Earlier quoted context omitted.
Indeed. It now potentially includes a very long list of Americans.
What does that mean?
Multiple Russia-aligned threat actors actively targeting Signal Messenger
141–150 of 329 posts
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#142Earlier quoted context omitted.
You cited this so I think this is what you mean: "Signal is designed to never collect or store any sensitive information." I interpret this, I think reasonably, to not include encrypted information. For that matter they collect (but probably don't store) encrypted messages. The question is, does PIN+SGX qualify as sufficiently encrypted? This line is a lie only if it does not. Sorry I skimmed those articles, I don't…
"I interpret this, I think reasonably, to not include encrypted information" Why? Encrypted information is still sensitive information.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#143Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#144Earlier quoted context omitted.
[flagged]
This comes as news to me, and rather disappointing news at that. Do you have a source I can read further?
https://community.signalusers.org/t/proper-secure-value-secu...
https://web.archive.org/web/20210126201848mp_/https://palant...
https://www.vice.com/en/article/pkyzek/signal-new-pin-featur...
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#145Earlier quoted context omitted.
Phones aren’t secure but are more secure than the standard radios most have access to. Encrypted milspec comms aren’t the standard in a massive war. It’s weird but discord, signal and some mapping apps on smartphones are how this war is being fought.
Russians aren't allowed to bring phones on the frontlines apparently but Ukranians often do still as they have the combat management app which is critical to operations. I've always wondered if this is why there's far more published footage of Ukranian combat video than Russian. Beyond the donation incentive they attached to videos when publishing them on Youtube/Telegram.
And I think a pretty much all published Ukrainian and Russian combat footage is vetted by their respective military (who would want to be court martialed for Reddit karma?).
They just take different approaches to what, when and were to release the footage.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#146Earlier quoted context omitted.
This is the glib over simplification he was complaining about with a haughty poorly informed statement We have never done it with an ally this critical of this size with this level of investment. Yes we have done it with smaller, less critical nations very often and it is of coruse atrocious. In fact Sadam, Bin Ladin, and others were all originally our allies that we betrayed. But we never did it against an aggressiv…
True, but Europe has been relying on Russian oil for decades now, and the attempt to restrain the influence of Russia on European powers has become a great strain on the US. It pushed Russia closer to China and made it more likely that the US would get more involved in interminable proxy wars with a powerful eastern allience at the expense of its economic development. While I’m not a fan of Putin, I can’t see any str…
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#147Signal (and basically any app) with a linked devices workflow has been risky for awhile now. I touched on this last year ( https://news.ycombinator.com/context?id=40303736 ) when Telegram was trash talking Signal -- and its implementation of linked devices has been problematic for a long time: https://eprint.iacr.org/2021/626.pdf . I'm only surprised it took this long for an in-the-wild attack to appear in open liter…
If I'm reading that right, the attack assumes the attacker has (among other things) a private key (IK) stored only on the user's device, and the user's password. Thus, engaging on this attack would seem to require hardware access to one of the victims' devices (or some other backdoor), in which case you've already lost. Correct me if I'm wrong, but that doesn't seem particularly dangerous to me? As always, security o…
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#148Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#149Earlier quoted context omitted.
You cited this so I think this is what you mean: "Signal is designed to never collect or store any sensitive information." I interpret this, I think reasonably, to not include encrypted information. For that matter they collect (but probably don't store) encrypted messages. The question is, does PIN+SGX qualify as sufficiently encrypted? This line is a lie only if it does not. Sorry I skimmed those articles, I don't…
> I interpret this, I think reasonably, to not include encrypted information I disagree since attacks and leaks can happen/have happened which could compromise that data. Signal was already found to be vulnerable to CacheOut. Even ignoring that guessing or brute forcing a pin is all anyone would need to get a list of everyone a signal user has been in contact with. just having that data (and worse keeping it forever)…
My point is only that the headline of your point was "they are lying about not storing sensitive information". That leaves out a very important part of your point. IMO it makes the claim seem sensationalized and starts you off on the wrong foot.