cross-posted from : https://lemmy.zip/post/71321898
Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance
I might be mistaken but I don’t think Signal uses SMS alone to gain access to a chat so the attack vector for the Signal part based on what the article is saying is that the police are just getting access to a device that’s already authorised (and has the keys) then just adding in another device which they control. This sounds like Signal functioning as expected. The article does refer to police not wanting to give away too many details to maybe there’s something that hasn’t been disclosed, but the cited methods (assuming SMS is off the table for Signal) sound like normal behaviour.
Signal failed to prevent soneone from accessing my unlocked phone and starting Signal! Everything was right there!
On iOS you can set an app to require additional credentials to open, to prevent this situation. I’d imagine Android had something similar. I did it for all my important apps, just in case. Don’t want someone able to access my bank account
or nudes.Just poked around. As far as I can tell there aren’t any options to require additional credentials to open an app on android. Im on a pixel 10 running android 17. However there is a locked “app drawer” that hides the apps from your home screen/ main app drawer that you need to have an additional password to access.
I have App Locker in settings iy let’s me use a fingerprint unlock on any apps I want, I assume it’s a stock Android feature.
fingerprint
guess what.
It s litteraly on the signal option “Require acces code to open signal”
Yes, but that’s a signal option, not an android option. The original commenters said ios had a feature to require additional credentials and was wondering about android, not a specific app that happens to be on android
There’s Private Space, but that’s not ideal for a general-purpose messaging app because notifications are suspended when the space is locked. Signal also has the option to require the same authentication method as your screen lock in order to access the app.
All of this is great, but there’s literally nothing stopping the next article from saying “user who left their phone unlocked with signal also unlocked ‘got hacked’”
You can lock Signal. It’s in it’s privacy settings.
Doesn’t help a whole lot if you hand the unlocked phone with the unlocked app to a police officer.
Because if you do, you just got Cellebrite’d. Your entire phone is compromised, now and going forward.
If someone can get unlocked access to your phone, your security practices are already insufficient. If you really want to prevent something like this, you need to make this first step impossible, not add a bandaid on top of it.
Real life isn’t that clean. Security is about layers and making things as difficult as possible; there is never a single step which will fully protect you from everything
Open source FIDO2 keys, KeePassXC, and Aegis.
SMS 2fa has always been a bad deal
I’ll never understand why people accept SMS 2FA as any kind of security. Might as well put it as an ad in a newspaper. 🤦🏻♂️
Because many services only have SMS as 2FA option. Especially government services.
Also it is impossible to use google without enabling the SMS 2FA option. No matter what, with only 2FA authenticator app or email, they will lock down the account by saying “unable to verify”.
I never set a phone number on two of my google accounts and they still work fine. Those accounts are old. Google didn’t ask for a phone number to sign up back then.
I recall seeing something about them planning to get rid of SMS 2FA last year. It looks like it’s still an option though.
Watch out, if those accounts are ever “locked”, you will get permanently locked out of the accounts. Happened to me because a data breach revealed my email address and some idiot tried brute forcing my password. Didn’t work but it broke the account. Secondary recovery email address and correct password wasn’t good enough. Support basically told me to give up and make a new account (???).
To me, this proves that the police can still get the information they need without us handing over our encryption keys and requiring ‘service providers’ to MITM for them.
Except they had to get the keys, at least for Signal, as described in the article. Only you can allow a new device. If you get a notification for a new device and you go “sure, let me flash that code for you”, you’re giving the key. And a moron.
Can’t say about the other services.
Yeah, what I’m saying is that this proves there’s no need for chat control. Law enforcement can already get what they want by being sneaky.
There’s also no need for chat control because there is almost always enough information anyway, but the police doesn’t act on it. Their incompetency and lack of resources won’t be helped by adding even more information to sift through.
Yes, I agree. I’m saying that the article posted here provides actual evidence that they already have the tools they need, therefore…
for signal, that is still required. if you look, they used linked devices to get the messages
That’s not MITM done by the signal foundation.
I meant us handing over our encryption keys. ofc MITM does not work here
Interesting they highlight Signal again as though this is a vulnerability.
If someone else has access to a linked device… that’s you fucking up access controls.
I want a version of Signal that doesn’t allow linked devices. Linking devices is a clear vulnerability.
Im going to go out on a limb here and suggest something that should be obvious - you don’t have to link devices
But “Law enforcement” can do it by spoofing sms. I want one account, one device.
Signal does not use SMS.
The vulnerability they call out in the article is a phishing attack. A phishing attack requires the user’s input. There is no defense, no security, no techniques or technology to prevent you from handing the key to your safe to someone else.
It’s a vulnerability precisely because people always swarm to defend Signal in stories like this, as though using Signal means the authorities (or other bad actors) can’t read your messages. Seems like every six months there’s some story involving Signal users getting hacked, and every time there’s a rush of wellacshuallys explaining why it wasn’t really Signal’s fault. (that last one is particularly egregious because I remember people defending it as “it wasn’t Signal, it was their partner who they subcontracted and gave your personal data to”, which is crazy levels of mental gymnastics.)
Security is more than just encryption. If you flag something up as “hey use this if you want to hide from the Government” and have a personal phone number attached to it, that’s like a red rag to a bull.
(edit: LOL, it’s hilarious how many people think they’re making great rebuttals in the replies when all they’re doing is proving my point. One child even flew directly into screaming at me. Signal fanbois are even worse than Apple supporters)
as though using Signal means the authorities can’t read your messages.
Nobody who understands the topic thinks this.
Signal exists to prevent the contents from being read off the wire and from having the capability of compelling Signal’s parent company from turning over stored messages.
It doesn’t exist to hand hold you so you don’t get phished, or prevent you from running it on a vendor phone full of spyware. You’re responsible for making sure your hardware is secure and that you’re not socially engineered.
Nobody who understands the topic thinks this.
Yes, and articles like this are important so people who DON’T understand don’t think this.
You don’t think the tens of millions of people who use signal all understand that just because everyone says it’s super secure, doesn’t mean they can’t be hacked or phished, right?
They even inform you in the app about spying vectors like keyboard apps…
https://support.signal.org/hc/en-us/articles/360055276112-Incognito-Keyboard
Yeah most people click through warnings like that lol
Why are you lying about what security guarantees Signal say they offer?
https://support.signal.org/hc/en-us/articles/9932632052378-How-to-protect-yourself-on-Signal
Even your example of the Twilio hack is far less relevant now since they added transparency logs, which means it is much harder to impersonate you without detection even if the hacker can control the telco
https://support.signal.org/hc/en-us/articles/10223569377562-Automatic-Key-Verification
IT DOESN’T ADVERTISE ITSELF AS A SECURE PLATFORM!!!
It says PRIVACY. If you are dancing ass naked inside your house but you have your windows open… guess what?
A lot of these types use ‘perfect being the enemy of good’ as their attack vector. If it’s not private and anonymous why bother? If you can’t cut out all big tech companies, if you can’t stop buying any American goods, if you can’t feed all the poor or house all the homeless, etc. It’s an effective way to attack progression by making people believe they should just stop fighting, they’ll never win. You nailed it, Signal is private, it doesn’t claim to be anything else.
You just pointed something out there that I haven’t really considered. But its also the difference between abolitionists and reformists too- namely, abolition should be the goal, but don’t let that stop you from making reforms too.
Seems like signal could send a notification 24 hours after any new device is added to remind the user that it was done. Make it so it has to be dismissed on each device so dismissing it on one doesn’t make it vanish on the rest.
doesn’t help if you’re in custody and your device is in a lab
Signal in this was clickbait they literally just say oh well if someone can link in their device they can see 45 days of message history
The headline makes people think signal is somehow broken.
It’s not. Just be careful and monitor your account. And don’t let anyone gain physical control of your device.
Is everyone here really whining about social engineering? It’s basic comp sec, weakest link are the people.
It goes above that.
or intercepting SMS messages via telephone surveillance.
Read the fucking article before commenting.
What’s described in the article is the same method Russia was using to compromise Ukrainian Signal accounts. It’s just phishing.
you know what would solve this? simplex.
“Just get everyone in your life to move to ______ and that will solve all your problems”
A suggestion as old as time
it’s one of the most secure message apps available.
messages are signed, encrypted and passed through servers, never left on the server. unless you were the intended recipient you will not decrypt it.
it’s the truecrypt of instant messaging.
Signal does all that already
signal has a closed source server that can’t be audited.
https://github.com/signalapp/Signal-Server
That changed
what does it need a database for?
simplex is literally a message broker. no data remains on the server.
Signal doesn’t keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don’t have your metadata.
The article also mentions using linked device access. Clever. Fuck the police, though.
There have been too many of these types of events related to signal. And it has so many red flags. You are required to have a phone number which is essentially ur real identity. They used to federate with 3rd party servers but they killed that and all but wiped it from the internet. They try to shut down 3rd party clients. They don’t provide reproducible builds so we can’t trust the source. They received their initial funding from In-Q-Tel the CIA venture capital firm.
Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.
At minimum they have a full social graph of real identities with time-stamped message events. Sealed sender doesn’t negate this as signal knows ur ip address when u give them a message. They also know the destination of that message as that isn’t sealed. This is sufficient information to link sender and recipient and timestamp. That’s assuming the unreproducible builds don’t have backdoors.
It’s all got a slightly fishy smell to it.
Tldr: If u want actual secure messaging u should consider SimpleX
There are all of these stories about signal because it is notable when someone gets around it
That there’s anything approaching secure communication on a cell-phone dominated Internet whose.operating systems are either “snobbish walled garden” or “ad agency living in the corpse of a search engine” is astonishing. In the same way that a gun safety that keeps a toddler from shooting themselves with an otherwise loaded gun is astonishing.
can’t get around simplex encryption unless you have physical access to the device or have been physically invited by a member.
Ok so no better than Signal?
You can do all the same things and use Tor, allow Sealed sender, and rotate username with phone number hidden.
Why does Simplex want investors?
what company doesn’t want to grow or maintain services? they host the primary servers that everyone uses, that costs money.
you could host your own though. can you do that with signal?
If I only want to talk to my own group of people registered on my server yes
as I pointed out in your other comment. signal uses a database, fails to explain why a database is required, and doesn’t even make a mention of it in their technical information.
why use a database at all? that just introduces more attack surface area and complexity for attackers to leverage.
Yeah precisely you didn’t check what it’s for. It doesn’t hold conversation data or even metadata.
Not to quote myself but:
Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.
You should trust signal tree the same way you trust a front door lock that has never been broken or picked despite repeated attempts to do both.
.Just remember that police only go through the door when it’s easier than breaking a window or tearing through a wall.
The US government has openly stated they killed people because of metadata and ur comfortable just giving that all away? U also didn’t address any of my precise exact points you simply made a vague deflection.
Signal doesn’t reveal that kind of metadata.
All ur messages have a recipient address. All ur messages go though signal servers. You have an IP address that u communicate to said servers with. They know when and who you are messaging.
Telegram and whatsapp never had encryption. Also - they just give your messages on law enforcement request, always have.
Signal - how does it work with signal again?
You don’t ask too many questions about signal cos the answers don’t make you any more confident.
WhatsApp uses signal protocol
But that does not prevent Meta from accessing your messages.
How?
WhatsApp is owned by meta
Signal protocol is end to end encrypted
Yes. How does that happen? You open the app you type a message you hit send. In that process WhatsApp has access to your clear text message that they get from the keyboard. They can do whatever they want with that. They could encrypt your message with your key and also one of their keys. They could send those together so that they look like one message but at their servers split their copy off.
They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.
Which is clever, to be fair. Whether or not that’s legal is already a court case. The law is so frightfully grey.
Its also a failure of the user’s access control and operating security.
Once a third party has access to the secure environment, that environment is and will always be compromised.
Is the user made aware of this by the operator (signal, telegram, et al)?
If not, it’s a big haul to get to competency. The operator should be educating users on how to limit compromise.
i just logged into signal on my desktop app about 4 hours ago, and about 90 minutes after that i got a message from signal to my phone to inform me about this.
What exactly did they tell you?
“hey, somebody logged into your signal account on desktop about an hour ago. might want to check that that was actually you”
Heck the state












