by takoid on 5/10/24, 3:33 AM with 110 comments
by andreyvit on 5/10/24, 11:24 AM
It’s really a showcase of how very high IQ and outstanding mathematical abilities mix with a distrust of existing technologies and a lack of expert intuition coming from more normal industry experience.
Just try implementing MTProto, or at least read the low-level docs, and you’ll see for yourself. Crypto isn’t the weirdest part. The whole thing is an attempt to define a binary protocol in terms of grandiose mathematical concepts most of which didn’t even end up ever used in the actual protocol. And there’s zero thought given to what’s actually important, making a bullet-proof syncing between server and client states (and that results in numerous bugs to this day).
Can’t discount malice, but I don’t believe that’s the case.
by dang on 5/10/24, 6:01 AM
The most backdoor-looking bug I’ve ever seen (2021) - https://news.ycombinator.com/item?id=30013192 - Jan 2022 (77 comments)
Discussed at the time:
The Most Backdoor-Looking Bug I’ve Ever Seen - https://news.ycombinator.com/item?id=25726068 - Jan 2021 (208 comments)
Cryptography Dispatches: The Most Backdoor-Looking Bug I’ve Ever Seen - https://news.ycombinator.com/item?id=25721990 - Jan 2021 (1 comment)
by syngrog66 on 5/10/24, 6:42 PM
Technically I try to boycott everything with too strong of a connection to any of the so-called CRINK nations (ie. China, Russia, Iran, North Korea.) Its hard to enforce it perfectly. But where its easy enough for me to do, I do.
by cbxyp on 5/10/24, 7:26 AM
by whenlambo on 5/10/24, 7:18 AM
by SCUSKU on 5/10/24, 5:26 AM
by dathos on 5/10/24, 5:23 AM
by medo-bear on 5/10/24, 6:20 AM
by plugin-baby on 5/10/24, 5:23 AM
Seems like a red flag.
by ccvannorman on 5/10/24, 5:57 AM
by surfingdino on 5/10/24, 5:37 AM
by igammarays on 5/10/24, 7:16 AM
See Durov’s (Telegram founder) recent announcement regarding Signal.
> A story shared by Jack Dorsey, the founder of Twitter, uncovered that the current leaders of Signal, an allegedly “secure” messaging app, are activists used by the US state department for regime change abroad
> Unlike Telegram, Signal doesn’t allow researchers to make sure that their GitHub code is the same code that is used in the Signal app run on users’ iPhones. Signal refused to add reproducible builds for iOS, closing a GitHub request from the community. And WhatsApp doesn’t even publish the code of its apps, so all their talk about “privacy” is an even more obvious circus trick .