4 ms·
I briefly looked at Telegram's crypto code a couple months ago. Here's a few funny things I spotted: Telegram's message format uses ambiguous padding, so they
by sweis 11y ago
I briefly looked at Telegram's crypto code a couple months ago. Here's a few funny things I spotted:
Telegram's message format uses ambiguous padding, so they have to try all padding lengths when validating a message:
https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/src/main/java/org/telegram/messenger/HandshakeAction.java#L346 https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/...
That loop leaks timing information, as does the "Utilities.arraysEquals" method it uses. I'm not sure if it opens up a timing attack, but it's suspect:
https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/src/main/java/org/telegram/messenger/Utilities.java#L283 https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/...
There is another spot where they pad with zero bytes without any authentication. This may leave room to mess with the protocol:
https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/src/main/java/org/telegram/messenger/HandshakeAction.java#L261 https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/...
There are also some weird things throughout the code, like using SecureRandom.nextDouble() all over:
https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/src/main/java/org/telegram/android/SecretChatHelper.java#L1531 https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/...
https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/src/main/java/org/telegram/messenger/HandshakeAction.java#L164 https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/...
- Kiro 11y agoWhat does leaking timing information mean?
- m_mueller 11y agoResponse timing can be indicative of the key, especially if you have the crypto algorithm's code (source/IR/machine code).
- sweis 11y agoNate Lawson has a good explanation of timing attacks (against my own code): http://rdist.root.org/2009/05/28/timing-attack-in-google-keyczar-library/ http://rdist.root.org/2009/05/28/timing-attack-in-google-key...