Signal is doing its best to be a web scale company and also defend human rights. Individual dignity matters.
This is not a simple conversation.
151–160 of 329 posts
Signal is doing its best to be a web scale company and also defend human rights. Individual dignity matters.
This is not a simple conversation.
"Russia-aligned threat actors" has a whole new meaning this last week.
Signal (and basically any app) with a linked devices workflow has been risky for awhile now. I touched on this last year ( https://news.ycombinator.com/context?id=40303736 ) when Telegram was trash talking Signal -- and its implementation of linked devices has been problematic for a long time: https://eprint.iacr.org/2021/626.pdf . I'm only surprised it took this long for an in-the-wild attack to appear in open liter…
If I'm reading that right, the attack assumes the attacker has (among other things) a private key (IK) stored only on the user's device, and the user's password. Thus, engaging on this attack would seem to require hardware access to one of the victims' devices (or some other backdoor), in which case you've already lost. Correct me if I'm wrong, but that doesn't seem particularly dangerous to me? As always, security o…
That leaves you with the only remedy for a signal account that has accepted a link to a 'bad device' being to burn the whole account. (maybe rotating safety numbers/keys would be sufficient, i am uncertain there) -- If you can prove the malicious link was only a link, then yeah, the attack i described is incomplete, but the issues in general with linked devices and remedies described are the important bits, I think.
Earlier quoted context omitted.
[flagged]
I'm not going to run interference against all the comments you're writing on this thread, because I don't think Signal needs the help and it would make the thread ultra-tedious. But during the brief window where people were taking Wire seriously as a Signal alternative, I'd occasionally write a comment or tweet like: Were you aware that Wire keeps a high-fidelity plaintext database of exactly who talks to who on thei…
Signal is advertised and recommended to some extremely vulnerable people whose lives/freedom depend on their security. Signal owes users a clear explanation of the risks that come from the use of their software so that whistleblowers, journalists, and activists can make informed choices. Lying to those users is disgusting.
Seen most charitably, the fact that the very first line of their privacy policy page is an outright lie might be intended as a dead canary to warn users away as loudly as they can, but even in that case I'll be happy to say it plainly: Signal shouldn't be trusted.
"Russia-aligned threat actors" has a whole new meaning this last week.
"Russia-aligned threat actors" has a whole new meaning this last week.
[flagged]
USA pushed Ukraine to give up nukes, offered security assurances instead. And then during full scale war donated just 30 old tanks. And now Trump is talking with Putin behind Ukraine's back on how they should surrender.
Unfortunately USA is not a superpower anymore and their word means nothing.
Earlier quoted context omitted.
> I interpret this, I think reasonably, to not include encrypted information I disagree since attacks and leaks can happen/have happened which could compromise that data. Signal was already found to be vulnerable to CacheOut. Even ignoring that guessing or brute forcing a pin is all anyone would need to get a list of everyone a signal user has been in contact with. just having that data (and worse keeping it forever)…
Okay, so you not only take issue with PIN+SGX, you think that any encryption scheme (at least from Signal) isn't secure enough. Your point still comes down to "they are storing sensitive information in a form that is ostensibly encrypted but still subject to attack (in the opinion of XYZ reputable people...)". My point is only that the headline of your point was "they are lying about not storing sensitive information…
Signal (and basically any app) with a linked devices workflow has been risky for awhile now. I touched on this last year ( https://news.ycombinator.com/context?id=40303736 ) when Telegram was trash talking Signal -- and its implementation of linked devices has been problematic for a long time: https://eprint.iacr.org/2021/626.pdf . I'm only surprised it took this long for an in-the-wild attack to appear in open liter…
If I'm reading that right, the attack assumes the attacker has (among other things) a private key (IK) stored only on the user's device, and the user's password. Thus, engaging on this attack would seem to require hardware access to one of the victims' devices (or some other backdoor), in which case you've already lost. Correct me if I'm wrong, but that doesn't seem particularly dangerous to me? As always, security o…
Background services on devices has been a thing for a while too. Install an app (which you grant all permissions to when asked) and bam, a self-restarting daemon service tracking your location, search history, photos, contacts, notes, email, etc