8 ms·
Telegram’s Cryptanalysis Contest
- sillysaurus2 13y agoI wish there was an article that succinctly conveys to potential users why Telegram is snakeoil and why TextSecure is the real deal.
- vitalyny 13y agoYep. So far it was more like "Please please don't use Telegram. Please please use TextSecure.".
- deleted 13y ago[deleted]
- Nursie 13y agoSo you didn't understand the article here then? There's no shame on that, crypto is complex and requires study. But please don't dismiss well written and well thought-out critiques like this one just because you didn't understand the arguments.
- sillysaurus2 13y agoTalking down to people helps nobody. If I were a random potential user and read what you wrote, my reaction would not be polite, and I would probably feel polarized against your recommendation out of spite. The problem isn't that potential users are lacking anything. It's that nobody on our side of the table has communicated clearly and succinctly. https://news.ycombinator.com/item?id=6941007 https://news.ycombinator.com/item?id=6941007
- Nursie 13y agoI'm not talking down, it's clear that the commenter hadn't understood the article. And there really is no shame in that. Further, your linked comment seems to be exactly what they're complaining about - Textmate good, Telegram bad. It doesn't explain why and why turns out to be quite hard to explain succinctly.
- girvo 13y agoWith all respect, crypto (and broken crypto) is wrt difficult to explain in a user friendly way to a lay person without just ignoring the technical details. Once you do that, it really is just "fuck telegram use snapchat", which doesn't help anyone... I am going to give it a bash tomorrow to try and write the article you are after. Good technical writing practice :) What makes the Article here not sufficient from your perspective?
- vitalyny 13y agoOh, wow, and people complain about Telegram team's attitude. Don't be so vulnerable, please. Take the critics easy. As for the article, it's well written, but most of the points had been answered in Telegram FAQ or comments on HN. And yet they come up again and again. Not all, most.
- Nursie 13y ago>> Oh, wow, and people complain about Telegram team's attitude. Don't be so vulnerable, please. Take the critics easy. I'm not sure what you mean by this as I'm not the author, so you haven't criticised anything I've said. >> As for the article, it's well written, but most of the points had been answered in Telegram FAQ or comments on HN. And yet they come up again and again. Not all, most. Not adequately, hence the well written deconstruction by the post author. I'm going to echo what I've seen in another post - you appear to be a Telegram cheerleader with a brand new account, are you associated with them at all?
- ash 13y agoI think Telegram "cheerleaders" are here because Telegram backer Pavel Durov (paveldurov on HN) is very well known in Russia. He is the founder of one of most popular social networks in Russia, vk.com. He is a (local?) celebrity and he has fans. Imagine Mark Zuckerberg backing Telegram.
- trycatch 13y ago> I'm going to echo what I've seen in another post - you appear to be a Telegram cheerleader with a brand new account, are you associated with them at all? Discussions on HN about Telegram were mentioned on several Russian sites (e.g. [1]). No wonder that some persons decided to pitch in. [1] http://www.siliconrus.com/2013/12/telegram-vs-hacker-news/ http://www.siliconrus.com/2013/12/telegram-vs-hacker-news/ Approximate translation: "How experts on Hacker News laughed at Telegram."
- adcoelho 13y agoYesterday's article A Crypto Challenge For The Telegram Developers was a good analysis on why Telegram's challenge fails to prove anything.
- deleted 13y ago[deleted]
- sillysaurus2 13y agoSadly, it was probably too technical for most potential users to be swayed much by it. We need focused talking points, e.g. the fact that the NSA and other governments vacuum up all your data, and that TextSecure represents the first step toward a future in which it's very difficult for governments to do that. Whereas with Telegram, it's just as easy for them to access your conversations as it is for them to bypass SSL. Governments can and will do so. That's what users are concerned about; that's what they care about. Telegram has no defense against that argument due to their protocol's inherent vulnerability to this form of attack. Therefore it's the single most important point for to stress to any potential user. Yet it's getting lost in the noise. Actually, I haven't seen it mentioned very much at all. Someone should do a writeup calling attention to it.
- forgottenpass 13y agoWe need focused talking points No we don't. At least not for your goal of: an article that succinctly conveys to potential users why Telegram is snakeoil and why TextSecure is the real deal There is no way to convey this with better rhetoric because the proof is in the technical detail, the party that is wrong can just ramp theirs rhetoric up too. If you don't dig into that detail, it just becomes a he said/she said argument that no observers can judge on merit. Those discussion relies on the participants to be knowledgeable, and politely acknowledge when they're out of their depth technically or just plain wrong. But there is nothing to enforce that, see any Hacker News discussion about something that isn't web development or devops.
- sheetjs 13y agoSimpler explanation: I am selling fire-proof safes. These are designed to protect your documents and valuables from thieves and from fire and other events. The normal way people set up tests is to put some documents and valuables in a box and actually try to break it (MythBusters style, bringing out cool machinery and trying different ways). For fire resistance, there is a rating system (https://en.wikipedia.org/wiki/Fire-resistance_rating https://en.wikipedia.org/wiki/Fire-resistance_rating) and a standard way to test. The Telegram proposition is: we are going to place the safe in Fort Knox. If you can't break the safe that is in Fort Knox, then clearly our safe is secure. The Article rebuttal: to break the safe, you have to break into Fort Knox. And for all intents and purposes that's not going to happen. You could have put a cardboard box and no one could tell the difference because of how you structured the test.
- deleted 13y ago[deleted]
- tptacek 13y agoThat would be nice. But, for what it's worth: don't use Telegram. It's a mess. TextSecure was built much, much more carefully.
- seertaak 13y agoIs TextSecure only for SMS messages, or does it use the internet? I'm asking because of the need to send text messages abroad (at a reasonable price). Also, is there a desktop client for TextSecure? I would love something like WhatsApp -- but secure and with a desktop client.
- girvo 13y agoXMPP + OTR will do what you want. I asked moxie the same question re the internet vs text, but he hasn't replied yet. As far as I'm aware it uses text for insecure stuff, and I think for initial key exchange to start the ratchet then uses the internet for secure messaging. Its quite user friendly. No desktop client, and the messages are of ephemeral so keep that in mind and see whether that's okay for your use case (it is for mine).
- StavrosK 13y agoDepending on how much you're willing to pay, Silent Circle might fit the bill: https://silentcircle.com/ https://silentcircle.com/ Disclaimer: I work for them.
- natch 13y agoIs TextSecure open source?
- andrewschleifer 13y agohttps://github.com/WhisperSystems/TextSecure/ https://github.com/WhisperSystems/TextSecure/
- xerophtye 13y agoWith all the publicity TextSecure is getting from all this Telegram Debacle, I am beginning to suspect telegram isn't even a real company, and just a very elaborate publicity stunt by Moxie and the rest of the TextSecure team!! :P
- vitalyny 13y agoBy the comments it seems that most of the active haters of Telegram are TextSecure team. Yes, they want publicity and funding - and who doesn't?
- chris_wot 13y ago"Haters" is a very emotive term. There is no real hate I can detect form the TextSecure team. They have just pointed out flaws and why they feel that the solution is flawed. You wouldn't be associated with Telegram, by any chance?
- vitalyny 13y agoAlright, haters is probaby a too strong term. TextSecure team pointed out flaws in the first topic about Telegram on HN and these flaws were answered by Telegram team: they updated FAQ, they commented in twitter and here on HN. Every post with Telegram's flaws explicitly mentions TextSecure as an alternative, and that is suspicious - they seem to find it a great way to get publicity.
- tucson 13y ago> They use the broken SHA1 hash function They answer this point on the website: "Q: Why do you use SHA-1 in the place of a MAC? [...] since this means still requiring at least 2^128 operations (instead of 2^256 with, say, SHA-2) to even begin trying to break this scheme, the trade-off seems fair." Why not break the crypto (and take the money) if it's so amateurish?
- testing12341234 13y agoThe easiest to understand response to this question that I've seen so far is from this comment [0]: The contest limitations rule out most of the likely attack vectors for breaking the protocol in the real world. It's like saying "Our bank vans are 100% secure. Just try stealing money from them without puncturing our tires or bribing one of our employees." [0] - https://news.ycombinator.com/item?id=6936949 https://news.ycombinator.com/item?id=6936949
- simias 13y agoIn particular none of the attacks described in TFA (Known Plaintext, Chosen Plaintext and Chosen Ciphertext) are possible within the frame of their contest (since Telegram controls all inputs). Yesterday someone blogged an example of a completely broken cryptosystem that would still pass Telegram's challenge with the same limitations: http://www.thoughtcrime.org/blog/telegram-crypto-challenge/ http://www.thoughtcrime.org/blog/telegram-crypto-challenge/
- StavrosK 13y agoThat's Moxie Marlinspike, developer of TextSecure.
- Beltiras 13y agoWith a very valid challenge.
- raverbashing 13y agoIt may even be possible to factor the RSA Key More to the point, KPA,CPA, etc are very important, and systems should be definitely tested against them, but in real attacks, they may not be available
- raverbashing 13y agoFunny how they say "oh but the attack possibilities are limited" then proceed to mention all the weaknesses in the algorithm. Well, if the algorithm is so broken then it should be trivial to break it even with their limitations. Isn't that what they say? "Oh SHA-1 is broken", great, show it. Of course, the capability to do that may be worth more than getting the $200k from the contest
- Confusion 13y agoWell, if the algorithm is so broken then it should be trivial to break it even with their limitations. Well, if the house is so badly protected, it should be trivial to break in, even with their limitations[1]. [1] Limitations include: not being allowed within 200m of the house.
- raverbashing 13y agoI disagree You are allowed access to the encrypted data. In a real attack you may, depending on the circumstances, only have access to that (at first, at least). Probably more like "you aren't allowed to destroy any locks or doors to enter the house". Hard, but much different than staying 200m from the house.
- Drakim 13y ago> In a real attack you may, depending on the circumstances, only have access to that (at first, at least). You misunderstand the whole deal. When imagining different potential attacks on your house you can't go laying down rules that the burglars have to follow. What if there are special circumstances (that you weren't aware of) that allows the burglars to bypass your restrictions under certain conditions? You plan for the worst case scenario, always! Take password hashing+salting for instance. You could say that it's actually safe to store plaintext passwords because outsiders don't have credentials to access the database. You could even run a contest where to say that you will give a million dollars to anybody who can get access and steal the passwords, and then insist that since nobody has claimed that million dollars yet, plaintext passwords are clearly safe. But we all see how foolish that would be. You plan for the worst case scenario and hash+salt your passwords. You don't plan for the "average case scenario" where "normally attackers don't have access to the database".
- rkangel 13y agoForgetting the discussion of the merits or otherwise of Telegram - I just wanted to say that that is a very written article. A clear argument built on clear explanations of the various models.
- kayoone 13y agoSome strong claims in there for not really proving that the protocol is indeed "terrible".
- Confusion 13y agoAn expert on trees: This oak is probably diseased. It has discolorations on some of the leaves and the bark is much looser than normal. I think it should be thoroughly investigated or perhaps just cut it down to be safe. kayoone, knowing nothing of trees: "some strong claims in there for not really proving that the tree is indeed diseased."
- kayoone 13y agoAnd you obviously know that i know nothing of on the subject?
- skj 13y agoWith respect, at first glance it seems that way. The burden of proof lies with the claim to security, not the claim of insecurity.
- tucson 13y agoThe contest actually puts the burden of proof on the "claim of insecurity" side.
- forgottenpass 13y agoThe contest is a stunt that appears to a casual observer to shift the burden of proof because they wrote a long winded "PROVE ME WRONG BRO."
- Confusion 13y agoFrom your comment everyone can immediately surmise that you lack the practical knowledge of using cryptography for real world applications that people like tptacek and moxie have. They are known experts and have been quite clear on the questionable nature of Telegram's choice of cryptographic primitives and their composition. Their objection is not 'this is obviously broken'. Their objection is 'this does not obviously work and there are some red flags'. This blog post merely mirrors that objection. The crucial point is that the past has shown that no proof of brokenness is required. In cryptography, if it doesn't obviously work, it is probably broken, because it is incredibly hard to get right and because an incredible amount of money and effort is available to find the tiniest crack. You are dealing with criminals and governments who have deep pockets. Either you prove it works or you assume it doesn't work. The proof is missing.
- venomsnake 13y agoIs there a reason why all fad "secure" products lately default to custom protocols and exotic solutions instead of using well tested and trusted solutions? Designing a protocol so that is does not leak is very hard.
- peteretep 13y agoUnique Selling Point
- venomsnake 13y agoWell create metadata resistant protocol that communicates on set intervals of time with set length of random data when there is no real payload. This could be done on TLS with little or no effort. The math behind the crypto is strong enough. No need to harden it further. Every client sends and receives 16KB blob every 30 seconds - this way you could prevent analysis that you are communicating with someone. You could learn a lot just from the size and frequency of packets in a normal chat program.
- oakwhiz 13y agoIt seems like there is a 'No-Free-Lunch' tradeoff between bandwidth efficiency and traffic analysis resistance.
- venomsnake 13y agoI prefer the later to the former in a heartbeat.
- Nursie 13y agoLOL. We really need to make the world at large aware that a USP in the crypto area is a big red flag. "We use up to date, standard protocols and crypto techniques" really ought to be the top of the marketing blurb. "Ours is better because we invented it" is really terrible.
- vitalyny 13y ago
- xnyhps 13y agoI think it's a brilliant move from the people behind Telegram: all cryptographers will now keep the vulnerabilities they find to themselves until March 1st. This saves them from a lot of bad press now, and probably doesn't cost them anything. If they were serious about using their $200k for their security they should have either: a) Hired an actual independent cryptographer to do an audit. b) Set up a bug bounty program that rewards any weakness found, not just this "all-or-nothing" contest they have now.
- blahbl4hblahtoo 13y agoWow...this thing just keeps on giving. It's Christmas in crypto-fail land!
- infocollector 13y agoI think people should keep quiet if they cant break their system. What good is a cryptographer, if its only good for pointing fingers?
- yalogin 13y agoDid you read the blog post? This is precisely what the OP is saying, that the contest is flawed. They are basically saying if you can break my new fancy lock you win but you can only see the lock over the webcam and not touch it.
- shootaray 13y agoIf you can't get to the lock using the webcam, then stop writing blogs. Get to work. Don't complain that the lock internally uses sha-1, and ... Break it and then talk. Don't just point fingers. And anyone who mentions TextSecure in their blog, sounds like they have an ulterior motive writing the blog.
- wgx 13y agoBest quote: "Telegram’s design seems to disregard all of the important crypto research from the past two decades."
- TelegramApp 13y agoThe contest, as proposed by Pavel, while limited for the moment, does cover an important issue as far as our users are concerned. And the scope will naturally expand with time, should Telegram be invulnerable under the current conditions (see contest FAQ: http://core.telegram.org/contestfaq http://core.telegram.org/contestfaq). Quoting a post by Pavel here on HN: "Telegram will always be interested in creating incentives for the crypto-community to check its security and provide feedback. So if you are waiting for tools to try, e.g., a MITM on Telegram and get your $200К, please stay tuned. It's @telegram on Twitter." (https://news.ycombinator.com/item?id=6938987 https://news.ycombinator.com/item?id=6938987) As for general critique of the protocol, please allow us to add a few vital corrections regarding the article (unfortunately, the author chose a platform that would not permit a direct comment). > They use the broken SHA1 hash function. SHA-1 isn't exactly broken. There is a theoretical paper from 2005 that describes a way to narrow down collision search from 2^80 to approx. 2^69 operations (http://people.csail.mit.edu/yiqun/SHA1AttackProceedingVersion.pdf http://people.csail.mit.edu/yiqun/SHA1AttackProceedingVersio...) with subsquent improvement to 2^63, but collisions won't help in the case at hand. In order to break the implementation in MTProto you would require generating a text with chosen SHA-1 (to our knowledge, this problem was not yet solved) — and even that wouldn't get one far, because of the server salt, session id and time. More on our SHA-1 implementation here: http://core.telegram.org/techfaq#q-are-you-doing-encrypt-then-mac-mac-then-encrypt-or-mac-and-enc http://core.telegram.org/techfaq#q-are-you-doing-encrypt-the... and here: http://core.telegram.org/techfaq#q-why-do-you-use-sha-1-in-the-place-of-a-mac http://core.telegram.org/techfaq#q-why-do-you-use-sha-1-in-t... > they are trying to do “Mac and Encrypt” which is not secure. We are not doing this. We are doing this: http://core.telegram.org/techfaq#q-are-you-doing-encrypt-then-mac-mac-then-encrypt-or-mac-and-enc http://core.telegram.org/techfaq#q-are-you-doing-encrypt-the... > They rely on an obscure cipher mode called “Infinite Garble Extension.” Yes, we do. The setup goes like this: http://core.telegram.org/techfaq#q-do-you-use-ige-ige-is-broken http://core.telegram.org/techfaq#q-do-you-use-ige-ige-is-bro... > Some really weird stuff about factoring 64-bit integers as part of the protocol. This weird stuff can be pretty effective as part of our DoS-protection scheme. Meanwhile, we've expanded our Tech FAQ with responses to most common questions concerning MTProto's robustness against certain types of active attacks: http://core.telegram.org/techfaq#protection-against-known-attacks http://core.telegram.org/techfaq#protection-against-known-at... Thank you for your comments, Telegram Team
- theg2 13y agoGood idea, lets keep attacking the marketing team. It's a PR stunt, can we stop acting like it's anything else?
- utnick 13y agoIf the crypto is broken, then break the crypto and collect the 200k. Or if its vulnerable to a MITM, then explain how. Or if its vulnerable to chosen plaintext/ciphertext or known plaintest, explain how. There has been so much piling on of telegram, but nobody has actually proven any problems with their code or protocol. Meanwhile telegram is trying to do the right thing by being open source and taking the time to respond here and elsewhere to misconceptions and criticisms about them. I really don't get the hostility towards them so far.
- girvo 13y agoWell, the severe issues highlighted by better cryptographers than me (although I do understand why and how they are issues) show that the protocol can't be trusted. These issues have caused other protocols to be broken, so aeeinf similar issues again from the get go, coupled with heir marketing spiel means that it shouldn't be trusted. Which is what it's about: cryptography is mostly about trust with a bit of math thrown in. If you can't trust that it won't be broken (see: all the issues 'moxie and 'tptaeck bring up for an example) then it shouldn't be used.
- MichaelGG 13y agoPeople have pointed out their weaknesses. Telegram provides non-responses. The crypto has problems, but they aren't exploitable under the very limited conditions set by their contest.
- cheald 13y agoThe contest is framed in such a way that the protocol's weaknesses aren't exposed to attack in the way that they would be in the wild.
- mangeletti 13y agoHas anyone else noticed that their protocol sounds a lot like "empty proto"... http://core.telegram.org/mtproto http://core.telegram.org/mtproto [thinks of null key encryption]
- releod 13y agoI don't understand why this is such a massive problem (front page news for days now, really?). Mind you, I am not a crypto expert, but enough with the bitching already. Crypto experts, just crack it then.. who cares about the special conditions in the contest which make it so difficult. Just do it, prove your point and carry on. $200k is PR, everyone knows that already.
- deleted 13y ago[deleted]
- Nursie 13y agoIt may well be impossible to crack within the terms of the contest. This does not make it secure in the slightest, as the terms are set up specifically to exclude most of the attacks that are used in crypto validation these days. See - http://www.thoughtcrime.org/blog/telegram-crypto-challenge/ http://www.thoughtcrime.org/blog/telegram-crypto-challenge/
- ibudiallo 13y agoSo everyone is mad cause they used their own approach to security. Now no one managed to break their crypto so far. Don't say it is bad unless you can break it. Don't go around write a full paper about how bad it is while you still can't break it. I still don't get why there is all this hostility toward telegram.
- dcalacci 13y ago>So everyone is mad cause they used their own approach to security No, that's not why people are upset at all. People are upset because whether or not someone has been able to break their system under the constraints of the contest means almost nothing. Did you even read the article?
- mcguire 13y agoNot necessarily on topic, but... "... will give $200,000 in BTC to the first person ..." Is that $200,000 in BTC at the time the contest was announced, or at the time the winner is announced? Or at some other point? (This comment brought to you by the Committee For Pointing Out That A Currency That Wildly Fluctuates In Value Is Not Particularly Useful (CFPOTACTWFIVINPU).)
- thedufer 13y agoUgh. There are a lot of reasons not to participate in this contest, but that's not one of them. The FAQ explicitly says that they'll just give you USD if you'd like, so it doesn't really matter when they pin the USD/Bitcoin exchange rate.