6 ms·
Another guy has butthurt from Telegram. As I read somewhere telegram guys said that after 1st march 2014 they somehow will allow to perform MITM in that crypto
by alonium 13y ago
Another guy has butthurt from Telegram. As I read somewhere telegram guys said that after 1st march 2014 they somehow will allow to perform MITM in that crypto challenge
- octo_t 13y agoyou sure seem to like Telegram. Also please don't use "butthurt".
- nwh 13y agoIf they allow man in the middle attacks then the system is completely and demonstrably broken. The out of band public key verification uses deterministic images to confirm that the keys are the same, which can be easy forged given the relatively bad comparison engines in use (humans describing what a pixelated 16px image looks like). At no point is the real key shown to the user, so it's impossible to verify that they're identical through a description. http://telegram.org/img/key_image.jpg http://telegram.org/img/key_image.jpg I wager that if they did allow a tampering eavesdropper in their bounty contest, it would be in the same conversation that has already done a key exchange and verification, making it yet more snake oil. You can hardly call something secure when you don't allow real-world MITM attacks in testing.
- utnick 13y agoHow is the key image impossible to describe? There are only 4 possible colors per cell. You just describe it like 0,1,2,3,2,0, etc Just as if you were reading off the real key.
- nwh 13y agoFrom just asking around, most people described the key image to me in terms of the darkest portions and ignored the parts that were lighter. It's easier for the example image to say that there's a dark L and lighter X shape in the center and then assume that the rest is the same. At least, that's how people did when I presented it to them as a challenge.
- velis_vel 13y ago> There's also not that many possible images anyway, there's 8 rows with 8 columns, and 4 possible colours for each pixel. Even not assuming any fuzzy matching (human comparison) it's still very possible to generate keys with colliding image hashes. Uh, 4^(8*8)=2^128 is a pretty large number.
- nwh 13y agoSo it is, I've removed that. I need to sleep more.
- MagicWishMonkey 13y agoPeople need to stop posting his shit here, it's basically linkbait he's using to pimp his Whisper service. He's the worst kind of troll.
- jagermo 13y agoMoxie? He is kind of a real expert in everything crypto and, instead of using the phrase "military grade encryption", WhisperSystems actually explains what they do and how they do it. His posts are very well written and understandable, even for non pros (with a pinch of sarcasm, but that's how I like it). So, where exactly is he trolling?
- jagermo 13y agoMan in the Middle attacks are so easy and cheap to set up. Just use a few wireless access points, pop them up around town, install something like Jasager and a 3G dongle. Phones like to connect with known networks and will happily connect with your rouge access point, if you tell them that you are exactly the ap they are looking for. So, any system that claims to be secure must factor in MitM. More information on this, and how easy it is to trick devices can be found at Troy Hunts website [0] and at Wifi Pineapple [1] [0]: http://www.troyhunt.com/2013/04/the-beginners-guide-to-breaking-website.html http://www.troyhunt.com/2013/04/the-beginners-guide-to-break... [1]: https://wifipineapple.com/ https://wifipineapple.com/