Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

201–210 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#201

Earlier quoted context omitted.

Isn’t WhatsApp end-to-end encrypted?

Yes it is, they actually use the signal protocol,[0] but they collect metadata which Signal supposedly doesn't (you can't really know) [0] https://en.wikipedia.org/wiki/Signal_Protocol#:~:text=Severa...

Signal doesn't collect that data, but you have no reason to trust me on it.

Look at what data they can provide to governments when compelled by law: https://signal.org/bigbrother/

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#202

So a few days ago Elon Musk blocked all links to Signal from the X platform and now this... Could be a coincidence but the timing sure is sus.

Unrelated most likely, signal.me is a legitimate domain used by Signal. Doubt twitter is so on top of Threat Analysis when they fumbled their own redirects from twitter.com to x.com for a while.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#203

Earlier quoted context omitted.

Trump and his voters.

[dead]

He also failed to secure a majority of the votes cast, winning with a mere plurality. (Not that the raw number of votes cast actually matters all that much, given our idiotic presidential electoral system.)

So what?

Totally agreed that it's out of bounds to label all Trump voters as rednecks & white nationalists. But not sure where you're getting that: read upthread. No one said anything like that. Just "Russia-aligned state actors". Which is also pretty silly.

But in a way, it's worse than all that. If his supporters were actually all rednecks & white nationalists (or Russia-aligned state actors), at least we could say, "well, the country is actually full of shitty, uneducated, racist people, so I guess this actually is the will of the people". But right, that's not the case. Instead, Trump and the GOP have lied and manipulated to the point they've managed to dupe a much more diverse group of people into believing in Trump. Or, at the very least, into believing that the system needs to burn in order for it to be remade in a way that will serve these people's interests.

All this is a crock, of course, and there are already quite a few surprised and upset Trump voters who have experienced an interruption or loss of some government service that they depend on. So ok, let's expand it the list. Sure, there are rednecks & white nationalists. But there are also just regular ol' idiots who fell for Trump's nonsense. And actively awful people who are fine with a lot of others getting hurt, just to spite the current establishment.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#204

They provided some domains, but not all of them are taken. For example, signal-protect[.]host is available, kropyva[.]site is available, signal-confirm[.]site is registered in Ukraine. Some of them are registered in Russia. Never trust a country at war—any side. Party A blames B, Party B blames A, but both have their own agenda.

>signal-confirm[.]site is registered in Ukraine

The WHOIS is usually fake made up data so don't know why you are using that to claim it's registered in Ukraine. Russia is also known to use stolen credentials, SIM cards etc. from their neighbouring countries, including Ukraine, for things like this.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#205

"Russia-aligned threat actors" has a whole new meaning this last week.

[flagged]

>This comment isn't witty, and it doesn't contain any useful information or promote discussion either.

Complaining about the comment isn't witty, contain useful information, or promote discussion either.

I would recommend being the change you want to see in the world (or avoid political threads).

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#206

They provided some domains, but not all of them are taken. For example, signal-protect[.]host is available, kropyva[.]site is available, signal-confirm[.]site is registered in Ukraine. Some of them are registered in Russia. Never trust a country at war—any side. Party A blames B, Party B blames A, but both have their own agenda.

[flagged]

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#207

Russia fucking up the worlds stuff this decade will be the material for history books. The are actively breaking Europe and almost noone seems to care.

Second will be how the internet with social media like twitter/x destroyed our democracy.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#208

Earlier quoted context omitted.

[dead]

Nobody labeled Trump voters as "redneck, white nationalists" in this thread. The claim was that Trump and his voters are "Russia-aligned", which is obvious at least for Trump and his immediate admin appointees.

I don't have opinions on most of this stuff but I know of some distant relative of mine who voted for Trump not because he's some sort of fascist but just because he didn't understand why voting for Trump maybe wasn't the best idea. People like this probably exist all over the place.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#209
post #112

You can check for unexpected linked devices in the settings menu.

I wonder if Signal should expose linked devices directly in the UI at all times. Something like a small icon that indicates "You have 3 linked devices active" or similar.

I think the trouble is information overload is a bit of a thing in this case. It's information that is 99% of the time useless, except the one time it isn't. But also, to an informed user is much less of a threat - the threat is anyone you interact with getting compromised.

EDIT: Like an analytics based approach would probably be far more useful - popping up a confirmation for example if GeoIP shows a device is far removed from all the others, which for most people would be true unless they were traveling.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#210
post #9

It is not plainly stated in the article, but as far as I understand, the first step of one of the attacks is to take the smartphone off a dead soldier’s body.

The article says they phish people into linking adversarial devices to their Signal: > [...] threat actors have resorted to crafting malicious QR codes that, when scanned, will link a victim's account to an actor-controlled Signal instance. If successful, future messages will be delivered synchronously to both the victim and the threat actor in real-time, [...]

There's a new feature to sync old messages that seems like it could potentially make that attack vector ten times worse:

https://www.bleepingcomputer.com/news/security/signal-will-l...

Would a malicious URL be able to activate this feature as part of the request?

Post reply on HN