logo
episode-header-image
Sep 2024
1h 4m

Telegram with Matthew Green

Deirdre Connolly, Thomas Ptacek, David Adrian
About this episode

We finally have an excuse to tear down Telegram! Their CEO got arrested by the French, apparently not because the cryptography in Telegram is bad, but special guest Matt Green joined us to talk about how the cryptography is bad anyway, and you probably shouldn't use Telegram as a secure messenger of any kind!


Transcript: https://securitycryptographywhatever.com/2024/09/06/telegram

Links:

- https://blog.cryptographyengineering.com/2024/08/25/telegram-is-not-really-an-encrypted-messaging-app/
- Lavabit / Ladar Levinson: https://en.wikipedia.org/wiki/Lavabit
- Pavel Durov indictment statement from French authorities: https://www.tribunal-de-paris.justice.fr/sites/default/files/2024-08/2024-08-28%20-%20CP%20TELEGRAM%20mise%20en%20examen.pdf
- MTProto 2.0 protocol spec: https://core.telegram.org/api/end-to-end
- https://words.filippo.io/dispatches/telegram-ecdh/
- MTProto 1.0 (old no longer used): - https://web.archive.org/web/20131220000537/https://core.telegram.org/api/end-to-end#key-generation
- OTR: https://otr.cypherpunks.ca/otr-wpes.pdf
- AES and sha2 used in ‘Infinite Garble Extension’ mode: https://eprint.iacr.org/2015/1177.pdf
- Four Attacks and a Proof for Telegram: https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=9833666
- History of Telegram e2ee chats availability: https://en.wikipedia.org/wiki/Telegram_(software)#Architecture
- https://securitycryptographywhatever.com/2023/01/27/threema/
- https://securitycryptographywhatever.com/2022/11/02/Matrix-with-Martin-Albrecht-Dan-Jones/
- https://en.wikipedia.org/wiki/Matrix_(protocol), introduced in September 2014


"Security Cryptography Whatever" is hosted by Deirdre Connolly (@durumcrustulum), Thomas Ptacek (@tqbf), and David Adrian (@davidcadrian)

Up next
Oct 31
Apple’s Memory Integrity Enforcement
Apple announced its new suite of memory security improvements from the top of the stack all the way to the bottom, so we dug through what they did and how they did it (performantly). Watch on YouTube: https://www.youtube.com/watch?v=9FJwOI2PliUTranscript: https://securitycryptogr ... Show More
56m 45s
Aug 23
Stop Using Encrypted Email with William Woodruff
There was a bug in an OpenPGP library which finally gave us an excuse to tear encrypted email via PGP to shreds. Our special guest William Woodruff joined us to help explain the vuln and indulge our gnashing of teeth on why email was never meant to be encrypted and how other mode ... Show More
1h 11m
Aug 16
Alex Gaynor
We chat with friend of the pod and special guest Alex Gaynor, former deputy chief technologist at the FTC and all around good Security Person™. Join for nerdery about WebAuthn, stay for accidentally melting down GitHub APIs around November 2020! Watch on YouTube: https://www.yout ... Show More
1h 25m
Recommended Episodes
Sep 2024
How Telegram Became the Underworld’s Favorite App
<p>A Times investigation has found that Telegram, one of the world’s biggest messaging apps, with nearly a billion users, is also a giant black market and gathering place for the likes of terrorists and white supremacists.</p><p>Adam Satariano, a technology reporter for The Times ... Show More
25m 45s
Sep 2024
The Telegram case: Privacy vs security
<p>What are the limits of privacy when it comes to our online lives? If authorities are investigating a crime, should they be able to access private messages sent between two individuals? In this episode of Tech Tonic, John Thornhill interviews Eva Galperin, director of cybersecu ... Show More
27m 50s
Sep 2024
The Telegram case: Pavel Durov
<p>The FT’s Innovation editor John Thornhill and San Francisco tech correspondent Hannah Murphy have in the past both met and interviewed Pavel Durov, the secretive founder of Telegram who was arrested in France for alleged failure to address criminality on the messaging app. In ... Show More
34m 52s
Aug 2024
Telegram’s nightmare week
Telegram CEO, Pavel Durov, is under investigation over criminal activity on the messaging app. He spent four days in detention after being arrested when arriving in France and is now barred from leaving the country.Sumi Somaskanda speaks to the BBC's Cyber Correspondent, Joe Tidy ... Show More
26m 35s
Nov 2024
Le Gouvernement français à fond sur l’app Signal ?
<p>L’été a été marqué par l’arrestation de Pavel Durov, le fondateur de Telegram, par les autorités françaises. Bien que le milliardaire franco-russe ait depuis coopéré avec l’État, l’application continue de traîner une mauvaise réputation. En témoigne une nouvelle circulaire adr ... Show More
2m 1s
Sep 2024
Telegram : accès libre aux IP et numéros de téléphone pour les autorités ?
<p>Le patron de Telegram, Pavel Durov, semble avoir opéré un tournant radical depuis qu'il est sous la supervision de la justice française et interdit de quitter le territoire. Connu pour sa résistance aux autorités, il coopère désormais pleinement avec les demandes légales. Ce c ... Show More
1m 49s
Aug 2024
Telegram : pourquoi ce réseau social inquiète-t-il autant les autorités ?
Pavel Durov, le patron du réseau social Telegram, a été arrêté et placé en garde à vue par la justice française samedi 24 août 2024. Une information judiciaire portant notamment sur des faits commis en bande organisée a été ouverte. Elle met en lumière les multiples controverses ... Show More
4m 24s
Sep 2024
SN 990: Is Telegram an Encrypted App? - CrowdStrike Exodus, DDoS-as-a-Service, 'Active Listening' Ad Tech?
Telegram puts End-to-End Privacy in the Crosshairs Free security logging is good for everyone CrowdStrike hemorrhaging customers Microsoft to meet privately with EDR (Endpoint Detection & Response) vendors Yelp's Unhappy with Google Telegram as the hotbed for DDoSass – DDoS as a ... Show More
2h 9m
Oct 2024
Signal’s Meredith Whittaker on Surveillance Capitalism, Text Privacy and AI
What do cybersecurity experts, journalists in foreign conflicts, indicted New York City Mayor Eric Adams and Drake have in common? They all use the Signal messaging app. Signal’s protocol has been the gold standard in end-to-end encryption, used by Whatsapp, Google and more, for ... Show More
1h 2m