Live data from Hacker News

Viewing profile — inor0gu

inor0gu

HN member
Joined
Wed, Feb 19, 2025, 8:52 PM UTC
HN karma
41
Public activity
16 items

About inor0gu

No profile information was provided.

Recent public activity

  1. comment
    Comment #43112815

    > government actor can intercept the text message Signal and others use for verification and set up the victims account on a new device Yes, but if they only control the phone numb…

  2. comment
    Comment #43112295

    Revocation of trust is always a tricky issue, you can look at TLS certificates to see what a can of worms that is. The Signal server does not forward messages to your devices, and …

  3. comment
    Comment #43109198

    About the paper: if someone has gotten access to your identity (private) key, you are compromised, either with their attack (adding a linked device) or just getting MitM'ed and all…

  4. comment
    Comment #43108685

    > latest and shittiest marketing lingo It exists since Android 6: https://developer.android.com/reference/com/google/android/m... Informative banner that does not require user inte…

  5. comment
    Comment #43108557

    I don't think they are insane, they are quite useful when designing security mechanisms, while at the same time being utter noise for the end-user benefiting from that system. > If…

  6. comment
    Comment #43108353

    You will always have to root your trust in something, assuming you cannot control the entire pipeline from the sand that becomes the CPU silicone, through the OS and all the way to…

  7. comment
    Comment #43108207

    Probably not, in any normal case a secondary device shouldn't have that kind of authority to dictate. It is more concerning if the toggle is on by default and then you carelessly p…

  8. comment
    Comment #43108108

    Would probably lead to notification fatigue. Showing a big snackbar when a new device is added is probably enough, especially if the app can detect there was no "action" on your ph…

  9. comment
    Comment #43107984

    Unrelated most likely, signal.me is a legitimate domain used by Signal. Doubt twitter is so on top of Threat Analysis when they fumbled their own redirects from twitter.com to x.co…

  10. comment
    Comment #43107965

    Signal doesn't collect that data, but you have no reason to trust me on it. Look at what data they can provide to governments when compelled by law: https://signal.org/bigbrother/

  11. comment
    Comment #43107946

    you also send them your contacts in plaintext so you can find who's also on WhatsApp; signal doesn't

  12. comment
    Comment #43107928

    Unrelated most likely, signal.me is a legitimate domain used by Signal. Doubt twitter is so on top of Threat Analysis when they fumbled their own redirects from twitter.com to x.co…

  13. comment
    Comment #43107898

    I would also read it from another perspective. Attackers, especially at the level of nation states, will always try to get as many avenues for achieving their goals as possible. If…

  14. comment
    Comment #43107802

    Your phone (primary device) and the linked ones have to share the IK since that is the "root of trust" for you account: with that you generate new device keys, renew them and so on…

  15. comment
    Comment #43107706

    That's not what the attack does tho - they have access to your private key so they can complete the linking protocol without your phone and add as many devices as they want (up to …

  16. comment
    Comment #43107587

    The attack in that paper assumes you have compromised the user's long term private identity key (IK) which is used to derive all the other keys in the signal protocol. Outside of l…