Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It also doesn't mean "plain text". Telegram uses MTProto and the decryption keys are stored on multiple servers in multiple jurisdictions, something which Gizmodo doesn't even mention.

See also this excellent comment by another HN user: https://news.ycombinator.com/item?id=41348228



Here is a better resource by an actual respected cryptographer: https://blog.cryptographyengineering.com/2024/08/25/telegram...

One of the links shared by the comment you're linking to points to a paper which concludes:

> We have presented the formalisation of the MTProto 2.0 protocol suite in the applied π-calculus, and its analysis using the protocol verifier ProVerif. This approach adopts the symbolic Dolev-Yao threat model: an active intruder can intercept, modify, forward, drop, replay or reflect any message. Within this model, we have provided a fully automated proof of the soundness of MTProto 2.0’s protocols for first authentication, normal chat, end-to-end encrypted chat, and rekeying mechanisms with respect to several security properties, including authentication, integrity, secrecy and perfect forward secrecy, also in the presence of malicious servers and clients. Moreover, we have discovered that the rekeying protocol is vulnerable to a theoretical unknown key-share (UKS) attack [ 5 ]: a malicious client B, with the help of another client E, can induce a client A to believe that she (still) shares a secret key with E, and instead A shares the key with B. The practical exploitability of this attack in actual implementations is still to be investigated. Our formalization covers also the behaviour of the users, when relevant; e.g., if the users do not check the fingerprints of their shared keys, a MitM attack is possible.


> the decryption keys are stored on multiple servers in multiple jurisdictions

Which is completely besides the point when the question is "should you trust Telegram", given that they are still entirely under Telegram's logical control.

The only circumstance under which this is a meaningful difference is when somebody other than Telegram (law enforcement with a warrant, law enforcement without a warrant, criminals etc.) walks into a data center and pulls those servers' hard disks.


What keeps an employee from impersonating a user by registering a new device and intercepting the confirmation code? The code must be somewhere in their systems for the time being, so at least one employee must be able to get it. Then they can see everything the user can see.

(Assuming the user has the default setting of no 2FA.)

There are probably more ways to get to the data.

Splitting keys in different jurisdictions seems like security theater.


Also, since you can see scroll back don't they host the telegram chats even if they are in encrypted form?


A reply to the comment you link to: https://news.ycombinator.com/item?id=41348494

They claim it only covers transport and not data at rest.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: