Hacker News new | ask | show | jobs
by tarasmatsyk 1992 days ago
TL;DR

A TG server was sending a "salt" to clients in order to randomize keys (telegram claim) when in fact the "salt" turned out useless in terms of encryption and the only reasonable explanation for the "nonce" was using it as a backdoor to perform MITM attack.

You decide whether it was done intenionally or because of lack of sleep/understanding

PS. an original author got 100k$ for finding/exposing a potential backdoor.