{"id":28593,"date":"2015-01-16T06:40:58","date_gmt":"2015-01-16T11:40:58","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/how-much-trust-can-you-put-in-telegram-messenger.php"},"modified":"2015-01-16T06:40:58","modified_gmt":"2015-01-16T11:40:58","slug":"how-much-trust-can-you-put-in-telegram-messenger","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/encryption\/how-much-trust-can-you-put-in-telegram-messenger.php","title":{"rendered":"How much trust can you put in Telegram messenger?"},"content":{"rendered":"<p><p>    Messaging programs are a    closely watched application category, with experts scrutinizing    how communications are protected from government surveillance    dragnets and hackers. The primary defense invariably involves    encryption, but just saying an application uses encryption by    no means ensures its secure.  <\/p>\n<p>    One of the latest programs to    come under fire is Telegram, which is backed by Pavel    Durov[cq], who also founded the popular Russian social    networking site Vkontakte. Telegram is a free desktop and    mobile application launched in 2013 that promotes itself as    taking back our right to privacy.  <\/p>\n<p>    Telegram is well intended but    has several weak spots, said Alex Rad[cq], who has a background    in application security testing and reverse engineering. He and    researcher Juliano    Rizzo, who discovered two major attacks against SSL (Secure    Sockets Layer), have been analyzing Telegram intermittently    since last year as a side project to help improve its    security.  <\/p>\n<p>    They went public on Sunday    with a     blog post pointing out problems with Telegram, which may    cause concern for those who are particularly worried about how    such messaging systems could be compromised. Rad said in a    phone interview that his correspondence with Telegram has been    cordial but a bit tense.  <\/p>\n<p>    What bothered me about    Telegram was the way they market themselves versus the reality    of how people use their application, said Rad, who lives in    Stockholm.  <\/p>\n<p>    For example, Telegram doesnt    implement end-to-end encryption by default, a technique that    ensures a message is encrypted on a device and is only    decrypted by a recipient. That kind of encryption is regarded    as the safest way to send information.  <\/p>\n<p>    To send a fully encrypted    message, Telegram users must initiate a secret chat. But Rad    said there are potential problems with how a secret chat is set    up that could make it vulnerable to a man-in-the-middle (MITM)    attack.  <\/p>\n<p>    Before a secret chat begins,    two Telegram users see an image that verifies their connection    hasnt been tampered with. Rad describes in the blog post how    an attacker could replace that image with one of their own,    potentially giving assurance to users that their chat is secure    when it is not.  <\/p>\n<p>    Determining whether the MITM    attack would even be feasible leads to an academic argument    about computing power. Telegram has dismissed the attack in a    blog    post as too expensive to pull off. It also requires that    the attacker already has access to Telegrams servers, an    assumption that Rad concedes makes a MITM attack on two users    less likely given the vast hacking opportunities that such a    position would afford anyway. But he also said his theoretical    attack could be made impossible by using a stronger encryption    algorithm, a trivial upgrade for Telegram.  <\/p>\n<p>    Telegrams Markus Ra[cq] said    via email that while his company contests the feasibility of    Rads attack, Telegrams secret chats are evolving constantly,    and well make sure they stay secure even as potential    attackers gain processing power over time.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more from the original source:<br \/>\n<a target=\"_blank\" href=\"http:\/\/www.pcworld.com\/article\/2871412\/how-much-trust-can-you-put-in-telegram-messenger.html\/RK=0\/RS=tFb61a7YafgAuIBJeVteNbUx36E-\" title=\"How much trust can you put in Telegram messenger?\">How much trust can you put in Telegram messenger?<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Messaging programs are a closely watched application category, with experts scrutinizing how communications are protected from government surveillance dragnets and hackers. The primary defense invariably involves encryption, but just saying an application uses encryption by no means ensures its secure. One of the latest programs to come under fire is Telegram, which is backed by Pavel Durov[cq], who also founded the popular Russian social networking site Vkontakte. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-28593","post","type-post","status-publish","format-standard","hentry","category-encryption"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/28593"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=28593"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/28593\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=28593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=28593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=28593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}