Live data from Hacker News

Signal: Firm claims to have cracked chat app's encryption

web.archive.org

11–18 of 18 posts

Re: Signal: Firm claims to have cracked chat app's encryption

#11
post #4

> We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”. I'm not familiar with Android, but is this an easy step, or a "draw the rest of the fucking owl" step?

It's the "draw the rest of the fucking owl" step because it implies you've already compromised the whole device.

Re: Signal: Firm claims to have cracked chat app's encryption

#12
> Signal keeps its database encrypted using SqlScipher, so reading it requires a key. We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”.

> Once the decrypted key is obtained

there are a few steps missing between these 2 paragraphs!

Re: Signal: Firm claims to have cracked chat app's encryption

#13
post #6

> Decrypting Signal messages and attachments was not an easy task. It required extensive research on many different fronts to create new capabilities from scratch. At Cellebrite, however, finding new ways to help those who make our world a safer place is what we’re dedicated to doing every day. Nice PR spin and non-story - yes, with access to the Android keystore secret, the database can be decrypted. Doesn't work if…

I wonder why Signal's locking/password feature is not enabled by default or at least hinted at.

Re: Signal: Firm claims to have cracked chat app's encryption

#14

While potentially worrisome I always figured the biggest benefit of using Signal was the self destructing messages. If you are (as the article states) using Signal as a protester to "communicate securely with their teams marshaling protestors, discussing tactics..." I would definitely enable self destructing messages in short time frame. Also in order to get to the Signal data storage you would first have to defeat t…

I have self destructing messages turned on. But only because I’ve never understood the need to cling on to message histories year-after-year, from old device to new device, to the next. Maybe my circle of friends, and myself, just aren’t that interesting enough to archive. I delete email too, except anything financial.

Re: Signal: Firm claims to have cracked chat app's encryption

#15
> This (was!) an article about "advanced techniques" Cellebrite uses to decode a Signal message db... on an unlocked Android device! They could have also just opened the app to look at the messages.

> The whole article read like amateur hour, which is I assume why they removed it.

- Moxie

[1] https://twitter.com/moxie/status/1337434126186553345

Re: Signal: Firm claims to have cracked chat app's encryption

#18

How long until devices start using TPM-type chips to store secrets? I get that this is a silly threat model, but the sooner we rely on non-mass storage for secrets, the better.

Apple devices already do with their “Secure Enclave”.

Android is much more fragmented ecosystem but most flagship manufacturers offer something similar.

Post reply on HN