Telegram News
1.07K subscribers
127 photos
83 links
๐Ÿ—ž @geeksChannel
๐Ÿ”Ž @stickersChannel
๐Ÿค– @botsChannel
๐ŸŽฎ @tlgramGames

FUN
๐Ÿ“บ @gifsChannel
๐Ÿ˜ฑ @viralChannel

CHANNELS/GROUPS
๐Ÿ“ข @tlgrmChannels
๐Ÿ‘ฉโ€๐Ÿ‘ฉโ€๐Ÿ‘งโ€๐Ÿ‘ฆ @groupsTelegram

๐ŸŽจ THEMES
PC @desktopThemes
android @themeChannel

need promotion? @S4Support

โšก๏ธ by @S4Dynamics
Download Telegram
โœณ๏ธ SECURITY | CRYPTOGRAPHY โœณ๏ธ

Computer Science Master's thesis
Aarhus University Denmark ๐Ÿ‡ฉ๐Ÿ‡ฐ
_________________
๐Ÿ”ง A practical cryptanalysis of the Telegram messaging protocol
_________________
๐Ÿ‘ฅ Author: Jakob Bjerre Jakobsen
๐Ÿ‘ฅ Supervisor: Claudio Orlandi
_________________
Full document: http://cs.au.dk/~jakjak/master-thesis.pdf

#security #cryptography #cryptanalysis #MTProto
โœณ๏ธ SECURITY | CRYPTOGRAPHY โœณ๏ธ


โ€ผ๏ธ CONCLUSIONS โ€ผ๏ธ

โ–ถ๏ธ In this work we have shown that Telegram, with its use of aging primitives, does not manage to provide data integrity of ciphertexts nor authenticated encryption, and is vulnerable to chosen-ciphertext attacks.

โ–ถ๏ธ The attempt to mitigate known attacks has introduced new vulnerabilities, and we suggest that the Telegram team updates its protocol to use strong, modern primitives.

โ–ถ๏ธ For message authentication codes it should use a good HMAC, use a proper key derivation function, and up date the key exchange to use elliptic curve Diffie-Hellman based on Curve25519. Telegram has a great emphasis on computational performance of its protocol, which is why CTR with its parallelization seems to be the logical choice of encryption mode. We suggest using CTR instead of IGE mode, as IGE offers no benefits over CTR.

โ–ถ๏ธOverall, we can conclude yet again that homegrown cryptography is a bad approach.

#security #cryptography #cryptanalysis #MTProto
โœณ๏ธ SECURITY | CRYPTOGRAPHY โœณ๏ธ

๐Ÿ“• ABSTRACT ๐Ÿ“•


โ–ถ๏ธTelegram is a popular messaging app which supports end-to-end encrypted communication. In Spring 2015 we performed an audit of Telegram's source code. This short paper summarizes our findings.

โ–ถ๏ธ Our main discovery is that the symmetric encryption scheme used in Telegram -- known as MTProto -- is not IND-CCA secure, since it is possible to turn any ciphertext into a different ciphertext that decrypts to the same message.

โ–ถ๏ธ We stress that this is a theoretical attack on the definition of security and we do not see any way of turning the attack into a full plaintext-recovery attack. At the same time, we see no reason why one should use a less secure encryption scheme when more secure (and at least as efficient) solutions exist.

โ–ถ๏ธ The take-home message (once again) is that well-studied, provably secure encryption schemes that achieve strong definitions of security (e.g., authenticated-encryption) are to be preferred to home-brewed encryption schemes.

#security #cryptography #cryptanalysis #MTProto