4 ms·
Why give the prize for not doing what was needed to win the prize, namely reveal the message?
by genwin 13y ago
Why give the prize for not doing what was needed to win the prize, namely reveal the message?
- shawabawa3 13y agoAs others have already said, the prize was essentially meaningless because the terms were so narrow. If the spirit of the prize was "if you break our crypto you win", this guy should win it. If the spirit of the prize was "we don't want to give away 200k, but we want to pretend we're secure", he shouldn't
- ballard 13y agoHoliday banter may go something like this: "Carnival booths, lawyers and politicians maybe the most honest... But there was once this company called Telegram that went the way of its namesake. Blah blah... for screwing over a Russian guy in a PR disaster of an unpaid $200k contest award. Maybe they should have offered a canned ham instead."
- genwin 13y agoI don't get it. If it's not secure why can't the message be revealed? What's the value of breaking someone's crypto if you are still unable to see the data unencrypted? Was the recipe for decryption given, with the actual decryption being much harder (terms so narrow, as you say)?
- alanh 13y agogenwin, I’ve invented a secure system. If you can tell me what this message says, you win $200k: jo You don’t know what the message says, because it’s so short. You will never win the prize. But my system was not so secure. My cipher system was this: Take a message and type it on a US Qwerty keyboard, but shift every letter over one place. So `hi` became `jo`. Not very strong. It would easily be cracked with a message consisting of an actual sentence or two. Now, with Telegraph, it wasn’t just length of the message involved, but additional information; still, the conditions are so narrow that it doesn’t apply to the real world. Just like I’d never simply send you a message that said "hi", Telegraph would be used in ways beyond one simple back-and-forth exchange, so it artificially limits the information available to a cracker. Make sense? See also: The BEAST attack or the general class of side channel attacks.
- na85 13y agoIf you search back a few days of HN posts there was an explanation posted.
- rpedroso 13y agoMoxie's blog post does a better job explaining the problems than I can [1]. Basically, the framework of the contest precludes many avenues of attack to which a given cryptosystem could be vulnerable. The researcher who discovered the vulnerability in the OP used a man-in-the-middle attack, which cannot be used in the Telegram contest.