|
|
|
|
|
by Nursie
4568 days ago
|
|
>> > they are trying to do “Mac and Encrypt” which is not secure.
>> We are not doing this. We are doing this: http://core.telegram.org/techfaq#q-are-you-doing-encrypt-the.... Right, but you still include the sha-1 of the plaintext in your outgoing message, which is (IIRC) generally considered bad practice because it leaks information about the plaintext. |
|