9 ms·
Crowdsourcing a More Secure Future
- growse 13y agoSeems a little.... arbitrary....? Don't people who run bug bounties publish their reward structure beforehand?
- jonknee 13y agoYes, they did. This was not the goal of the bounty, but was still a serious issue. They couldn't give away the prize for the contest and instead decided on a still quite generous $100,000. http://telegram.org/crypto_contest http://telegram.org/crypto_contest
- sillysaurus2 13y agoThis was not the goal of the bounty, but was still a serious issue. To be clear, this bug was enough to compromise the security of every Telegram secret chat session. I can't think of a more serious issue.
- bhitov 13y agoVulnerability to passive attacks is worse than vulnerability to active attacks. I'm not downplaying the severity of a MITM vulnerability, but certainly there could exist more serious issues.
- makomk 13y agoYeah. In essence, it made their nominally end-to-end encrypted secret chat feature no more secure than simply giving the Telegram server operators a plaintext copy of every message you sent and trusting them not to log, read or tamper with it. Worse, it's the kind of flaw you'd expect someone subtly sabotaging the protocol to create. It's a small, superficially plausible modification that turns an apparently secure scheme into something completely broken. Yet if they'd made that modification in the obvious way - by combining the nonce and Diffie-Hellman result with a secure hash function - it wouldn't have caused the problem; for the vulnerability to exist the nonce has to be handled in a very particular way.
- deleted 13y ago[deleted]
- adambenayoun 13y agoOther people claimed that the Telegram team might find that bug to be outside of the scope of their bounty contest, so $100k is better than nothing (and to be frank I'm quite surprised they were _that_ generous). But you're right - they should have a clear reward structure.
- jsumrall 13y agoI thought a lot of people pointed out ways to attack the security protocol if they had physical server access.
- lelf 13y agoWith this bug people who run server have access to your entire chat. (Of course they won't formulate it that way in the post)
- mikegioia 13y agoGood for Telegram. I haven't downloaded and installed their App yet, but I applaud their effort at putting out a secure chat app that everyone can use. I've been using TextSecure for a while (as everyone on HN ruthlessly suggests) but guess how many encrypted texts I've sent? 0. That's because they have no iOS app and very few Android users. There are two problems when it comes to creating a good, secure messaging app: strong, proven security and popularity! Hopefully Telegram either solves both or forces TextSecure to solve the latter.
- sillysaurus2 13y agoI applaud their effort at putting out a secure chat app that everyone can use. They aren't making a reasonable effort to put out a secure chat app. If they were, then they would use some of that $200k to hire a company like Matasano to fly out and audit their architecture for flaws. Matasano probably would've caught this bug, because it was a pretty basic mistake.
- mikegioia 13y agoI don't mean to sound snide, but judging from your comment history on Telegram related posts, are you really the right person to determine what "reasonable effort" means in this context? Every single post you make is biased negatively towards Telegram. What I applaud is their effort here and I hope it continues and moves in the right direction. This announcement makes it seem like they are in fact moving in the right direction.
- sillysaurus2 13y agoThis announcement makes it seem like they are in fact moving in the right direction. Why? Because they're literally paying people to like their product? This developer who found the bug wasn't even trying to get any money. He was, by his own admission, a cryptography newbie who happened to be looking over their protocol and found a serious bug. Now they're throwing money at him. How is that in any way a good thing?
- abus 13y agoThis is actually really generous considering it didn't meet the terms of the contest. They have a long way to go before anyone here trusts them but perhaps we could be more positive and constructive?
- sillysaurus2 13y agoperhaps we could be more positive and constructive? You find DanBC's comment interesting. It explains why there's been a general tone of negativity towards Telegram's security product. https://news.ycombinator.com/item?id=6949842 https://news.ycombinator.com/item?id=6949842
- jes 13y agoI question whether Telegram is actually delighted with how this unfolded. I also think it's disingenuous to call the discovered issue a potential vulnerability. Either it is a vulnerability or it is not.
- sifarat 13y agoBravo Son! you have earned respect for your this deed. Appreciated. On a side note, I am still not sure, if i will ever use this app. This is primarily because, I act on the internet in the same fashion as i do in real life. I won't do anything online, what I can't do in real life. Hence I don't and perhaps would never need an app like this. As for sending someone 'secret' message, I always whisper that in the ears. It's an old fashioned trick but has proven to be most secured.
- im3w1l 13y agoIf someone takes a photo in the street, and you are in the photo, then you will probably not mind. But if someone follows you around everyday and takes thousands of photos, then that is slightly creepy. For me it is the same with my chat messages. If someone reads one or two, I don't mind: they aren't very sensitive. But I don't like it if someone can find everything I've ever written.
- sifarat 13y agoIt's not about being creepy, it's about having enough time on hands and why. I would be interested to find someone, who values taking 1000s picture of mine than his time spent making money for himself. In the case of celebrities for instance, they have almost their entire life public, and i don't think it had harmed them any way, unless, they committed something illegal and it was made known. People over the internet, are little too much over-sensitive. I am not implying 'Privacy' has no value, but we have taken this issue bit too far over the 'internet'. A prime example of so-called 'anonymity' over the internet is 4chan, you pretty much know what sort site that is. I am not implying it's an illegal website, but frankly, anonymity mostly leads to creepy, drugs (silkroad), and everything else considered wrong and bad, than something good which is pretty rare. Snowden is an exception, but again, he committed a crime for a good cause. Most people however commit a crime for every possible wrong reasons.
- m_mueller 13y agoThese latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. I have one question that doesn't seem to be covered anywhere (FAQ, Google): What about Offline messages? I'd like to be able to send encrypted messages even when people are offline - on smartphones it could make use of push notifications, on the Desktop it would just wait until the client goes online again. Skype doesn't work reliably for this scenario, as in both clients (for the sender even the same client on the same device) need to be online for the message to be sent. The last implementation that worked reliably seemed to be MSN, which is dead now. How does Telegram behave?
- sillysaurus2 13y agoThese latest news have convinced me that Telegram currently has the highest potential to be the right IM tool at my current workplace. Why is that? This latest revelation should give less faith in Telegram, not more.
- m_mueller 13y agoSee my replies to makomk and ceejayoz.
- ceejayoz 13y agoReally? The fact that they addressed security concerns with "they're bullshit, here, we'll prove it - break out system!" and then had to pay out nearly immediately convinced you they're awesome?
- m_mueller 13y agoYes it does. Show me another non-profit Open Source (mostly) IM service that invests this heavily in seamless encryption and I'll change my opinion. The weakness that they found could have easily been brushed off as non-exploitable, yet they didn't, instead encouraging more security experts to become involved by paying out immediately.
- s1kx 13y agoWhile it is very generous, I doubt they would give a sum like that if it wasn't for the publicity. I'm sure news like this can help their image quite a lot in their target audience (security-aware computer people).
- h0cked 13y agoI actually have a theory that this is all a scam... the person who found the bug is actually the authors (or a friend) of the Telegram protocol. They published the security issue and reward themselves so that 1) they don't have to pay anyone else; 2) they get good publicity by doing this; 3) shut others up up front as this is really a very easy bug to figure out (a few others hinted the possibility as the key exchange is unautenticated DH, which is bound to flaws like this)
- pearjuice 13y agoWhat I don't understand is: where do they get the money from if their intention is to be "free forever"? Are they funded by a non-profit incubator? Why is it that a "new" app spends relatively much money on white-hat hacking bonuses? What do they get out of this other than a deemed secure application?
- h0cked 13y agoThe same reason as why Google provide Gmail for free, 1) to get a huge user base (fame = money, in today's internet world; 2) get a hold of user data
- deleted 13y ago[deleted]
- oskarth 13y agoThe developer who found the potential weakness has earned a reward of $100,000. We have contacted him to find out how he would like to collect his prize. This is great news. Contrast this with other security contests were finding out-of-scope security flaws weren't rewarded. People in this thread: Good for Telegram, seems arbitrary, disingenuous, just for publicity. Short of them being in a conspiracy with the researchers, I can't imagine how this is not good news for everyone. Cool it with the hate, people.
- sillysaurus2 13y agoCool it with the hate, people. There's no hate for Telegram here. There's concern for people's safety. https://news.ycombinator.com/item?id=6949842 https://news.ycombinator.com/item?id=6949842
- oskarth 13y agoI don't think you actually read the article. This article is good news, precisely because they show how willing they are to improve their service. EDIT: Of course it's good PR. So what? That's how Google, Apple and most other big companies operate. They don't have to be altruistic to work and create value for people.
- sillysaurus2 13y agoIt's an impressive sum of money. Have you considered they're doing this for marketing purposes, not out of concern for people's security?
- surreal 13y agoSo what? They're still doing it. Unless it turned out they'd set the whole thing up, which would be different.
- bushido 13y ago> Unless it turned out they'd set the whole thing up That's an important question, really curious to know if the user x7mz steps up to take the reward and if telegram would release any proof of payment (minus any obvious info that would give away the identity of x7mz). This vulnerability seems to be connected to Diffie-Hellman, right? Even a rudimentary search shows that a MITM is easy on it. I wonder if its even possible that they did not know this one?
- nly 13y agoGiven the complexity of bug this in cryptography terms, this was an astonishingly easy earner. Insanely complex software bugs go for less.
- deepuj 13y agoIf Telegram is a non-commercial project, who is funding this bounty?
- jzwinck 13y agoFor the original "$200K" bounty, it was stated that it would be paid out in bitcoin. So it's quite possible that the person or organization funding the bounty simply has some old bitcoin laying around, and it cost them next to nothing to get it initially, and it might even be difficult for them to exchange for their preferred fiat currency today. So don't think of it as "Somebody just spent $100K," think of it as "A bitcoin speculator just traded some coins that were not worth much two years ago for something that is pretty darn valuable today."
- alphakappa 13y agoTelegram is backed by Pavel Durov who offered the $200k in non-bit ion currency too in a previous thread here.
- Alexx 13y agoPavel Durov - https://en.wikipedia.org/wiki/Pavel_Durov https://en.wikipedia.org/wiki/Pavel_Durov
- blahbl4hblahtoo 13y agoWow...Telegram. The only thing you will ever get from engaging the "public" on forums like HN is heartache. You will never get them to like you...they just aren't that in to you. Contact people that are actually in the crypto community and go the normal route. Once their betters tell them to love you there is actually nothing that you could do to make them stop.
- lttlrck 13y agoMaybe they should give him a job too.
- rb2k_ 13y agoSlightly off-topic, but here it goes: I always get a bit annoyed when apps use the phone number as the primary identifier. As somebody that just moved to another country, I now end up with a situation where I can either decide to lose my German whatsapp friends or not being discovered by my American whatsapp friends. I would love to see the ability to get some sort of ID number and then being able to register more than 1 phone number with it.
- vitoreiji 13y agoI read somewhere that moxie is planning that feature for TextSecure.
- infinity0 13y agomoney is cheap, show me the code. even if people are being unfair with these criticisms, what telegram should focus on is to make their designs more secure, and ignore all this publicity. if they truly believe in the "importance of keeping the [system] open", then they should understand that all this publicity (good or bad) is insignificant - especially as they say they have rich guys backing them, so they're not relying on public opinion influencing investors. it's very easy to make statements like "Together we can make Telegram unbreakable"; harder to turn this into a reality. the current round of attention is a red herring, both for Telegram and for us commenters. let's give them a year and see what it's like after that.
- josephlord 13y agoThis is still in the FAQ: Q: How secure is Telegram? Very secure. We are based on the MTProto protocol (see description and advanced FAQ), built by our own specialists, employing time-tested algorithms, to make security compatible with high speed delivery and reliability. At this moment, the biggest security threat to your Telegram messages is your mother reading over your shoulder. We took care of the rest. While Telegram may be on the way to a secure future it is not there yet and the FAQ needs to be less certain before I can applaud them. Edit: Actually I think the FAQ been toned down a bit but I think some acknowledgement of how new the protocol is and the risks associated with that should be mentioned.
- csomar 13y agoQ: How are you going to make money out of this? We believe in fast and secure messaging that is also 100% free. Therefore Telegram is not a commercial project. It is not intended to sell ads, bring revenue or accept outside investment. If Telegram runs out of money, we'll invite our users to donate or add non-essential paid options. Yeah, but where does there money come from?
- chrislloyd 13y agoPavel Durov[1]. Net worth $260MM[2]. [1] http://telegram.org/faq#q-who-are-the-people-behind-telegram http://telegram.org/faq#q-who-are-the-people-behind-telegram [2] http://en.wikipedia.org/wiki/Pavel_Durov http://en.wikipedia.org/wiki/Pavel_Durov
- kolev 13y agoThere are a lot of haters of Telegram on HN and I think one of the reason is that they are a Russian company or the fact that a Russian developer found the flaw first. :) But wasn't Pavel Durov the one who offered Edward Snowden a job back then? There are many "secure messaging" apps out there, but they all suck in terms of UX. Telegram looks nice and will only get better. Also, they have an API since day one. Show some respect!