Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

151–160 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#151
There are many voices which try to tell you that signal is compromised. Notice that all of those voices have less open-source-ness than Signal in virtually all cases.

Signal is doing its best to be a web scale company and also defend human rights. Individual dignity matters.

This is not a simple conversation.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#155
post #40

Signal (and basically any app) with a linked devices workflow has been risky for awhile now. I touched on this last year ( https://news.ycombinator.com/context?id=40303736 ) when Telegram was trash talking Signal -- and its implementation of linked devices has been problematic for a long time: https://eprint.iacr.org/2021/626.pdf . I'm only surprised it took this long for an in-the-wild attack to appear in open liter…

If I'm reading that right, the attack assumes the attacker has (among other things) a private key (IK) stored only on the user's device, and the user's password. Thus, engaging on this attack would seem to require hardware access to one of the victims' devices (or some other backdoor), in which case you've already lost. Correct me if I'm wrong, but that doesn't seem particularly dangerous to me? As always, security o…

No, it means that if you approve a device to link, and you later have reason to unlink the device, you can't establish absolutely that the unlinked device can no longer access messages, or decrypt messages involving an account, breaking the forward-secrecy guarantees.

That leaves you with the only remedy for a signal account that has accepted a link to a 'bad device' being to burn the whole account. (maybe rotating safety numbers/keys would be sufficient, i am uncertain there) -- If you can prove the malicious link was only a link, then yeah, the attack i described is incomplete, but the issues in general with linked devices and remedies described are the important bits, I think.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#156

Earlier quoted context omitted.

[flagged]

I'm not going to run interference against all the comments you're writing on this thread, because I don't think Signal needs the help and it would make the thread ultra-tedious. But during the brief window where people were taking Wire seriously as a Signal alternative, I'd occasionally write a comment or tweet like: Were you aware that Wire keeps a high-fidelity plaintext database of exactly who talks to who on thei…

Even if you thought that SGX was bulletproof and pins were impossible to brute force, instead of just being 'better than what most other apps use' what possible justification is there for outright lying to users by claiming that their app doesn't collect any sensitive data when it does?

Signal is advertised and recommended to some extremely vulnerable people whose lives/freedom depend on their security. Signal owes users a clear explanation of the risks that come from the use of their software so that whistleblowers, journalists, and activists can make informed choices. Lying to those users is disgusting.

Seen most charitably, the fact that the very first line of their privacy policy page is an outright lie might be intended as a dead canary to warn users away as loudly as they can, but even in that case I'll be happy to say it plainly: Signal shouldn't be trusted.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#158

"Russia-aligned threat actors" has a whole new meaning this last week.

[flagged]

Try to open news about USA-Russia latest talks. Basically Trump now is repeating propaganda topics from Russia Today, their fake claims about Ukraine.

USA pushed Ukraine to give up nukes, offered security assurances instead. And then during full scale war donated just 30 old tanks. And now Trump is talking with Putin behind Ukraine's back on how they should surrender.

Unfortunately USA is not a superpower anymore and their word means nothing.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#159

Earlier quoted context omitted.

> I interpret this, I think reasonably, to not include encrypted information I disagree since attacks and leaks can happen/have happened which could compromise that data. Signal was already found to be vulnerable to CacheOut. Even ignoring that guessing or brute forcing a pin is all anyone would need to get a list of everyone a signal user has been in contact with. just having that data (and worse keeping it forever)…

Okay, so you not only take issue with PIN+SGX, you think that any encryption scheme (at least from Signal) isn't secure enough. Your point still comes down to "they are storing sensitive information in a form that is ostensibly encrypted but still subject to attack (in the opinion of XYZ reputable people...)". My point is only that the headline of your point was "they are lying about not storing sensitive information…

That's fair, I can see how someone could feel that way.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#160
post #40

Signal (and basically any app) with a linked devices workflow has been risky for awhile now. I touched on this last year ( https://news.ycombinator.com/context?id=40303736 ) when Telegram was trash talking Signal -- and its implementation of linked devices has been problematic for a long time: https://eprint.iacr.org/2021/626.pdf . I'm only surprised it took this long for an in-the-wild attack to appear in open liter…

If I'm reading that right, the attack assumes the attacker has (among other things) a private key (IK) stored only on the user's device, and the user's password. Thus, engaging on this attack would seem to require hardware access to one of the victims' devices (or some other backdoor), in which case you've already lost. Correct me if I'm wrong, but that doesn't seem particularly dangerous to me? As always, security o…

“Just install this chrome browser extension” is all it takes now. Hell, you can even access cookies and previously visited sites from within the browser. All it takes is some funky ad, or chrome extension, or some llama-powered toolbar to gain access to be able to do exactly that.

Background services on devices has been a thing for a while too. Install an app (which you grant all permissions to when asked) and bam, a self-restarting daemon service tracking your location, search history, photos, contacts, notes, email, etc

Post reply on HN