll definitely give them a try. Anyway yep, these marketing stuff is a bit too dubious, but what should they write? * is rather fast, faster than some applications * can self-destruct, but sometimes can not (Ha!) * etc That's not the thing that happens in real world nowadays.
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- hbmnn 13y agoRegistered two hours ago and you're taking offense to criticism of their marketing. Coincidence?
- n1kh1lp 13y ago> Anyway yep, these marketing stuff is a bit too dubious, but what should they write? How about some benchmarks to support this claim?
- huhtenberg 13y agoLooking at [1], it has several red flags. The replay protection is overly complicated and doesn't kick in after the message is decrypted. This makes it possible to DoS the server with forged messages. Key derivation uses a custom scheme. Typically there's no reason NOT to piggy-back on existing schemes and there's plenty to choose from - from TLS to IKE. Also, as already mentioned, there's again NO reason not to use TLS in Anonymous DH mode with an app-level authentication of the session handshake. Designing your own crypto protocols is a very interesting challenge, but for practical purposes you just have to recycle existing designs. There's really no other way about it. A custom crypto doesn't make any difference for those who doesn't know/care about it, but it certainly will not make you any friends between those who does. Unless, of course, you can explain and prove why your design is better than those that exist already, and these guys don't do this. [1] http://core.telegram.org/mtproto/description http://core.telegram.org/mtproto/description
- kpierre 13y agomake sure to check out their structure definition language: http://core.telegram.org/mtproto/TL-dependent http://core.telegram.org/mtproto/TL-dependent look like a great parody to me? can't tell if they are serious with these 'dependent types'
- TelegramApp 13y agoIs anything wrong with it?
- kpierre 13y agoit's ridiculous, pseudo-mathematical, and a severe case of NIH syndrome :-) Peano numbers for data definition language? are you serious?
- Confusion 13y agoYou can drop the first two. And the third can have different motivations: I think here we just have a mathematician with sufficient time on their hands who enjoyed coming up with this. I think the primary valid complaint is: overly complex for its task.
- jeswin 13y agoLooks like they kept the interface exactly the same as What's App to attract users. The smiley selection has the entire list of What's App smileys in exactly the same order. What's App is going to be upset, but it might help users.
- arianvanp 13y agoI always that it was just the order of the emoji unicode range
- VMG 13y agoI think it is, the default android keyboard is using the same emojis
- onedev 13y agoThe authors are also the founders of the social network VK which is pretty much a Facebook clone design-wise[1]. [1]http://en.wikipedia.org/wiki/VK_(social_network) http://en.wikipedia.org/wiki/VK_(social_network)
- grandpoobah 13y agoWhere's the desktop app? I guess I'm old fashioned, because I'm looking for the next msn/icq.
- okso 13y agoThere is one, it's the CLI (Command-line Interface : https://github.com/vysheng/tg https://github.com/vysheng/tg)
- prepin 13y agoMac https://itunes.apple.com/us/app/messenger-for-telegram/id747648890?mt=12 https://itunes.apple.com/us/app/messenger-for-telegram/id747... Win https://tdesktop.com https://tdesktop.com
- litemn 13y agowin - https://tdesktop.com/ https://tdesktop.com/
- ingenter 13y ago>Q: Who are the people behind Telegram? >Telegram is supported by Pavel and Nikolai Durov. I would not trust social network owner with my messages.
- josu 13y agoThis is what the wikipedia says about Pavel[0]: >Durov holds libertarian economic and political views and says he is a vegetarian and identifies as a Taoist. He published anarcho-capitalist manifestos describing his ideas on improving Russia. On his 27th birthday, he donated a million dollars to the Wikimedia Foundation. Well, I think I'd rather trust them than Google or Facebook, after all, you've got to trust somebody. [0] http://en.wikipedia.org/wiki/Pavel_Durov#Personal_life http://en.wikipedia.org/wiki/Pavel_Durov#Personal_life
- chippy 13y ago> you've got to trust somebody. Better the devil you know?
- deleted 13y ago[deleted]
- subb 13y agoHow can this be free? They're not Wikipedia. I'm not sure how they can pay for multiple servers...
- macalicious 13y agohttp://telegram.org/faq#q-how-are-you-going-to-make-money-out-of-this http://telegram.org/faq#q-how-are-you-going-to-make-money-ou... The brothers do have some money, I suppose, from their company. However, I'm not sure if they are using the data gathered from this service, thus resulting in revenue somehow (maybe in their social network).
- okso 13y agoI see source code for clients, but nothing for the server side. Are they using something standard or do they want to lock-down users to their own proprietary servers ?
- __alexs 13y agoTheir HTTPS server isn't configured with the right certificate :( Firefox gives me "The certificate is only valid for the following names: *.stel.com , stel.com" for https://telegram.org/ https://telegram.org/
- chrj 13y agoThe link isn't for https://telegram.org/ https://telegram.org/.
- dchest 13y agoLooks fine https://www.ssllabs.com/ssltest/analyze.html?d=telegram.org&hideResults=on https://www.ssllabs.com/ssltest/analyze.html?d=telegram.org&...
- TelegramApp 13y agoThanks for noticing, we fixed that yesterday.
- adnam 13y agoSnake oil
- adventured 13y ago"How is Telegram different from WhatsApp? Unlike WhatsApp, Telegram is cloud-based" Yeah, ok. Decided not to use it right there.
- seanhandley 13y ago"Cloud based" eh? Very secure.
- seanhandley 13y agoand apps on iOS and Android - no possible way data could leak there.
- yeukhon 13y ago> Telegram is decentralized! Great. Then... > Telegram servers are spread worldwide for security and speed. So this is what they mean by decentralized.... > As a result, Telegram is the fastest and most secure messaging system in the world And this has exist for how many years? I can probably say everything except private message, google hangout or Facebook chat is already doing it. They have some of the top-notch security, network and distributed system developers and they have their own cable delivering more volume than your new service can combine together. and if I want true privateness? I'd one-time pad everything. in reality, I guess PGP is good enough.
- lazyjones 13y ago> I can probably say everything except private message, google hangout or Facebook chat is already doing it. They have some of the top-notch security, network and distributed system developers ... and they are based in US of NSA - no thanks.
- yeukhon 13y agoAs an American I fear the NSA but at the same time to be fair, NSA is not the only intelligence doing this sort of work. Let's be fair, every other governments are doing similar things anyway, so maybe we should say no thanks to every other website.
- jokoon 13y agoI don't understand, how is this thing on top of hacker news, while it's being deconstructed like it's a toy ?
- maigret 13y agoMy suspicion: peoples with little idea on the topic vote it up, while the knowledgeable vote it down.
- Ihmahr 13y agoPeople here are complaining a lot about this app, and rightfully so. However, this is definitely the best encrypted communications app there is for ios and therefore also the only app that is cross platform and able to reach a wide audience. I know they didn't do it completely right, but it definitely seems to be the best option that is currently available.
- ge0rg 13y agoAn "encrypted communications app" that is not using secure encryption is worse than an unencrypted one - the users get a fake feeling of security, and might reveal sensitive information to whoever is listening. Regarding real security, have a look at ChatSecure, which is available for iOS and Android, uses standard encryption protocols (XMPP with TLS, OTR), is open source, and was developed by the Guardian Project (who have a track record of developing security software): https://itunes.apple.com/de/app/id464200063 https://itunes.apple.com/de/app/id464200063 https://play.google.com/store/apps/details?id=info.guardianproject.otr.app.im https://play.google.com/store/apps/details?id=info.guardianp...
- Ihmahr 13y agoYes, I have been using chatsecure and I know it is much more secure but it is almost unusable on ios because it can not run in background. As for the false sense of security, you're probably right.
- ge0rg 13y agobut it is almost unusable on ios because it can not run in background Unfortunately, the only way around that is to integrate with Apple's Push Service, which means you need to run a server-side component which notifies Apple (and which in turn notifies your app). This is not specified for XMPP, so most "XMPP clients" for iOS instead store your credential on the app developer's infrastructure. However, this problem is being worked on: http://legastero.github.io/customxeps/extensions/push.html http://legastero.github.io/customxeps/extensions/push.html
- alonium 13y agoWow, there are so many cryptography experts with world names in this thread! And interesting why you think that it's not possible to read most of cryptography/cryptanalysis books and check common mistakes of implementation afterward? Do you really think that this is THAT hard? Your scepsis would be understandable if they used OWN cryptoalgorithm. However their protocol is based on well known strong crypto.
- rblaze 13y agoYes, it's THAT hard. I'd read many good books and still feel bad looking on my first attempts in protocol design. BTW, IGE cipher mode isn't well known for being strong.
- dspillett 13y agoThere is a lot more to secure protocol design than just stringing together commonly accepted standards, unfortunately. There are a great many ways you can all gaps which mean a hacker can circumvent your security arrangements, and we are sceptical because we've seen it done wrong so many times before that it is healthier to take the pessimistic view (assume it is wrong and be pleasantly surprised if it isn't, rather than unpleasantly surprised if/when it turns out not to be).
- artellectual 13y agowhy does HN comments have to be so negative all the time? its very depressing to read through HN comments.
- sparkie 13y agoBecause intelligent, educated folk don't blindly accept the claims of others without scrutinizing them? I don't see it as negativity. People are bringing attention to the details that marketers typically omit (perhaps intentionally). If anything, these are positive discussions as we're sharing our own views and experience to give others more information to allow them to make more informed decisions. (i.e, whether the claims of security can be trusted in this case.) If you want comments that are always happy and positive about every claim made by marketers, there's plenty of other places on the web for that.
- yxhuvud 13y agoHow about desktop clients? Being restricted to mobile devices is not very practical.
- solarmovement 13y agoMac OS X desktop client is available in the App Store
- motters 13y agoIf this is closed source (and the source seems to be only implementing API calls to a closed system) then it's fair to assume that this application is probably insecure or has backdoors. Also if the private key is stored in the cloud then it's likely to be subject to requisitions.
- TelegramApp 13y agoPrivate keys for secret chats are only stored on the two participating devices. As for server code — open sourcing the server code wouldn't really do much to improve trust. You would still have to trust us that we are using THAT code, not something different.
- garethadams 13y agoDepending on your definition of "decentralised", open sourcing the code would enable other people to set up servers that they can trust is running that code.
- gwu78 13y ago"... open sourcing the server code wouldn't really do that much to improve trust." It would allow people to run your code (if they like it) on their own servers. Then they wouldn't need to trust you.
- anix 13y agoBtw, whatever happened to Heml.is? They've been totally quiet over 2 months, but I really hope they're getting somewhere.
- betterunix 13y agohttp://telegram.org/privacy http://telegram.org/privacy That such a policy even exists should suggest that "secure" is the wrong way to describe this. Reading through this, it looks like yet another attempt at what Lavabit and Hushmail were trying to do. In other words, snake oil.
- kristopher 13y agoNot sure how uploading all of your contact information to their servers counts as "taking back our right to privacy."
- ge0rg 13y agoI have not run the app, but from the Android source code it looks like this "secure" app is uploading your contacts including full names and all their phone numbers into the "cloud": MessagesController.readContacts() [0] is called on creation of the MessagesActivity. When invoked for the first time, it collects first names, last names and phone numbers from the Android Contacts interface, creates a table containing the data, and passes that to importContacts() [1], which performs an RPC call to "the cloud", passing the contact list upstream and obtaining a server-processed list as a reply. For me this is a major trust breach, and makes all the fuzzy claims about the app's security absolutely worthless. [0] https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/src/main/java/org/telegram/messenger/MessagesController.java#L555 https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/... [1] https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/src/main/java/org/telegram/messenger/MessagesController.java#L1323 https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/...
- TeeWEE 13y agoThey need todo this to know which numbers are also using Telegram. Whatsapp does the exact same thing.
- ge0rg 13y agoSorry, but this is just a lame excuse. There is no need to upload the personal names for this feature. Also, there are approaches to make number registration lookups more secure, e.g. bloom filters: http://en.wikipedia.org/wiki/Bloom_filter http://en.wikipedia.org/wiki/Bloom_filter I would expect such an approach from a "secure" app.
- TeeWEE 13y agoEverybody is so negative here. Ok rolling your own security protocol might not be the best move. However, they want to be competetive with whatsapp. Most people who try to make a whatsapp killer suck in uix. But this app is really good and fast. I think its better than whatsapp in a multitude of terms. Okay, there are improvements. But I can submit a pull request to the android app and improve it myself! How Awesome!
- haarts 13y agoI fully agree. Everybody can surely agree this is vastly better that WhatsApp despite it's shortcomings.
- utnick 13y agoA lot of haters in this thread. To be expected. I've been following this space for a while and telegram is the best app out there right now. The usability is great and they are trying to do the right things when it comes to security. The apps are open source and can be audited. I fully expect there to be bugs, that is part of the process! You would be insane to trust your life to a crypto app thats been around a few months. So yes, there will be bugs. But that doesn't mean they should just give up. In a few years this could turn into a really nice , secure app. I think their big competition will be: Textsecure, also a great app and better for security due to OTR. But the iphone app is still in development as is their data channel. Once those are complete, they could take the #1 spot. Also, hemlis is one to look out for. But they take about the same security approach as telegram but seem to be less open so far.
- salient 13y agoThey are making a lot of bogus claims using marketing speak, and they are very low on details, while saying the app will be opensourced "eventually". For a "security" app, hell yeah you should be skeptical. Right now I think the most interesting and most trustworthy secure messaging projects are TextSecure v2 and Dark Mail (granted, that one isn't even out yet, their ideas so far sounded quite good).
- mahyarm 13y agoBut the clients are open sourced: http://telegram.org/source http://telegram.org/source
- anu_gupta 13y ago> In a few years this could turn into a really nice , secure app. And that would be a better time to market it as "very secure"
- Confusion 13y agoThe point of most 'haters' is that trying to do the right thing isn't good enough.
- bound008 13y agoOpen != API
- bound008 13y agosorry... did not see that the source code is available for all platforms including iOS.
- aet 13y agoHow does this operation make money?
- talles 13y agoWhere have I seem this logo before...
- andyl 13y agoHow does this compare with Wickr?
- moxie 13y agoThe reason that cryptographers laugh at people who advertise "military grade cryptography" or "we use AES256" is because the choice of crypto primitives is often less important than how they're composed. Those phrases tend to reflect a critical misunderstanding of that, and often mean that a project is using secure primitives in a way that completely undermines their security. At a glance, while this project is using secure (if aging) primitives, they've made some extremely unusual protocol choices that they need to publicly justify rather than simply describing in an API doc. Just at a glance, the use of modes like Infinite Garble Extension (a failed mode for Kerberos) is troubling, they made up their own KDF (with no proof), and they make what appear to be some amateur mistakes with how they use RSA. I'm obviously biased, but if you want a mobile-oriented asynchronous messaging protocol, at this point I think the Axolotl ratchet should absolutely be its basis: https://www.whispersystems.org/blog/advanced-ratcheting/ https://www.whispersystems.org/blog/advanced-ratcheting/ If Telegram folks are on this thread, I'd encourage you to take a look at the TextSecure protocol. If you think it's interesting, you can federate into our network, get a provably secure asynchronous forward secrecy protocol, and also have access to an existing 10MM user base.
- zmanian 13y agoI'd immediately adopt a cloud messaging system from whisper systems. Always find your critiques extremely informative. :-)
- TelegramApp 13y agoTwo questions for you: 1. Kindly be more specific about our RSA implementation. Please note, that we only use RSA with public keys, not private. If you are aware of any possible attacks on this setup, please let us know. 2. And what problems with IGE are you aware of? Any known attack? As far as we know, it is the ubiquitous CBC that has had issues. And by the way, Kerberos had to abandon PCBC - not IGE. Thank you for the offer to join in the project you represent. However, we feel that what we are doing is going in a somewhat different direction and has its own potential. The team behind Telegram, led by Nikolai Durov, consists of six ACM champions, half of them Ph.Ds in math. It took them about two years to roll out the current version of MTProto. Names and degrees may indeed not mean as much in some fields as they do in others, but this protocol is the result of thougtful and prolonged work of professionals. The basic copy on telegram.org rightfully appears as simplistic to the Hacker News resident. It was written for the general public, since we want to bring secure messaging to the masses — not just to the security geek, who has it already (in oh so many forms). But for the technically minded we provided rather detailed documentation for our protocol: http://core.telegram.org/mtproto http://core.telegram.org/mtproto and API: http://core.telegram.org/api http://core.telegram.org/api We would be glad to respond to criticism, but not on the level of "I looked at it for 4 minutes, maybe they didn't think about X" (as another guy in the comments below put it), or "why didn't you just use this?". If anybody here can identify a specific point and prove that it is vulnerable and can be hacked a certain way, we are ready to respond and\or fix, if neccessary. Gentlemen?
- herge 13y agotptacek should write up a block like http://craphound.com/spamsolutions.txt http://craphound.com/spamsolutions.txt for everytime somebody rolls up their own crypto solution.
- xolve 13y agoThis is not distributed at all. IRC is distributed. Messages stored on cloud! Big privacy problem. Just tall marketing claims.
- eliteraspberrie 13y agoThe authors' education credentials are impressive, and I admire their initiative. However, they do not seem to have employed a cryptographer to review their design and protocols, so I expect that serious security problems will be discovered. Personally, my expertise is rather in application security, so I will review some of the source code over the holidays. At first glance the C client is not bad. The real metric of this project's success will be how they react to criticism, harsh as it may be. I hope they learn from their inevitable mistakes and succeed in the long term.
- deleted 13y ago[deleted]
- ssewell 13y agoRandom observation. What's with the crossed out "h" in chats on the landing page?
- asadlionpk 13y agoDevs of this app: Don't be disappointed by these harsh comments because most of them contain technical fixes you need to do asap! These suggestions, if implemented/fixed will surely get you some really dedicated early adopters!
- niketas 13y agoTo whom it may concern: Pavel Durov, one of the authors of Telegram, announced he will pay $200K (or 200 BTC) to decrypt his traffic http://tjournal.ru/paper/durov-decifer-telegram http://tjournal.ru/paper/durov-decifer-telegram
- ash 13y agoYes, but not yet. He plans to announce the reward in a week. No encrypted traffic published yet.
- totty 13y agonice