Fixed: https://github.com/signalapp/Signal-Android/issues/10247#iss...
A rather vague explanation. Sounds a bit evasive. Where is the commit that fixes it?
Signal on Android: Images sent to wrong contacts
211–220 of 403 posts
Re: Signal on Android: Images sent to wrong contacts
#212Earlier quoted context omitted.
Delta chat starts from reading email and theb works backwards: https://delta.chat/en/
Cool, my contacts can keep using their gmail account and leak all communication metadata to Google without me having any say on that if I want to talk to them. Where can I sign up?
Re: Signal on Android: Images sent to wrong contacts
#213Hi there, Signal-Android developer here. I updated the issue to reflect this, but this bug has been fixed. I was tracking it on a separate issue, and had forgotten to close this one. We do, in fact, take issues like this very seriously. This bug was extraordinarily rare, and because we have no metrics/remote log collection, there was an initial period where we had to spend time adding logging and collecting user-subm…
Can you provide a link to the commit that fixes it? Shouldn't there have been an announcement to inform users what has been leaked and under which circumstances? How can user A send an image to user B that neither of them took? Isn't everything end-2-end encrypted? Then how can unencrypted data from user C end up on the device of user B?
Re: Signal on Android: Images sent to wrong contacts
#214Hi there, Signal-Android developer here. I updated the issue to reflect this, but this bug has been fixed. I was tracking it on a separate issue, and had forgotten to close this one. We do, in fact, take issues like this very seriously. This bug was extraordinarily rare, and because we have no metrics/remote log collection, there was an initial period where we had to spend time adding logging and collecting user-subm…
You should have shut down the servers while this was happening - especially because you couldn't track it down. Shame on you for not caring about your users or their privacy when they were specifically using Signal for privacy. Edit: Anyone downvoting this also simply doesn't understand how serious this privacy leak really is. Shame on you too.
Wouldn't showing a warning suggesting not to post sensitive images while the bug is being investigated be better than straight up shutting down the service while solving the privacy issue?
Wouldn't closing the service have made people leave for other (probably worse) services, the one relying on privacy, privacy-minded people and "regular users" alike, and have worse consequences for privacy than this bug?
(not currently a Signal user, and I did not downvote your comment)
Re: Signal on Android: Images sent to wrong contacts
#215Earlier quoted context omitted.
Sure, but there's a small theoretical difference with democracy. You have to live under some system of government. You don't have to use a secure messenger. You can choose to have sensitive conversations in person or not have them at all. I agree that in practice, a lot of people are going to use their phones for relatively sensitive conversations, and in practice, Signal remains the best choice for doing so. But the…
> You can choose to have sensitive conversations in person or not have them at all. I don't think this is fair. Most of the solution to this is "not having them at all." That's not a good solution and still doesn't solve your problem since you can still be listened to. > There's iMessage/FaceTime, for instance. Which also has gotten in trouble recently with Pegasus as there was a 0-click exploit in iMessage. Honestly…
Take Reality Winner, for instance (the mechanics of that case were entirely unrelated to secure messengers, but it makes a relevant example overall). The effect on the world of her whistleblowing seems to have been minimal, and the cost to her was significant. Was it worthwhile? If she had been told the risks of the government identifying her were higher and decided not to leak anything, wouldn't that have been a better outcome?
I'm not saying there's perfect security. Vulnerable users absolutely need to be making risk assessments and deciding what they're comfortable with, and we should be clear nothing is risk-free. I'm just saying my sense of Signal's risk, in absolute terms, is higher than it was before I learned about this, and that matters to vulnerable users, not just the fact that it probably remains the lowest-risk messenger of the various options.
I agree with you overall, and the Pegasus exploit does reflect badly on Apple (and probably should reflect more badly on them than seems to be happening).
Re: Signal on Android: Images sent to wrong contacts
#216Earlier quoted context omitted.
"For the sake of argument" does not mean "I invite you to debate this", it means the exact opposite: "let's assume this is correct/we agree/etc. for a while and debate what comes after". So in this case you are doing the exact opposite of what the phrase "for the sake of argument" is requesting. https://idioms.thefreedictionary.com/for+the+sake+of+argumen... > I know you want to go to Stanford, but just for the sake…
It sounds to me like NullPrefix accepted the hypothetical bug, for the sake of the argument, and then addressed the rarity assumptions made about that bug. "For the sake of argument" doesn't mean "No debating" it means "Let's assume some thing x is taken as a given and go from there."
Re: Signal on Android: Images sent to wrong contacts
#217You say, "if someone had conversation trimming on, it could create a rare situation where a database ID was re-used in a way that could result in this behavior."
Is this someone user A or user B? Where is this database and what is it storing? Are these images previously sent or received from either A or B, or are they possibly from some thread between users C and D? How does this agree with end-to-end encryption?
How can you expect people to use your product with a bug this severe and no analysis of the impact or a statement as to who might have been affected?
Re: Signal on Android: Images sent to wrong contacts
#218Earlier quoted context omitted.
Selective quoting? "As soon as we were able to pick up a scent, it was all we worked on, and we were able to get a fix out very quickly."
Oh sorry, I interpreted it differently. Tho it still doesn't change anything, they prolonged investigating this issue for months and only put mayor work behind it when they "pick[ed] up a scent on it". Although they knew about it from day one (one Signal staff replied on the same day the issue was posted).
Re: Signal on Android: Images sent to wrong contacts
#219Earlier quoted context omitted.
> we were able to get a fix out very quickly. Is 6 months really what Signal considers quick for a bug that leaks private data?
Selective quoting? "As soon as we were able to pick up a scent, it was all we worked on, and we were able to get a fix out very quickly."
This is a company that aggressively markets itself to people needing privacy, and mistakes can ruin lives. And before you say it, they have tens of millions of dollars in funding.
Re: Signal on Android: Images sent to wrong contacts
#220Earlier quoted context omitted.
The chat client misinterprets something and attaches a file to the message. The encryption works fine, the business logic of the app failed. E2EE won't protect you from a client accidentally encrypting and submitting files in the wrong chats.
But what exactly went wrong with signal here? Could someone remotely instruct my signal client to share media? Previously sent or arbitrary files?