Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

161–170 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#161

Earlier quoted context omitted.

It's a joke, because virtue signaling (or whatever name you want to give it) is bad, but Signal the messenger app is good so it's a play on words.

It’s not bad. It just IS. the only people that think it is bad are people who have a different opinion and feel attacked for whatever reason. I find it telling when people accuse others of virtue signaling because it is almost always someone who is jealous or insecure attacking said signaler.

"Virtue signaling" in theory means "talking the talk without walking the walk", but it's generally thrown out by people who make no effort to assess whether the person criticized is walking the walk or even in contradiction of such evidence.

Driving an economically efficient car -- choosing any sort of car -- has enormous consequences on one's life, for example. Choosing to by a particular car isn't a decision made lightly. But Prius drivers back in the day were accused of virtue signaling, as though the Prius were equivalent to a temporary tattoo.

In fact, speaking of temporary tattoos, simply having a bumper sticker advocating for animal rights, say, belief in anthropogenic climate change, or peace in the Middle East will expose one to regular displays of hostility and aggression, so it isn't a cheap signal.

In other words, in my experience your observation is spot on.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#162

Earlier quoted context omitted.

Trump blames Ukraine for starting the war, Putin is happy

I heard he also blames Poland for being invaded and starting WWII. As to that Archduke Ferdinand, diving in front of that bullet. Was asking for it.

> I heard he also blames Poland for being invaded and starting WWII.

This one is fake, even if plausible. https://www.der-postillon.com/2025/02/ueberfall-auf-polen.ht... - Der Postillon is equivalent to US's The Onion.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#163
post #40

Signal (and basically any app) with a linked devices workflow has been risky for awhile now. I touched on this last year ( https://news.ycombinator.com/context?id=40303736 ) when Telegram was trash talking Signal -- and its implementation of linked devices has been problematic for a long time: https://eprint.iacr.org/2021/626.pdf . I'm only surprised it took this long for an in-the-wild attack to appear in open liter…

The attack in that paper assumes you have compromised the user's long term private identity key (IK) which is used to derive all the other keys in the signal protocol.

Outside of lab settings, the only way to do that is: - (1) you get root access to the user's device - (2) you compromise a recent chat backup

The campaign Google found is akin to phishing, so not as problematic on a technical level. How do you warn someone they might be doing something dangerous in an entire can of worms in Usable Security... but it's gonna become even more relevant for Signal once adding a new linked device will also copy your message history (and last 45 days of attachments).

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#164

Earlier quoted context omitted.

"I interpret this, I think reasonably, to not include encrypted information" Why? Encrypted information is still sensitive information.

Maybe via metadata? The size of the information, etc. Do you mean that they should have a caveat about that? Or if you want to be literal, you have to say that they're storing sensitive information even if it's encrypted. But by connotation that phrase implies that someone other than the user could conceivably have access to it. So for all any user could care, they just as well are not storing it. Do you mean that th…

Yes, I think they should rephrase it so that it's literally correct. Personally, I have a very high trust in the safety of Signal's encryption and security practices. But privacy policies aren't for the Signals of the world, they're for the ad networks and sketchy providers. For example, many ad networks collect "Safely Encrypted" email addresses—but still are able to use that information to connect your Google search result ad clicks with your buying decisions on Walmart.com. Whether something is "safely" encrypted is a complicated, contextual decision based on your threat model, the design of the secure system in question, key custody, and lots of other complicated factors that should each be disclosed and explained, so that third parties can assess a service's data security practices. Signal is a great example of a service that does an excellent job explaining and disclosing this information, but the fact that their privacy policy contradicts their public docs lessens the value of privacy policies.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#165

Earlier quoted context omitted.

I heard he also blames Poland for being invaded and starting WWII. As to that Archduke Ferdinand, diving in front of that bullet. Was asking for it.

> I heard he also blames Poland for being invaded and starting WWII. This one is fake, even if plausible. https://www.der-postillon.com/2025/02/ueberfall-auf-polen.ht... - Der Postillon is equivalent to US's The Onion.

The person you replied to was joking, but it makes it even funnier that you didn't think they were.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#166
Is this suggesting that a single QR scan can on its own perform the device linking? If so, it seems like that's kind of the hole here, right? Like you shouldn't be able to scan a code that on its own links the device; you should have to manually confirm with like "Yes I want to link to this device". And then if you thought you were scanning a group invite code you'd realize you weren't. (Yeah, you'd still have to realize that, but I think it's a meaningful step up over just "you scanned a code to join a group and instead it silently linked a different device".)

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#167

Earlier quoted context omitted.

I'm not going to run interference against all the comments you're writing on this thread, because I don't think Signal needs the help and it would make the thread ultra-tedious. But during the brief window where people were taking Wire seriously as a Signal alternative, I'd occasionally write a comment or tweet like: Were you aware that Wire keeps a high-fidelity plaintext database of exactly who talks to who on thei…

Even if you thought that SGX was bulletproof and pins were impossible to brute force, instead of just being 'better than what most other apps use' what possible justification is there for outright lying to users by claiming that their app doesn't collect any sensitive data when it does? Signal is advertised and recommended to some extremely vulnerable people whose lives/freedom depend on their security. Signal owes u…

I think we know you're happy to say it plainly, since you've been saying it plainly for over 4 years.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#168
post #142

Earlier quoted context omitted.

"I interpret this, I think reasonably, to not include encrypted information" Why? Encrypted information is still sensitive information.

A ciphertext is not sensitive information. If your ciphertext can't be exposed to an adversary, your cryptography is fundamentally broken.

You can't make that statement blindly without knowledge of the entire cryptosystem and threat model. For example, to me, an encrypted version of my email address, as used by many ad networks to do retargeting, is still sensitive information if it lets Walmart serve me ads based on my Google search history.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#169

Earlier quoted context omitted.

> I heard he also blames Poland for being invaded and starting WWII. This one is fake, even if plausible. https://www.der-postillon.com/2025/02/ueberfall-auf-polen.ht... - Der Postillon is equivalent to US's The Onion.

The person you replied to was joking, but it makes it even funnier that you didn't think they were.

As someone living in Poland and tracking the developments in the US, when I used the word "plausible", I meant it.
Post reply on HN