6 ms·
$200,000 to the first person to break Telegram
Telegram backer, Pavel Durov, will give $200,000 in BTC to the first person to break the Telegram encrypted protocol. Starting today, each day Paul (+79112317383) will be sending a message containing a secret email address to Nick (+79218944725). In order to prove that Telegram crypto was indeed deciphered and claim your prize, send an email to the secret email address from Paul’s message.
Your email must contain:
- The entire text of the message that contained the secret email.
- Your Bitcoin address to receive the $200,000 in BTC.
- A detailed explanation of the attack.
Encrypted Telegram traffic from and to Paul’s account is publicly available for download from this page. You can send Telegram messages to Paul and view his traffic in real time.
To prove that the competition was fair, we will publish the participating keys necessary to decrypt the traffic as soon as a winner is announced. In case there is no winner by March 1, 2014, encryption keys will be published at that date.
- GigabyteCoin 13y agoSurprising they didn't prove that they actually control $200k worth of BTC when it's so gosh darned simple to do so. How do I know they are being honest? They should have signed that blog post with their BTC wallet.
- nilkn 13y agohttp://en.wikipedia.org/wiki/Pavel_Durov http://en.wikipedia.org/wiki/Pavel_Durov http://www.complex.com/tech/2012/08/the-25-richest-tech-entrepreneurs-under-30/pavel-durov http://www.complex.com/tech/2012/08/the-25-richest-tech-entr... I don't think money is going to be a problem here.
- helgidub 13y agoSo yeah guys, Pavel Durov saw your comments regarding security of Telegram messenger. Go for it.
- pstuart 13y agoAll the haters here can go pound sand. It's a cool project, and I like the mindset behind it: https://telegram.org/faq#q-how-are-you-going-to-make-money-out-of-this https://telegram.org/faq#q-how-are-you-going-to-make-money-o...
- sergiotapia 13y agoOf all the software branches out there in the world, crypto's are by far the coolest and scariest in my opinion. They wield obscure knowledge, have long beards, a white van full of tech, communicate in some obscure protocol with each other - oh man. :) I'm really excited to see if this is cracked!
- igindin 13y agoAnd what if not?
- poolpool 13y agoThis is $200,000 in bitcoins, not actually $200,000.
- logicallee 13y agowhat do you think the definition of "$200,000 in bitcoins" is?
- poolpool 13y agoI think it means its 200k in "bitcoin" thats near impossible to cash out at such volumes. So I think this is a PR stunt and nothing more. Rolling your own encryption has always been proven to be the worst idea.
- Sambdala 13y ago$200k in Bitcoin is relatively easy to cash out without affecting the market much these days.
- eknkc 13y agoYou can easily cash that out today. $200k is not a huge deal.
- igindin 13y ago200k USD will be paid in BTC
- citricsquid 13y agoThere's more than enough volume on any established exchange. $200,000 is roughly 380 BTC at the current price on Bitstamp (~$530). If you were to sell 380 BTC now on Bitstamp there are enough buy orders for the entire sell to be filled before the price got to $525.
- paveldurov 13y agoIf you don't like BTC and other cryptocurrencies, we will be happy to transfer regular 200,000 USD to you after you win. It's up to you.
- r-s 13y agoTravel to russia, get big wrench and hit Durov with it until he gives up his password. Win 200k. In all seriousness, im interested to see if anyone can crack this.
- helgidub 13y agoHe is in US now.
- carmaa 13y agoYep, in San Jose.
- conductor 13y agoIf I remeber correctly the Russians indeed have a special term of getting the crypto key in such manner: Thermorectal Cryptanalysis.
- matslina 13y agohttp://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis
- vacri 13y agoA Russian friend of mine mentioned playing in an MMO with another guy called 'Krusk' for a year or so before realising that the other guy was also Russian, and 'Krusk' was the anglicised version of the Russian word for "the sound bones make when you crush them"...
- exit 13y agoso the winner is allowed to remain completely anonymous, receiving 200k usd payment in btc?
- nwh 13y agoOne would assume that's the point of paying in Bitcoin rather than any other method.
- damian2000 13y agoEnabling an insider who knows how it works to win and not be discovered? Although having to the detail the attack method may prevent that.
- greatestcake 13y agoSome super computer says cool.
- mikeyouse 13y agoAt least they'll put their money where their mouth is. I'm excited to see someone call out the naysaying masses on HN and stand by their product in this regard.
- StavrosK 13y agoUnfortunately, this doesn't mean that it's secure. If someone breaks it, it means it's broken, but if nobody breaks it, it doesn't mean someone else can't break it (or hasn't already).
- mikeyouse 13y agoAgreed, but the tone of the previous discussion was definitely more along the lines of "This could never work, you guys don't know what you're doing." If it proves resilient over 2.5 months of highly motivated attacks (motivated by both the money / "I-Told-You-So" factor), I think that's a fairly strong statement in their favor.
- jnbiche 13y agoExcluding an entity like the NSA, who cares nothing for $200,000 (literally a rounding error in their budget), but everything for the information available for the taking.
- loganu 13y agoWhile I agree with your point, immediately jumping to the NSA and their bottomless pool of resources and talent is kind of the new Godwin's law. Logan's law: In any given discussion tangentially related to security, the thing presented as "secure" will be soon declared "definitely not secure"... because...NSA.
- jnbiche 13y agoI actually agree with the motivation behind your argument -- it's ridiculous to pull out unknown NSA capabilities as a foil to every crypto argument. I just wanted to point out that there were times when money was not a very good motivator for someone who could break a given encryption system.
- jd007 13y agoIs that $200,000 in BTC valued at the time that the award will be given, or valued now? With the way things are going, not sure which would be better...
- deleted 13y ago[deleted]
- nwh 13y agoMost of the concerns people had were Telegram's servers acting maliciously or being coerced into acting maliciously, which is obviously not covered by this contest or the protocol they have designed. It's a bit disingenuous that Telegram is broken but not in a way that this bounty could pay for.
- jacquesc 13y agoYeah, it's probably against the rules of the competition and will get you arrested if you try. But I think if someone does break into their central server and wins the competition that way, they should still be paid out.
- sillysaurus2 13y agoNo, the goal of these security products is to defend against the government, not a random guy. In that context, it's extremely important that their server undergo the same level of cryptanalysis.
- nwh 13y agoWe already know the system is hopelessly vulnerable to server side MITM attacks, it makes no effort to defend against that attack model. It's mentioned in the comments that they might do manual key verification in the future, but that doesn't happen now. Compromise is silent.
- sillysaurus2 13y agoIs that really the case? Would you mind linking to that? Because if that's true, then this contest is dangerously misleading.
- nwh 13y agohttps://news.ycombinator.com/item?id=6924866 https://news.ycombinator.com/item?id=6924866
- patmcc 13y agoDoes the secret email address change every day? Or is it the same one from now until the close of the contest?
- h0cked 13y agoThis is like putting messages encrypted with ANY encryption algorithm, and ask people to guess the key. This has nothing to do with whether the communication protocol is secure or not.
- utnick 13y agoThey are providing the entire log of the protocol communication
- mds 13y agoCryptography Snake Oil Warning Sign #9: Cracking contests. https://www.schneier.com/crypto-gram-9902.html https://www.schneier.com/crypto-gram-9902.html (1999)
- sbisker 13y agoA better discussion from him on the topic is linked to from this page: https://www.schneier.com/crypto-gram-9812.html#1 https://www.schneier.com/crypto-gram-9812.html#1
- cocoflunchy 13y agoExpanded here: https://www.schneier.com/crypto-gram-9812.html#contests https://www.schneier.com/crypto-gram-9812.html#contests
- utnick 13y agoThis contest isn't a great example of the kind of contests he is talking about. 1) They are giving you the source code, protocol, and a tcpdump of all traffic between the chatters. You can even send messages via the protocol to one of the participants. Its not just here is some encrypted data, decrypt it. 2) They are offering a significant amount of money.
- anonymoushn 13y agoRight, except for 2) there are no arbitrary definition of what winning means The definition of winning in this contest creates a large class of potential vulnerabilities that would be paid $0.
- mcosta 13y agoFrom that page: > [...] the contest is fair because 1) the algorithm is completely specified, 2) there are no arbitrary definition of what winning means, and 3) the algorithm is public domain
- deleted 13y ago
- MichaelGG 13y agoThis is such a sham. Here, I'll offer $2000 to break my plaintext crypto. Every morning, in the shower, I'll say a secret word. Email me the secret word and I'll send you $2000 in BTC.
- mcosta 13y agoThe code is open. It's more or less the same if you tell us your address.
- prawn 13y ago"Wet"?
- stefan_kendall 13y agoElephant. I'll take my $2k now.
- vacri 13y agoI'll need to narrow it down further, but I'm pretty sure it's one of "Oh", "god", "groan", "I'm", "running", "late", "for", "work", "again". Hrm, does groan count as a word? How many guesses am I allowed?
- pbhjpbhj 13y ago"Jonathan"?
- TRUPPP 13y agoYou say "cold". I use the same plaintext crypto =)
- TomGullen 13y ago"a secret word"
- suyash 13y agoPLEASE edit the title saying $200K in Bitcoins and not real $.Otherwise it seems link-bait (misleading).
- paveldurov 13y agoIf the winner prefers regular USD over BTC, we will provide USD.
- negamax 13y agoThis is their protocol header <Magic Number (Nonce?)> . <Magic Number> <Number of bytes + 1> IN/OUT <Ip Address>
- joyeuse6701 13y agoMore like epoch time followed by bytes and then IP address
- uonyx 13y agoShots fired.
- feronull 13y ago> 100% FREE & NO ADS: Telegram is free and will always be free. We do not plan to sell ads or introduce subscription fees. how you are then going to make a money ?
- helgidub 13y agoPaid features, like stickers and etc.
- peter_tonoli 13y agoSorry, but how does Google ads mediation have anything to do with stickers and the like? I fail to see the connection.
- nekitamo 13y agoIf you decompile their client you will find code for serving ads. So they must've thought about it at some point: http://i.imgur.com/NA9bO0I.jpg http://i.imgur.com/NA9bO0I.jpg
- CJefferson 13y agoThe problem with this test is that there are many encryption systems I would consider fundamentally broken where I could not claim this prize. To make this a slightly fair challenge, we should at least be allowed to get the clear text of our choice also encrypted with the same key.
- d0m 13y agoSomeone will probably break an employee's computer and will just access private information, good game 200k. And then they will say it's unfair and I'm not paying you. And then HN will go crazy. Mark my word HN.
- josephlord 13y agoThe problem with such a test is that it is a limited attack surface compared with the real app in use. There is a log of messages that are encrypted but there are no possibilities of active attacks such as man in the middle attacks and others that attack the protocol rather than the encryption.
- blahbl4hblahtoo 13y agoNote to everyone in technology...Hacker News isn't the crowd that you need to impress. The cryptanalysis community, in particular, has a small group of experts that can credibly critique your ideas. They would probably love to pick apart a new system...seriously in the hopes that it advances the art, but critically in the case that it doesn't. Claims of some kind of "tightly knit" cabal of closed minded people excluding you would be a warning sign. (It sounds like creationism. Not that this is what these guys did. I'm just saying.) Maybe instead of a competition they could have just approached some of the cryptanalysis community for an early look? Those guys could kick the tires and pass it on to others that they know. That really seems to be how this area works.
- mynameisvlad 13y agoDid I miss somewhere where it stated this was HN-specific? This could just as easily have (and probably has) been posted to multiple communities, including ones that are more crypto-focused. Just because it appears here does not in any way shape or form indicate that they're trying to impress the HN community, nor that they're specifically targeting HN.
- blahbl4hblahtoo 13y agoThis contest is a direct result of some arguments that happened on HN when they announced their product.
- fegu 13y agoI love how Telegram, at the beginning of a secret chat, says og is "200% secure". Right below the graphical representation of the cryptokey.
- tromp 13y agoOnly 200%? That's not good enough for me. I need it 300% secure at a minimum...
- nsa-agent 13y agodone!
- nullc 13y agoIs anyone able to determine whos running this company? All the records seem to be anonymized.
- 11001 13y agoPavel Durov and his brother. Pavel Durov got rich by copying facebook for the Russians. His brother is supposed to be a mathematician/computer scientist.
- deleted 13y ago[deleted]
- legierski 13y agoHow is that supposed to be secure? All I need to snoop on your conversations is access to your phone for 1 minute to receive the activation code and delete message about new device connected to the account.
- eof 13y agoto do this "right" shouldn't they release a hash now of the keys that will be exposed in march; as well as sign a message from a bitcoin address containing ~500btc?
- Dylan16807 13y agoWhy a hash now, do you think they're going to be able to release fake keys that somehow decrypt the cyphertext to email addresses? And converting into bitcoin months preemptively is a speculative gamble, not a verification of anything.
- swami1984 13y agoinb4 post about Schneier and snake oil contests - oh wait!
- mullingitover 13y agoThis would be an easy contest to win: bribe someone at Telegram $100k to help you MITM.
- cypherpnks 13y agoThis contest is a sham. Crypto has to be secure against things like known-plaintext attacks and similar. That's typical in any real-world setting.
- kul_ 13y agoAlthough i have limited knowledge of crypto, but the algorithm seems pretty similar to what is used in SSL with key exchange via DH and encryption via AES. Although i notice that instead of a server clients are doing key creation and exchange which is why Telegram may be calling the architecture 'decentralized'. What is new here, how is it Telegram's own encryption method? Just having a ssl like client to client security model is what is being coined as MTProto?
- earthrise 13y agoThis is a bullshit challenge. The attack model in which it is set is nothing like the theoretical models cryptographic systems are designed to be secure against, and even less like how crypto software is actually attacked in practice. There is no possibility for known plaintext, chosen plaintext, chosen ciphertext, side channels, etc. If they just encrypted their communications with AES-128 in ECB mode with a fixed random secret key, the challenge could not be won. And that's not even semantically secure. So we will learn absolutely nothing about the security of their software from the results of this challenge. Whoever designed this challenge is either extremely dishonest or knows nothing about cryptography. If they really want to improve their software, they should offer a $200,000 bounty for a proof of concept implementation of an attack within their threat model. Edit: I originally started this post with "...probably designed to get press rather than to actually improve the software...", which I have removed, since I have no evidence to support the claim.
- tptacek 13y agoI think this is exactly right. In the model proposed here, TLS has never been broken either.
- deleted 13y ago[deleted]
- memracom 13y agoJudging by the phone numbers, I would say that this is likely to be some form of elliptic curve cryptography with domain parameters different from the NIST and GOST standards. I don't personally have the depth of experience with elliptic curves to go about cracking this crypto, but others have cracked elliptic curve algorithms. Perhaps one of those people will find this tidbit useful in narrowing the field. Also, I would expect that at least some of the plain text is Unicode, probably the plane from 0400-04FF.
- mattbarrie 13y agoThis can only end badly.
- nnx 13y agoI find it cute that the server's IP address as available in the logs is assigned to an organization named "Digital Fortress Corp"
- x0054 13y agoI have a better challenge! From today until March 1, 2014, I will SSH into my server and type a secret email address on the command prompt. Send me an email to that address and tell me my crypto key, and I will allow you to pet my dog for 5 minutes. (Sorry, I do not have $200k in BTC, or any other currency, for that matter :(, but my dog is totally cute.) The point is, the above challenge is impossible without a MITM attack, and that MITM attack has to take place when I first save the server keys on my computer. The point is that there are numerous cryptographic protocols available which can not be broken using currently available technology. This contest will prove one thing, and one thing only, the cryptographic algorithm they are using is secure. And it SHOULD be, considering that there are a lot of publicly available secure algorithms. This contest, however, will not prove that the Telegram service is secure.
- vinceguidry 13y agoYour challenge isn't at all hard. An attacker could get into your server using some other method besides breaking SSH then simply look at your bash history.
- sdevlin 13y agoThis is really chickenshit, which is completely in line with everything else these guys have said or done. Just so we're clear, this rules out: * Chosen plaintext attacks * Chosen ciphertext attacks * Adaptive chosen ciphertext attacks * EDIT: Also any kind of side channel If you're keeping score at home, that's just about everything. The only thing that would fail to meet this definition of security is repeating key XOR. And RC4.
- warfangle 13y agoIf you were able to exploit vulnerabilities in the server, the software distribution, and the client... but that's not testing Telegram itself, it's testing everything in between -- including what's between the chair and keyboard. Which is where the weaknesses (as witnessed by bitcoin shenanigans) lie, anyhow.
- xerophtye 13y agoOk so here's what i understand what's going on here from reading the challenge and people's responses. 1) A classical crypto-challenge where you are given a cipher text and the algorithm and told to crack it is somewhat useless Because that would just prove strength of the primitive algorithm, not the system. Here you are given a scenario and told to use whatever attack is at your disposal to hijack the conversation and somehow retrieve the plain text. So while it is similar to in someways, but not exactly the same case. 2) People are not amused because they seem to find the vulnerability that upon initiation of the secret chat, the first time, the server can perform a MITM attack. Because apparently they use a Deffie-Helman key exchange where the server connects them to each other. So the server is in the best position to do the MITM. And since this contest does not allow to make that attack (even if u had the server in your control, the secret chat has been initiated already). And hence everyone is frustrated because they seem to KNOW the system is weak, but they cant prove it right now. And this will lead to Telegram boasting in March.
- zooko_LeastAuth 13y agoCould you show us examples of the actual message sent each day from Paul to Nick, except with the secret email address XXX'ed out? Is it the same message each day, or different?
- xentronium 13y agoI find it amusing how first this genuinely benevolent side project puts Pavel in trouble with his investors and then HN crowd hates it too.
- abcd_f 13y agoPavel, since you are here, Don't you think that you are basically fighting a needless uphill battle here? I mean, people crave a good encrypted communication system and you have the intent and the infrastructure in place, but you are shooting yourselves in the foot with your cryptographic design indulgence. This animosity will continue, because Telegram crew comes across as cocky and arrogant know-it-alls, and not because people think you cannot design a crypto protocol. The contest doesn't help a bit, it only further enforces the impression of arrogance on your end. This is not what you would've done if you in fact allowed for the existence of flaws in your design. You would've released an RFC instead. I have all the sympathy for you. I don't doubt your motives, but you are setting yourselves up against skilled technical crowd. It has already started off on the wrong foot and this unfortunate dynamic will continue. Perhaps consider offering an alternative crypto suite based on standard protocols? In parallel with what you have. Just reuse an existing crypto framework and redo transport layer to your needs.
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- paveldurov 13y agoabcd_f, I'm not part of the Telegram team, nor am I a cryptographer. However, I do support these guys, and for the last 3 days I saw the Telegram team diligently reply tech questions in Twitter, HN and blogs. I saw them collect questions from security experts and put up FAQs based on them http://core.telegram.org/techfaq http://core.telegram.org/techfaq or http://core.telegram.org/contestfaq http://core.telegram.org/contestfaq as well as update the obscure parts of their documentation. >> Perhaps consider offering an alternative crypto suite based on standard protocols? In parallel with what you have. Just reuse an existing crypto framework and redo transport layer to your needs. Again, I am not cryptographer. But as a person who wants his data to be secure I don't see anything wrong with different teams trying different approaches. I 100% agree that people crave a good encrypted communication system, but I'm not sure it can be achieved in a world where everybody uses similar methods. What if some of the common "best practices" are intentionally promoted in the crypto-community as the best ones exactly because they contain flaws and backdoors? Please allow me to give you an example of something that could be just that. The Telegram team was criticized by some NH critics for their custom auth key exchange protocol. People asked – why take a random value from server and a random value from client and combine both with a creepy function? Why not, e.g., just generate a random value on the client and use RSA instead? Well, the answer is simple – the Telegram guys did not trust that the random value generated on the client-side was really random. In August 2013 it turned out that their custom approach to protocol enabled Telegram to stay more secure when multiple other secure apps using more conventional solutions were hacked (http://android-developers.blogspot.ru/2013/08/some-securerandom-thoughts.html http://android-developers.blogspot.ru/2013/08/some-secureran...). Many Bitcoin apps were cracked and people lost money, Open Whisper Systems (I noticed these guys are aggressively promoted here in the NH community as the epitome of best security) had to hasten to patch their RedPhone app to avoid that vulnerability. So I'm kind of suspicious when I see strong pressure to enforce the use of common techniques and get rid of uncommon ones just because they are uncommon. I think the Telegram guys have the right to choose their own path, and I'm sure our society will only benefit from it. Of course, building custom solutions is no easy task and requires a lot of effort. But I've seen some of the Telegram guys (yes, the "6 ACM champions") create things that I'd thought were impossible. Maybe I am wrong in putting my trust in their abilities, and I will be fined $200K+ for my naivete. However, I am willing to continue financing such contests, and I do hope that eventually we'll all get something much more valuable than $200K.
- Justsignedup 13y agowhile the contest itself not wonderful, they do offer the source code, they offer constant traffic, they claim the contest is ongoing, so even if you don't win now, you might later. The last point Schneider made of them winning but not telling you until they feel it's worth it is still valid.