Live data from Hacker News

Valid Signal privacy issues shrugged off while patches quietly rolled out

403forbiddenblog.blogspot.com

21–30 of 53 posts

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#21
post #9
post #5

I was expecting to hear about someone who got a new phone, set up Signal using the phone number, and then communicated with contacts without any more authentication. This doesn't appear to be anything of the kind. Signal has implemented a migration system so that people can move to a new phone without changing the safety number. Then a bunch of references to the promises Signal makes about re-verifying if the safety…

I imagine there is a human factors tradeoff here. If signal notified on each migration, users with even medium sized contact lists would likely be getting constant notifications - making the alert useless. See medical device or aviaton alerts experiences.

You basically lose trust after 2 false alerts.

Third false alarm in college - no one left dorm.

Third false alarm working overseas (required we wake up etc) everyone turned off buzzers.

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#23

TL;DR of article: Signal transfers key material upon migrating to a new device if you use the "transfer messages" workflow. As a result, safety numbers do not change. I don't see how this is a problem at all. This was actually a feature that many Signal users wanted to use - they didn't want to re-verify safety numbers every time that they had to reinstall Signal or switch to a new phone. > We don't want anyone to ge…

You assume here that you are aware of the fact that your device is in the hands of someone else.

I could ask you for your device under the pretense of making a phone call and then secretly transfer your account to my device. I could then secretly read your chats from my device and no one would be aware of it - until you check the amount of active sessions in settings.

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#24
post #9

Earlier quoted context omitted.

I imagine there is a human factors tradeoff here. If signal notified on each migration, users with even medium sized contact lists would likely be getting constant notifications - making the alert useless. See medical device or aviaton alerts experiences.

The problem is that there's no one size fits all solution. Security is all about making tradeoffs based on your threat models. I think this is probably a sensible default for many people engaging in casual conversations. However, this notification should probably be configurable. That way you can be notified when communicating with high risk individuals.

What threat model would it protect against?

The thing this proposed change would protect against is, if an attacker gets access to a participant's unlocked phone, and then transfers their Signal account, it will notify the other participants.

But an attacker can just as easily retain access to the original phone and send and receive messages with it - either physically, or by installing malware (a RAT or something) and remotely accessing the phone.

And when you move devices, because of the way the Signal ratchet works (I think), the original device doesn't get access to send or receive messages. So a device move is detectable if the original phone is returned.

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#25

I fail to understand why you would want your security numbers to refresh if there's no known risk of your private key having been leaked or stolen. Every time your keys change and you don't manually verify the new ones you risk a mitm attack. Signal just opts to trade off that risk in favor of convenience and more people using end to end encryption for every day communication. I guess OP is saying the fact that they…

The flow requires both devices to be in the possession of the account holder for the migration to start, mitigating any risks of foul play. I just tried migrating on my (Android) phones. If an attacker can get you put in your passcode, they don't need to mess with migrating between two phones.

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#26

TL;DR of article: Signal transfers key material upon migrating to a new device if you use the "transfer messages" workflow. As a result, safety numbers do not change. I don't see how this is a problem at all. This was actually a feature that many Signal users wanted to use - they didn't want to re-verify safety numbers every time that they had to reinstall Signal or switch to a new phone. > We don't want anyone to ge…

You assume here that you are aware of the fact that your device is in the hands of someone else. I could ask you for your device under the pretense of making a phone call and then secretly transfer your account to my device. I could then secretly read your chats from my device and no one would be aware of it - until you check the amount of active sessions in settings.

All security ultimately reduces to physical security.

If you can’t secure your physical phone, all digital security is moot.

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#27

Earlier quoted context omitted.

You assume here that you are aware of the fact that your device is in the hands of someone else. I could ask you for your device under the pretense of making a phone call and then secretly transfer your account to my device. I could then secretly read your chats from my device and no one would be aware of it - until you check the amount of active sessions in settings.

All security ultimately reduces to physical security. If you can’t secure your physical phone, all digital security is moot.

I would say "requires" rather than "reduces to". Just like all security requires vetting personnel. There are just a lot of checkboxes that need to be ticked as table stakes in the security game.

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#28

Does the safety number count as a sort of hash in this case? Or is it absolutely nothing like an MD-5?

My understanding was that it was a fingerprint of the public key, much like an SSH fingerprint.

It's specific to the two public keys involved in that conversation.

It was renamed from "fingerprint" because to those unfamiliar with cryptography, "fingerprints" are things used when a crime has been committed. There was a study out some years ago that illustrated that most of the crypto jargon in use is not helpful in conveying mental models to laypeople.

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#29
post #9
post #5

I was expecting to hear about someone who got a new phone, set up Signal using the phone number, and then communicated with contacts without any more authentication. This doesn't appear to be anything of the kind. Signal has implemented a migration system so that people can move to a new phone without changing the safety number. Then a bunch of references to the promises Signal makes about re-verifying if the safety…

I imagine there is a human factors tradeoff here. If signal notified on each migration, users with even medium sized contact lists would likely be getting constant notifications - making the alert useless. See medical device or aviaton alerts experiences.

What’s up always notified you inline in chats and it worked out just fine even for larger group chats
Post reply on HN