"Russia-aligned threat actors" has a whole new meaning this last week.
Multiple Russia-aligned threat actors actively targeting Signal Messenger
131–140 of 329 posts
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#132Earlier quoted context omitted.
The US was never the “hero,” you’re just not used to broad shifts in US policy broadcast so loudly. But this has happened numerous times in the past to other “allies.”
This is the glib over simplification he was complaining about with a haughty poorly informed statement We have never done it with an ally this critical of this size with this level of investment. Yes we have done it with smaller, less critical nations very often and it is of coruse atrocious. In fact Sadam, Bin Ladin, and others were all originally our allies that we betrayed. But we never did it against an aggressiv…
They were not allies, or not at all in the same sense. They were people the US did business with because of a common enemy, and then stopped doing business with when the situation changed. I don't think Saddam or Bin Laden thought for a moment that they were allies of the US, like Denmark and Japan are.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#133Earlier quoted context omitted.
Even if everyone agreed that the system was secure, and they absolutely don't, see for example https://web.archive.org/web/20210126201848mp_/https://palant... https://www.vice.com/en/article/pkyzek/signal-new-pin-featur... I think we should all agree that outright lying to users on the very first line of their privacy policy page is totally unacceptable.
You cited this so I think this is what you mean: "Signal is designed to never collect or store any sensitive information." I interpret this, I think reasonably, to not include encrypted information. For that matter they collect (but probably don't store) encrypted messages. The question is, does PIN+SGX qualify as sufficiently encrypted? This line is a lie only if it does not. Sorry I skimmed those articles, I don't…
I disagree since attacks and leaks can happen/have happened which could compromise that data. Signal was already found to be vulnerable to CacheOut. Even ignoring that guessing or brute forcing a pin is all anyone would need to get a list of everyone a signal user has been in contact with. just having that data (and worse keeping it forever) is a risk that absolutely should be disclosed.
> I don't want to read them in depth. But it sounds like they are again ultimately saying "PIN+SGX is not secure enough".
that was my conclusion back when all this started. The glaring lie and omissions in their privacy policy were just salt in the wound, but charitably, it might be a dead canary intended to help warn people away from the service. Similarly dropping the popular feature of allowing unsecured sms/mms and introducing a crypto wallet nobody asked for might have also been done to discourage the apps use.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#134Earlier quoted context omitted.
Phones aren’t secure but are more secure than the standard radios most have access to. Encrypted milspec comms aren’t the standard in a massive war. It’s weird but discord, signal and some mapping apps on smartphones are how this war is being fought.
Russians aren't allowed to bring phones on the frontlines apparently but Ukranians often do still as they have the combat management app which is critical to operations. I've always wondered if this is why there's far more published footage of Ukranian combat video than Russian. Beyond the donation incentive they attached to videos when publishing them on Youtube/Telegram.
I’d want to run military communications on a network my side controls
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#135Earlier quoted context omitted.
You cited this so I think this is what you mean: "Signal is designed to never collect or store any sensitive information." I interpret this, I think reasonably, to not include encrypted information. For that matter they collect (but probably don't store) encrypted messages. The question is, does PIN+SGX qualify as sufficiently encrypted? This line is a lie only if it does not. Sorry I skimmed those articles, I don't…
"I interpret this, I think reasonably, to not include encrypted information" Why? Encrypted information is still sensitive information.
Or if you want to be literal, you have to say that they're storing sensitive information even if it's encrypted. But by connotation that phrase implies that someone other than the user could conceivably have access to it. So for all any user could care, they just as well are not storing it. Do you mean that they should rephrase it so it's literally correct?
Or do you mean that it's actually bad for them to be collecting safely encrypted sensitive data? Because if so, you literally cannot accept any encrypted messenger because 3rd parties will always have access to it.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#136Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#137Earlier quoted context omitted.
Why would people give the most significant political events of this century so far "a rest"?
Because this thread is about a (potential) technological flaw in a communication app. It has nothing to do with the sitting US president.