Hacker Newsnew | past | comments | ask | show | jobs | submit | amima's commentslogin

They do not claim that. They do claim that they store specifically encryption keys in several data centers in different jurisdictions. Here is the exact quote: "All data is stored heavily encrypted and the encryption keys in each case are stored in several other data centers in different jurisdictions". So only keys are distributed.


What does heavily encrypted even mean? Fully encrypted? Slightly encrypted? Encrypted enough to call it “heavily encrypted” but not enough to be protected from whoever is interested?


Heavily means the key is large so it takes longer to crack, but also longer to encrypt/decrypt, so the service is more costly to run and slower. At least I've seen it used that way


There's nothing slow about AES.

In this context "heavily" means "we can't legally claim it's end-to-end encrypted because it's not".

Also it's not even post quantum, so it's not heavy. Telegram's Diffie-Hellman breaks instantly with a quantum computer large enough to run Shor against it.

Also, the keys sit on the servers' RAM, no matter what they lie. There is no global distributed RAM system, especially one that encrypts data in distributed fashion and works at the negligible latencies that Telegram boasts.


I've never claimed that anything about telegram's encryption is "heavy", because I don't even know what they use, I just said what "heavy" usually means

> In this context

In this context it's marketing bs for people that only seen action movies where hackers quickly cracked encryption. I'm sure whatever telegram uses is not that ridiculously easy to crack


It's not slow though so that's clearly not it. It's just a marketing intensifier here


telegram is the safest encrypted messaging app. Period, full stop.


>telegram is the safest encrypted messaging app. Period, full stop.

Yes, let's see

* Not end-to-end encrypted by default

* No end-to-end encrypted groups

* No end-to-end encryption on any desktop client by the vendor, forcing cross-platform users to drop secret chats. This includes 81% of working age people who sit on their computer during work day, and 100% of college students and IT workers.

* No post-quantum key exchange

* No future secrecy

* No per-message forward secrecy

* Bullshit claims about distributed keys https://security.stackexchange.com/questions/238562/how-does...

* Lacks ALL metadata protection from server like phone number, IP-address and thus geolocation, contact list, group memberships, quantity and schedule of communication, data types. In fact --

* Secret chats leak additional metadata about intent to hide content from TG as the vendor.

Also,

History of poor encryption implementation

* 2013: A cracking contest https://news.ycombinator.com/item?id=6932648

* 2013: Telegram, AKA "Stand back, we have Math PhDs!" http://unhandledexpression.com:8081/crypto/general/security/...

* 2015: IND-CCA issues https://eprint.iacr.org/2015/1177.pdf,

* 2015 64-bit complexity MITM attack https://web.archive.org/web/20160425091011/http://www.alexra...

* 2021 Valsorda "The Most Backdoor-Looking Bug I've Ever Seen" https://words.filippo.io/telegram-ecdh/,

* 2021 https://mtpsym.github.io/ and https://mtpsym.github.io/paper.pdf

Some analysis:

* 2025 Matthew Green analysis https://blog.cryptographyengineering.com/2024/08/25/telegram...

* 2025 "Telegram is indistinguishable from an FSB honeypot" https://rys.io/en/179.html

Also,

They employ volunteering sockpuppets https://tsf.telegram.org/

Durov who supposedly lives in exile has visited Russia over 50 times https://eutoday.net/pavel-durovs-secret-visits-to-russia/

I can't scream "drop & run" loud enough.


Telegram has nothing to do with Russia, other than having a Russian founder, and the Ukrainian military has literally relied upon it in the past, along with many Ukrainian civic services. You people are just racist towards Russians and need help.

Based on the analysis of packet captures above, I believe it is clear that anyone who has sufficient visibility into Telegram’s traffic would be able to identify and track traffic of specific user devices. Including when perfect forward secrecy protocol feature is in use.

This would also allow, through some additional analysis based on timing and packet sizes, to potentially identify who is communicating with whom using Telegram.

I love how the author of your honeypot blog post has nothing concrete other than potential attack vectors and is like "Well this is obviously a Russian honeypot" with no evidence what so ever other than a claim that there are plain text device identifiers, which is something the FSB would do. [insert clown emoji]. You can do similar attacks on signal and whatsapp.. Why is it that the Russian one bothers you so much?


>You people are just racist towards Russians and need help.

That doesn’t exclude the statements about Telegram to be correct though. That is, if some hater against whatever group say 1+1=2 or water is wet, what’s the conclusion?

>You can do similar attacks on signal and whatsapp.

Well yes. Don’t trust devices, they are not humans, they don’t qualify. They can at most have some degree of reliance for some purpose. But assuming that all devices out there are powned by some external parties is a rather sound security baseline approach.

>Why is it that the Russian one bothers you so much?

One don’t need to bother more on any specific oligarchy really, they all use their fellow humans like disposable pawns.


> You people are just racist towards Russians and need help.

>> That doesn’t exclude the statements about Telegram to be correct though.

just attack the telegram from the technical standpoint, then no complains about "racist towards russians" will be given. Like, mentioning the lack of user-friendly E2EE is great already. Saying things like "Durov who supposedly lives in exile has visited Russia over 50 times" is meh. How can one intepret it in any other way is "Russia is evil and visiting Russia is thus evil"?

and regarding the cracking contests — one of the telegram bugs was actually uncovered this way, see https://habr.com/ru/articles/206900/


>Durov who supposedly lives in exile has visited Russia over 50 times

Durov's exile marketing makes him look like he's Alexei Navalny. Navalny was a true dissident and critic and he was first poisoned, and then later arrested when he returned. He was was then imprisoned and he died in prison.

Durov has been visiting Russia more than I've been visiting my friends over the same period. Him returning to Russia that many times shows he isn't really living in exile. He's not on the run, and he's not getting arrested when he visits Russia. The disparity between the stories forces one to ask, is he working with the Russian government instead. He can prove he isn't by deploying ubiquitous end-to-end encryption, until then there's very little reason to suspect he isn't, again given the mismatch between what's claimed (the exile) and what's happening behind the scenes (the visits the public doesn't know about).

>and regarding the cracking contests — one of the telegram bugs was actually uncovered this way, see https://habr.com/ru/articles/206900/

That article doesn't even mention the cracking contest. The XOR-nonce bug was also found by Valsorda in 2021 https://words.filippo.io/telegram-ecdh/ so looks like that 2013 post you linked to never even led to a fix during the EIGHT years. No idea if it still exists.

Also, you can't be racist towards Russian government that's OBVIOUSLY evil. From Navalny, to Bucha, to bombing hospitals, to kidnapping children, to the illegal war in the first place.


I've never had a twitter account so all these people hating durov for his exile marketing look weird to me. I'm not disagreeing with what you say but it's like a whole another subsection of world opened to me


> How can one intepret it in any other way is "Russia is evil and visiting Russia is thus evil"?

Simple: Durov has no problem with constructing a narrative that has little to do with reality.


> How can one intepret it in any other way

As noise. The fact it's xenophobic or some other kind of noise is just implementation details at that level.


>Ukrainian military has literally relied upon it in the past

Well they realized their mistake and banned Telegram's use on state issued devices in 2024 https://www.bbc.com/news/articles/c78dwepw95do

I'm not going to speak for the author of that article. But I agree with his conclusion. Telegram is indistinguishable from a honeypot.

In the world of infosec, stuff isn't secure until someone proves you wrong (which you reject assuming racism). Stuff is secure when you prove it's secure.

Practically every major secure messaging app vendor has proven they can not be a honeypot, by end-to-end encrypting their communications, offering open source clients with public key fingerprints to verify that end-to-end encryption is working correctly.

Telegram hasn't done that. Telegram's lack of end-to-end encryption, paired with zero effort for metadata protection (not even stuff like sealed sender) shows they don't give a damn about actual security.

But what they do is also what an FSB op would do.

* It would advertise "heavily encrypted" and bash WhatsApp day after day convincing average Janes and Joes about it being really really secure, and confuse readers who take a closer look, with claims of all chats using MTProto but also calling both client-server and end-to-end encryption protocols MTProto.

* It would construct a narrative that the face of the app is a rebel dissident in exile.

* It would be banned temporarily or poorly

* It's role would be obfuscated by releasing an obviously backdoored app like Max, to make Telegram seem safe compared to it. Like Russian intelligence really believed they could use Max to monitor Russian dissidents. FSB isn't dumb. Russian military deception is world famous. https://en.wikipedia.org/wiki/Russian_military_deception

The backdoor sits in the fact nothing is end-to-end encrypted, groups can't be E2EE, but troll army can still defend it, claiming it does have 1:1 E2EE if you want. Yes, it does, if you really want the highest friction UX possible. People try and drop secret chats when they want to be able to alt-tab into the conversation instead of digging into their phones 100 times a day. This backdoor is ingenious because the users can only blame themselves when their 1:1 messages end up to the server.

A good messaging app creator knows this, so they make E2EE default so that users don't encounter such friction. E.g. Signal allows you to have E2EE 1:1 and group chats between all of your devices. That's what proper privacy by design looks like. Would Telegram do that, they would've proven they stand for their users, and I'd actually recommend them.

Data is a toxic asset. Even if Telegram isn't a honeypot, it's a massive data collecting apparatus, that has all that data sit on its servers, from which the hacking team of any major intelligence agency can access it en mass. That's the life of 1B users worldwide. So ultimately, it doesn't even matter if Telegram is a honeypot, it's equally usable to https://en.wikipedia.org/wiki/Fancy_Bear or NSA TAO or whoever.

Also, https://dfrlab.org/2018/02/15/putinatwar-how-russia-weaponiz... shows Russian troll army is using russophobia as a narrative online.

This isn't about hating on Russians. This is about Durov not passing the minimum bar of what modern secure communication is about.

You've so far claimed telegram is the best with nothing to back that claim, ignored every counter argument, attacked argument of someone other than me, and you're now replaying Russian government shill tactics to try to rally people behind you for emotional reasons, when I'm explicitly giving technical critique.


The ban is just there so every village cop may have something against you if they need it.

Besides that, they know and, as it seems, to be happy about it's wide availability and information.

Having their own app, they obviously also use for their causes, is just a cookie for the patriots.


If Telegram is a Russian honeypot, why is it banned and blocked in Russia?

(Answer: to make it not look like a Russian honeypot)


To my understanding, scaling production to bring prices down due to economy of scale is the part of the initial plan, which was based on the data about climate change. So these things are connected.


Not to mention how much's been invested in government subsidies to develop that scale. Cheap solar is not a spontaneous occurrence by any means.


I am still using Windows 10. A major reason for me to not upgrade is all the media coverage of ads, user tracking, forced subscriptions and unnecessary AI features in Windows 11. Also, Windows 10 is just plain really good. I do have TPM and strong hardware. Windows 11 reputation is the main concern.


Likewise. I have no reason at all to "upgrade" to windows 11 even though my current hardware supports it.


So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?


> What would stop them from paying the ransom

They can bring their systems back up and operational for less cost (both immediate, but also payroll during the fix, lost revenue from both downtown and reputationally after they're back, and opportunity cost off the top of my head).

Your only two options and rebuild on your own at significant cost or pay the ransom. There were long, heated discussions about what to do, and several people suggested paying the ransom but we ultimate decided not to and it ended up costing more than the ransom if you factor in payroll and lost revenue.

I still think out of principle you shouldn't pay the ransom, ever. Assume whatever the ransom would cost is already gone, if you can rebuild for less than that (you probably can't) it's a win.


But even when paying the ransom, you still need to roll back a portion of your environment after you've assessed the intrusion. Can you really trust you've patched everything and removed all trace of persistence that was put by the attacker as a contingency to get back in the system?


That's the job of an external cyber incident response team who can trace how it occurred and to check that the vulnerability has been appropriately eradicated and locked before resuming business operations


The easiest targets are those that are publicly known to be vulnerable.


> I still think out of principle you shouldn't pay the ransom, ever

There may have been a time when a company would act on principle, but I think it's very rare today. You hardly even expect people to do that. It's the world we have made.


All human activities, including things like principles, charity, sacrifice, and duty, are ultimately self-serving attempts by the biological DNA and cultural memes that constitute us to replicate and improve it's standing.


Nothing, so far. The alternatives to that would be to legislate penalties for paying, to mandate certain precautions like regular offline backups (which could usually be done through regulation), to forbid the government from doing business with entities that have paid in the past X time (procurement regulations are somewhat flexible) and/or to task some government agency with aiding private sector entities in recovery if they don't pay (which has varying difficulty depending on the jurisdiction).

Obviously none of these make it impossible, but the goal needs to be to tip the value proposition the other way.


I was assuming that countries would make it illegal to pay these ransoms.


The article doesn't seem to suggest that anywhere.


You are right. It's kind of a toothless tiger without that part though.


The data sharing mentioned in the article will help authorities to target the criminals directly.


An insurance fund that requires periodic air gapped backups. So you roll back to the last snapshot and get money to cover losses incurred.


There are a handful of problems with this approach, which is part of why these types of insurance policies are incredibly expensive. The entire MO of these operations is to infect a company's systems, and wait until most or all of the backups are affects before locking the system down. They will wait months or for bigger targets, years.


Sorry, by air-gapped I was envisioning things like tapes or disconnected disk drives.


That doesn't help. The system is already infected when the backups are taken, therefore the backups are infected. That's why these criminal organizations wait months until actually locking your system down, so that your oldest backups are deleted by retention policy. If they have access to your system and can figure out what your backup retention policy is, they'll set it to go off at the point when all your backups are infected.


Can't they check their backups once every few months from an isolated infrastructure?


If they could check the backups for evidence of an intrusion, they would be able to check production for evidence of an intrusion.


I meant check for evidence of corruption not an intrusion itself. How do you hide the fact that the data is unreadable?


Ransomware is often not triggered quickly. They will compromise a box, install a back door, and hang onto it for months. You also have to consider that once they pop it, they can check other vulns that are available and will still be present after the restore.

When I do remediation I usually recommend restoring only business state but installing and configuring all OSes and applications from scratch with latest freshly downloaded versions. You can't trust any executable or dll that has been laying around.

That is not the restore dream that the backup provider sold them but reinfection is common. Once the bad guy has a privileged credential it is trivial for them to investigate for other vulns to use in the reinfection phase and nobody has just one critical vuln. If a business is susceptible to ntlm relay it's also going to have unsigned smb and non encrypted ldap traffic for the same root cause -- it was the default in 2005 and never got modernized.


Infected how?

Our backups were the data, not code or systems (which were IaC and rebuilt as needed).


For a concrete example, someone could infect an image storing service with code that encrypts (and silently decrypts) the data when it's stored / retrieved. When the hacker removes the decryption key from the running service, the backups will also be inaccessible because they are also encrypted.


Wouldn't this be a bright red flag that is trivial to check for?


Are user accounts data or systems? Compromise of AD is a very common means. This said this can still be fixed before putting it back where it could reach the internet and cause trouble.


No reason such an insurance company couldn't be run in the early/mid 20th century manner, entirely with paper records. Send carbon copies of all documents to two remote locations to eliminate the threat of a fire wiping out the records.

This is easy. It requires you to hire a lot of human clerks, but since the customers are large businesses that means there aren't a whole lot of customers in the first place. And if you can't get enough typewriters, there's no reason the clerk work couldn't be done on computers connected to printers, with all document storage still being done on paper. If the computers get pwned, throw them out and buy new ones; it doesn't matter because the documents weren't being stored on those computers.


The dumbest take of companies was assuming insurance companies would keep paying their ransom because they were thinking fixing their networks was less important

Oh well turns out it is not like that


False positives are indeed a major problem with bigtech. Just got into the situation myself when I was traveling to France and wanted to order some food with Deliveroo. Their antifraud systems banned me without any option to prove my legitimacy. Needless to say I just normally wanted to order something to eat, and I later used Uber Eats without any problems. Permanent ban without procedure to correct antifraud false positive (most likely due to my bank card issued outside of France).


Also, worth mentioning that I was banned after I have contacted the support because my orders were being rejected (this was my initial problem and the reason I contacted the support). It was the support team who banned me. This is a problem of its own: legitimate users should not be discouraged to contact the support.


The real threat came from the fine the government intended to impose on the companies. They threatened to fine not the fixed amount, as they did before, but to calculate it from the turnover values. Which could result in millions of dollars. The Russian government recently fined Booking with almost 18 million USD. For Google and Apple the fine could be even bigger.

The threat to employees on the other hand was not real one, there is no one to legally procecute in the Russian subsidiaries of the companies.


Without knowing much about the specifics... A threat can be totally real, even if "there is no one to legally prosecute". In most countries (even in countries that most people would consider more democratic), if people in power want to "make a point", they will find a way.

I'm an immigrant who moved from Hungary to Germany, lived in Spain and Mexico, and I know many examples from all countries where people in power got their way through various ways, even if they had no legal way to enforce their will on others. Also do not forget, if you control legislation, the judges, the constitution, the police, etc, what is legal one day, can become illegal and prosecuted and persecuted pretty quickly.


They don't need a legal ground to harm any Russian citizen. Last several years political repressions are gaining momentum and there's less and less care about keeping it in a legal field.


The entire Telegram encryption protocol is open source. So are the apps.


While Stripe team is great and it's always good to place all services under one roof, both registering US corporation and opening US bank account online is not something new, Harvard Business Services (www.delawareinc.com) had done company formation for years for startups and the fee is nicer ($250 single payment + $50/year for registered agent vs Atlas $500 single payment + $125/year for registered agent). Atlas is twice more expensive, which may be sensitive for early-stage startups.

We formed a C-corp with HBS. Then opened SVB account for free, printed standard incorporation docs, got EIN from IRS and opened account with Braintree (could be Stripe as well), all for free. We just had to use different websites instead of one, but no additional difficulties.


Someone from DJI forums contacted B&H employee at store on this and he said it's at least until the end of January. Not official information, though.


Now it would not surprise me much even if they go public (IPO), before releasing the actual product to the market. That would be a nice precedent for the tech startup industry.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: