14 ms·
$300k for Cracking Telegram Encryption
- cpt1138 12y agoHave the Nigerian 419 scams gotten more sophisticated? "Your email must contain: . . - Your bank account details to receive the $300,000 prize."
- bhhaskin 12y agoWhat....
- dwild 12y agoIn order to get the amount, you need to send an email to the secret email of the message, containing your bank account details. Nigerian prince scam also say that.
- bhhaskin 12y agoI get that, but i can't believe anyone that can crack encryption would send their banking information over email.
- dvl 12y agoand what else I can do with your bank account besides send you money?
- 13 12y agoYou'd think nothing, but people have failed attempting to prove this before. > "But Clarkson admitted he was "wrong" after he discovered a reader had used the details to create a £500 direct debit to the charity Diabetes UK." http://news.bbc.co.uk/2/hi/7174760.stm http://news.bbc.co.uk/2/hi/7174760.stm
- vidarh 12y agoThough the Direct Debit guarantee gives an automatic right to a no-questions asked instant refund. Not even having a provably validly signed mandate protects merchants against a refund (merchants recourse is small claims court), so while it's a nuisance, and while some people do get de-frauded by not paying attention to their statements, the article overstates things: If he "lost" money it'll be because he chose not to demand a refund.
- tptacek 12y agoObligatory: https://www.schneier.com/crypto-gram-9812.html https://www.schneier.com/crypto-gram-9812.html $300,000 isn't a whole lot more than it would cost to get n entire novel cryptosystem for a complex application built out of idiosyncratic components assessed professionally. They should just retain Riscure or Rambus to do that for them instead of the PR stunt. Previous thread about Telegram on HN, featuring Moxie Marlinspike: https://news.ycombinator.com/item?id=6913456 https://news.ycombinator.com/item?id=6913456
- ilghiro 12y agoBut without the PR stunt there wouldn't be PR?
- eksith 12y agoPR stunt has side benefits besides pure security even though the method has shortcomings. Namely, the PR part, which may play a significant role in its actual success. We know for a fact that most people aim for better known than just better.
- tptacek 12y agoThere's the "well known" you get after holding a big contest, and the even better known you get after you're prominently featured in indictments, the way Hushmail and Lavabit were. Not so many news stories about simple OTR.
- ropman76 12y agoMaybe restating the obvious, but why don't they pay out the 300k to some professional pen testers or cryptography auditors and publish the results. At least then they would have a shot at validity in this area.
- santialbo 12y agoFree PR
- higherpurpose 12y ago"Security audit firm finds 9 flaws in Telegram" doesn't seem quite as a compelling as "Telegram is willing to give anyone $300k to 'break its crypto'".
- cissou 12y agoMaybe they did?
- Tehnix 12y agoThey could do that: Pay $300k for professionals to maybe or maybe not find something, and get limited PR Or, what they do now: Get good PR and if someone manages to win the competition, it means they found flaws which the pros would, hopefully, also have found. If no one wins, they can then use the $300k to get pros on it. Win-win if you ask me.
- owenmarshall 12y ago> Win-win if you ask me. For the company, maybe. If you're a user of their half-baked crypto you're playing a high stakes game with a partner that isn't actually interested in keeping you safe.
- electic 12y agoI give them, or anyone, credit for trying to create a secure messenger. It is not easy. However, I just wish they would release the source code to their clients and server. They have not. That would go a long way.
- tptacek 12y agoBoth OTR (ChatSecure on your phone) and TextSecure are good options. Telegram is not a good option.
- deleted 12y ago[deleted]
- WhitneyLand 12y agobecause...?
- sarciszewski 12y agohttp://www.cryptofails.com/post/70546720222/telegrams-cryptanalysis-contest http://www.cryptofails.com/post/70546720222/telegrams-crypta... Because the designers have their heads firmly planted where the sun doesn't shine, for one.
- justcommenting 12y agoas linked elsewhere in the thread, moxie offers an excellent explanation: http://www.thoughtcrime.org/blog/telegram-crypto-challenge/ http://www.thoughtcrime.org/blog/telegram-crypto-challenge/
- deleted 12y ago[deleted]
- tptacek 12y agoMoxie is right. I barely know him and have no stake in TextSecure.
- higherpurpose 12y agoWhich encryption? The end-to-end encryption that isn't even available by default for the vast majority of its users, or the SSL one?
- mistagiggles 12y agoSlightly off topic, but I really like their icons on their front page. Very reminiscent of the vault boy icons in the newer fallout games.
- astrodust 12y agoThose are reminiscent of 1950s marketing art.
- natch 12y ago>To prove that the competition was fair, we will add a command that returns the keys used for encryption as soon as a winner is announced. So, using a bug-prone process (software development) we will alter the software after the fact to introduce a feature which, if it escapes the sandbox and gets into the wrong build, will potentially reveal the secret keys of all users. Am I reading that right?
- ecaron 12y agoWhen I see contests like this, my first thought always goes to "But do they really have the money to pay me if I figured it out." For big prize payout contests, I'd get a lot more serious if they provided proof that the funds were waiting in escrow until end-date/winner. But I'm probably unnecessarily suspicious of the depth of a startup's pockets...
- Geee 12y agoIt's not a 'startup'. It's a project by the founders of VK, and they surely have deep pockets.
- Sambdala 12y agoEven ignoring that $300k isn't that much for most companies, there's insurance for big prize payouts where you'd pay the expected % time you'd have to pay out times the prize amount, plus a vig for the insurance provider.
- bascule 12y agoThey already paid $100,000 for finding flaws in their system before: https://vk.com/wall-52630202_7858 https://vk.com/wall-52630202_7858
- jturolla 12y agoThis contest is only valid if they provide access to their servers and databases. They will never prove, this way, that Telegram cannot crack itself.
- michael_h 12y agoWell: ...this time contestants can not only monitor traffic, but also act as the Telegram server and use active attacks
- deleted 12y ago[deleted]
- VikingCoder 12y ago> Your email must contain: > - Your bank account details to receive the $300,000 prize. Uh, no.
- orasis 12y agoBruce Schneier on Crypto Cracking Contests (1998) - https://www.schneier.com/crypto-gram-9812.html https://www.schneier.com/crypto-gram-9812.html
- eliteraspberrie 12y agoIf no one wins the contest, it proves nothing. But contests like this are a bad idea for another reason: people will hoard bugs instead of disclose, sometimes for years. For example, the Pwn2Own contest boosted the discovery and disclosure of bugs in browsers for the first few years, but now companies have co-opted it into a marketing event. They sit on exploits in order to win two or three years from now. I noticed a bug in one of the Telegram clients when the first contest was announced, but it wouldn't have qualified. Now the reward has tripled, and the scope expanded. As the user base grows, the reward will go up again (and again), and I'm sure no one will claim the bug since real experts have better things to do, so maybe it's smart to wait, maybe not... Telegram, and other projects thinking of doing this: think small. In the lottery model, there is one big winner; you should prefer a model with many (smaller) winners. Pay for patches that improve the quality of the code base, fix compiler warnings, improve documentation, etc. Many grains of sand will sink a ship.
- rthomas6 12y agoThe comments here are showing me that this contest is a good idea, because everyone is talking about Telegram. It doesn't matter that they're mostly saying they don't trust it. Without the contest, most people wouldn't even have heard of this app in the first place.
- akerl_ 12y agoIt's worth noting that the contest caused people here to talk about how Telegram's model of security and their approach to testing that security have flaws. But as is shown by the fact that they are running this contest, plenty of people who are not here see the contest and believe it is an indication of the trust they should have in Telegram. Otherwise, they wouldn't have run another contest after the response on HN to the last one. The contest is a bad idea because for the people who don't see our discussion here, they will be tempted to trust their sensitive data to Telegram. For lots of people around the world, that trust could put them at risk of serious harm.
- rthomas6 12y agoI should have said "good idea for Telegram". I can see why the contest, and Telegram's general approach, is a bad idea for everyone as a whole, but IMO this is the best advertising $300,000 can buy.
- _jomo 12y agoI have different opinions about Telegram. I like how Telegram is truly cross-platform with the clients being open source and available on every platform. They usually look great and are simple to use, which is why Telegram is the only non-whatsapp IM that more than 3 of my contacts use. It also works with multiple devices connected*, which is another pro against many other IMs. What I dislike is that even though Telegram advertises their messages as "private" and "heavily encrypted" on their landing page, secure chats are NOT the default, do not work in group chats and do not work across multiple devices. I am aware that this requires encryption for every recipient, but that shouldn't be an issue. TextSecure actually came up with a great solution [1] for this. What I also do not understand is why they are rolling their own crypto. They say it's for speed and stability [2], but don't provide any facts or measures. The fact that the server is closed source and the founders coming from VK (a russian Facebook alternative) doesn't make this any better. All in all I consider Telegram a great alternative to WhatsApp, but I wouldn't rely on it for secure messaging. 1: https://whispersystems.org/blog/private-groups/ https://whispersystems.org/blog/private-groups/ 2: https://core.telegram.org/techfaq#q-why-are-you-not-using-x-insert-solution https://core.telegram.org/techfaq#q-why-are-you-not-using-x-...
- scott_karana 12y agoFor the cryptographic newb, can someone explain how this contest is rigged, and destined for failure, like the previous one apparently was? The rules seem much more liberal this time, to my uneducated eyes... Even if it's still a contest in bad faith, why not break it and claim the money?