Hacker News new | past | comments | ask | show | jobs | submit login

Maybe this reddit comment will make you less worried /s

>The lead Telegram dev is a 3x International Math Olympiad gold medalist, won another gold in the informatiks olympiad, went on to earn two Ph.D.'s in algebraic geometry, all while working full-time as a programmer?

>Him rolling his own encryption algorithm is not the same as your copy-paste StackOverflow code monkey who scraped by with C's at his community college rearranging the alphabet letters in a caesar cipher.




>The lead Telegram dev is a 3x International Math Olympiad gold medalist

The lead dev

* doesn't have ANY qualifications as a cryptographer (he got his position through nothing other than nepotism) and thus

* thought AES-IGE was best practice

* used SHA-1 10 years after SHA256 was published

* didn't understand the importance of DH parameter pinning

* left in a 64-bit pre-computation MITM attack vector

* initially implemented crappy QR-code like fingerprint for secret chats without understanding the need for hex-decimals that could be compared over authenticated channels

* couldn't implement IND-CCA secure protocol

* didn't prevent these FOUR new vulnerabilities

But most importantly:

* doesn't have the know-how on how to implement E2EE for groups

* doesn't have the know-how on how to implement E2EE for 1:1 on Win/Linux desktop clients

* doesn't understand E2EE needs to be enabled by default

They are literally just winging it. Their Russian Pride would take too large a hit from publishing a CVE wrt the most recent issues, thus they downplayed the issues and wiggled out to maintain the prestigious image in front of the cult that is their users.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: