Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

101–110 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#101
post #40

Signal (and basically any app) with a linked devices workflow has been risky for awhile now. I touched on this last year ( https://news.ycombinator.com/context?id=40303736 ) when Telegram was trash talking Signal -- and its implementation of linked devices has been problematic for a long time: https://eprint.iacr.org/2021/626.pdf . I'm only surprised it took this long for an in-the-wild attack to appear in open liter…

If I'm reading that right, the attack assumes the attacker has (among other things) a private key (IK) stored only on the user's device, and the user's password.

Thus, engaging on this attack would seem to require hardware access to one of the victims' devices (or some other backdoor), in which case you've already lost.

Correct me if I'm wrong, but that doesn't seem particularly dangerous to me? As always, security of your physical hardware (and not falling for phishing attacks) is paramount.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#102

Earlier quoted context omitted.

Yeah, this just gave me the last nudge I needed to give Signal a go.

[flagged]

Following the conversation down, it sounds like what you're really saying is that Signal stores sensitive information encrypted with PIN+SGX, which is controversial. And maybe you have a good argument for why it's bad (and I'm uneasy with it myself). But I think people don't like that you made the assumption for them that PIN+SGX is bad.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#103

Earlier quoted context omitted.

[flagged]

Following the conversation down, it sounds like what you're really saying is that Signal stores sensitive information encrypted with PIN+SGX, which is controversial. And maybe you have a good argument for why it's bad (and I'm uneasy with it myself). But I think people don't like that you made the assumption for them that PIN+SGX is bad.

Even if everyone agreed that the system was secure, and they absolutely don't, see for example

https://web.archive.org/web/20210126201848mp_/https://palant...

https://www.vice.com/en/article/pkyzek/signal-new-pin-featur...

I think we should all agree that outright lying to users on the very first line of their privacy policy page is totally unacceptable.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#105
post #44

Earlier quoted context omitted.

Is this serious? It raises questions about smartphones being standard equipment for soldiers, but they do give every soldier an effective, powerful computing and communication platform (that they know without additional training). The question is how to secure them, including against the risk described in the parent. That seems like a high risk to me I would expect someone is working on how to secure them enough that…

Phones aren’t secure but are more secure than the standard radios most have access to. Encrypted milspec comms aren’t the standard in a massive war. It’s weird but discord, signal and some mapping apps on smartphones are how this war is being fought.

Russians aren't allowed to bring phones on the frontlines apparently but Ukranians often do still as they have the combat management app which is critical to operations. I've always wondered if this is why there's far more published footage of Ukranian combat video than Russian. Beyond the donation incentive they attached to videos when publishing them on Youtube/Telegram.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#106
post #72

Earlier quoted context omitted.

Obligatory request to provide a source to backup some serious claims?

If you're a signal user and didn't know about this already, that should tell you everything you need to know about signal. See https://community.signalusers.org/t/proper-secure-value-secu... Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." ( https://signal.org/legal/ ) Signal loves to brag about the times when the gov…

I wanted to add that there is the cease and desist case against Signal-FOSS fork that tried to implement an open server, too.

In my opinion Briar is where it's at, but because there's no data collection it's pain to do a handshake or manage contacts.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#107
post #60
post #53

Earlier quoted context omitted.

I helped an especially non-technical user install Signal and they didn't need my help at all. They were using it in a minute - download from the app store, transcribe a code from a text message, and you're in - and it worked just like legacy text and phone. I'd tell them that - just download it and you'll be texting me in a minute, and now nobody is tracking everyone you talk to.

To be clear, someone will/can track WHO you talk to. Right?

My understanding is that they can/do on WhatsApp.

On Signal, unless there is a some bug or outright fraud, afaik they cannot - that is one of their fundamental goals, and they did a lot of work to develop communication technology that worked without revealing that metadata.

(Of course, if someone gets access to your phone, then they know who you are talking to.)

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#108
post #90

Earlier quoted context omitted.

If you're a signal user and didn't know about this already, that should tell you everything you need to know about signal. See https://community.signalusers.org/t/proper-secure-value-secu... Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." ( https://signal.org/legal/ ) Signal loves to brag about the times when the gov…

I see a link to a forum where an anonymous participant says “Since a recent version of Signal data of all Signal users is uploaded to Signal’s servers. This includes your profile name and photo, and a list of all your Signal-contacts.” They then link to a Signal blog (2019) explaining technical measures they were testing to provide verifiably tamperproof remote storage. https://signal.org/blog/secure-value-recovery/…

> 2) do you have a basis to suggest it’s “not-very-secure or likely backdoored,” in response to their apparently thoughtful and transparent engineering to ensure otherwise?

The forum post explains this:

> This data is encrypted by a PIN only the user can know, however users are allowed to create their own very short numeric PIN (4 digits). By itself this does not protect data from being decrypted by brute force. The fact that a slow decryption algorithm must be used, is not enough to mitigate this concern, the algorithm is not slow enough to make brute forcing really difficult. The promise is that Signal keeps tge data secured on their servers within a secure enclave. This allows anyone to verify that no data is taken out of the server, also not by the Dignal developers themselfs, not even if they get a subpoena. At least that is the idea.

> It is also not clear if a subpoena can force Signal to quietly hand over information which was meant to stay within this secure enclave.

That should be very concerning for activists/journalists who use Signal to maintain privacy from their government. Subpoena + gag order means the data is in the hands of the government, presuming Signal want to keep offering their services to the population of the country in question.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#109

Earlier quoted context omitted.

The US was never the “hero,” you’re just not used to broad shifts in US policy broadcast so loudly. But this has happened numerous times in the past to other “allies.”

This is the glib over simplification he was complaining about with a haughty poorly informed statement We have never done it with an ally this critical of this size with this level of investment. Yes we have done it with smaller, less critical nations very often and it is of coruse atrocious. In fact Sadam, Bin Ladin, and others were all originally our allies that we betrayed. But we never did it against an aggressiv…

True, but Europe has been relying on Russian oil for decades now, and the attempt to restrain the influence of Russia on European powers has become a great strain on the US. It pushed Russia closer to China and made it more likely that the US would get more involved in interminable proxy wars with a powerful eastern allience at the expense of its economic development. While I’m not a fan of Putin, I can’t see any strategic problems with the move.
Post reply on HN