Live data from Hacker News

Signal on Android: Images sent to wrong contacts

github.com

231–240 of 403 posts

Re: Signal on Android: Images sent to wrong contacts

#231
post #215

Earlier quoted context omitted.

> You can choose to have sensitive conversations in person or not have them at all. I don't think this is fair. Most of the solution to this is "not having them at all." That's not a good solution and still doesn't solve your problem since you can still be listened to. > There's iMessage/FaceTime, for instance. Which also has gotten in trouble recently with Pegasus as there was a 0-click exploit in iMessage. Honestly…

I think what I'm trying to get at is that incorrectly believing you have access to a secure messenger can be worse than acting as if you don't, if those are your options. The whistleblower might choose not to make contact, but if the alternative is making contact and immediately going to prison (because someone else on your contact list saw a classified screenshot from you and told the authorities), maybe that's bett…

> I think what I'm trying to get at is that incorrectly believing you have access to a secure messenger can be worse than acting as if you don't, if those are your options.

For the average person, I do not believe this is true. For the non-average person, I believe you are correct but most of these people are aware and should be constantly trained.

I'm not saying you're wrong, I'm saying that there are two different conversations to be had and we need to know which one we're having. To me it looks like Signal is about as good as you get without loads of complication and for what it is meant to do.

> he Pegasus exploit does reflect badly on Apple

And same with this on Signal. I do believe we should hold these companies to high standards. But the point I'm trying to make is that these also aren't reasons to abandon the platforms completely (as many users are suggesting here). That's throwing the baby out with the bathwater.

Re: Signal on Android: Images sent to wrong contacts

#232
post #10

> [..] his Signal randomly sending images to me that he didn't intend to, even without initiating the addition of any attachments on the GUI... he even sees one of my messages displayed on his side with a random image attached to it, as if i have sent that image to him, even though that image is not even present on my phone. https://github.com/signalapp/Signal-Android/issues/10247#iss... Yikes. > [..] I've also recen…

> I've also recently had a probably unrelated issue where my mic was still audible to the other party after I hung up the call. That one there is a cataclysmic security land mine. Absolutely unacceptable. That was the last straw after [0]. I don't think I can recommend Signal at this time. To Downvoters: So these bugs are all fine then? They are not security issues then? Not only having images being sent to the wrong…

Laurens Cerulus @laurenscerulus Feb 20, 2020

News: The EU Commission told its staff to start using @signalapp to chat to friends and contacts. The move is part of an effort to fix the holes in EU cybersecurity. Story (for Pros for now) https://twitter.com/bendrath/status/1230455295018766337

Re: Signal on Android: Images sent to wrong contacts

#233

Earlier quoted context omitted.

Quill? Why would we want to use Quill that needs all of our private data? Have you not seen over at Apple App Store what they’re sucking off of your phone from your Quill app?

Which is why I said at worst . Please read. Could you recommend a better chat app that is user friendly enough for regular people to use that is not Signal or WhatsApp and is cross platform? Quill are at least working on E2E, not introducing a cryptocurrency like Signal and don't require your phone number.

>are at least working on E2E

So they're in the process of moving it from 1995 to 2004. That's great!

If all you have on Signal is opt-in feature for payment, and an issue of usernames that's being worked on -- but you want to offer as a solution a product that's for now, completely insecure by design (but it's being worked on), you're in dangerous waters. This is especially condemnable because the issue with Signal here is confidentiality of sensitive data.

You'd replace a one-in-a-billion database key collision problem with 100% of content leaking to service provider that literally offered the Telegram defense "The AES256 key is on a DIFFERENT computer". It's not. It by definition of how computers work, can not be. The database key sits in the RAM of the database server doing the database commits. The CPU can't perform AES operations without the key, and the key isn't being quantum teleported from another machine's RAM to the registers of the computer doing the encryption. These guys have no idea how computer security works, yet you deem them worthy of your attention. This makes me question your expertise on the subject matter too.

Re: Signal on Android: Images sent to wrong contacts

#234
post #47

Earlier quoted context omitted.

Why on Earth are people downvoting you? This is an absolute dealbreaker for any messaging app, much less one whose raison d'etre is privacy and secure messaging.

So which app would you recommend?

This isn't a valid argument.

Re: Signal on Android: Images sent to wrong contacts

#235
post #104

Earlier quoted context omitted.

> This bug was extraordinarily rare, and because we have no metrics/remote log collection, there was an initial period where we had to spend time adding logging and collecting user-submitted logs to try to track it down. Without telemetry, can you actually back up the claim that this issue was extremely rare?

Some details on how this assumption was made would be nice, but I think it's pretty obvious that any developer involved in a project can make a reasonable assumption of how rare a bug is depending on the technical details on what is required for the bug to happen. For example, if we say for the sake of argument that a hypothetical bug requires you to have more than ten contacts of the exact same name and these also n…

> just based on common sense regarding how the application is normally used

Just based on assumptions of how the application is used.

"falsehoods programmers believe" comes to mind. The uniqueness of names in your example could be false in some (or many? No idea) cultures.

Re: Signal on Android: Images sent to wrong contacts

#236

Earlier quoted context omitted.

That is idiotic. It's strictly, objectively worse than Signal and not even acceptable in the worst case .

How can you be so sure if you haven't tried it? I'd rather use a chat app that takes security matters seriously and urgently and will eventually have E2E. What's more 'idiotic' is prioritising and bolting on cryptocurrencies [0] than fixing urgent security issues, leaving it for months unfixed, while also claiming to be private and secure, and also requiring your phone number. [0] https://www.wired.com/story/signal-m…

>I'd rather use a chat app that takes security matters seriously and urgently and will eventually have E2E.

Deploying messaging app without E2EE being the first four chars on the security design paper -- even before the product name -- is the opposite of taking security matters seriously.

Re: Signal on Android: Images sent to wrong contacts

#237

I have no horse in this race. I don't use Signal or any of its competitors, so allow me to ask some basic questions. Could some users explain why you currently use Signal, and additionally, why you would continue to do so? It appears to me that not only this bug, but more importantly, the laissez-faire resolution of it is the opposite of what a privacy based app should do. Based on their homepage, it looks like they'…

Personally, I use it because it was the best choice a couple of years ago, and I (somewhat recently) managed to convince family to use it too.

However, after this, I am probably going to set up my own Matrix server and use that as much as possible, encrypted of course.

Re: Signal on Android: Images sent to wrong contacts

#238
post #128
post #79

Earlier quoted context omitted.

So, did they disclose the issue? Were people using Signal warned somewhere that this was a known issue that they were hunting down? (I am guessing not as no one here has been like "oh yeah: everyone using Signal knew to be careful with this feature".) It being a difficult bug to fix doesn't mean that's your only recourse for something this serious.

Does any app push bug report notifications to users? Should Microsoft Windows or Google Chrome warn users every time there’s a bug that can compromise their whole system just by visiting a certain website or downloading random pieces of software only a tiny subset of users will ever be exposed to? I get the motivation with a security/privacy critical app like Signal but this would also be a UX and customer support ni…

Usually when there are serious bugs in Windows, these get notified.

Latest example: https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...

Released Jul 1, 2021

Workarounds:

Option 1 - Disable the Print Spooler service

Option 2 - Disable inbound remote printing through Group Policy

Re: Signal on Android: Images sent to wrong contacts

#239

Earlier quoted context omitted.

The chat client misinterprets something and attaches a file to the message. The encryption works fine, the business logic of the app failed. E2EE won't protect you from a client accidentally encrypting and submitting files in the wrong chats.

But what exactly went wrong with signal here? Could someone remotely instruct my signal client to share media? Previously sent or arbitrary files?

They would have to compromise your client which is in no way different from compromising your device. The NSO / Pegasus systems do just that. They allow arbitrary command execution, which includes sending any file on your phone to any contact over Signal. Nothing software can do to protect from that. If you need 100% guarantee something doesn't leak over electronics, don't store it electronically. Ask them Slavs https://www.theguardian.com/world/2013/jul/11/russia-reverts...

Re: Signal on Android: Images sent to wrong contacts

#240
post #82

Earlier quoted context omitted.

Can you provide a link to the commit that fixes it? Shouldn't there have been an announcement to inform users what has been leaked and under which circumstances? How can user A send an image to user B that neither of them took? Isn't everything end-2-end encrypted? Then how can unencrypted data from user C end up on the device of user B?

> Can you provide a link to the commit that fixes it? If I understand the issue [0] correctly, these two commits should be the fix: https://github.com/signalapp/Signal-Android/commit/e90fa05d6... https://github.com/signalapp/Signal-Android/commit/b9657208f... The former updates how recipients (or really threads, I suppose) are merged (the issue occurred when trimming threads) and the latter changes the way how thread…

I love the terrible commit name. "Updating recipient merging."
Post reply on HN