Live data from Hacker News

Signal on Android: Images sent to wrong contacts

github.com

211–220 of 403 posts

Re: Signal on Android: Images sent to wrong contacts

#211
post #81

Fixed: https://github.com/signalapp/Signal-Android/issues/10247#iss...

A rather vague explanation. Sounds a bit evasive. Where is the commit that fixes it?

He replied to the Issue here: https://github.com/signalapp/Signal-Android/issues/10247#iss...

Re: Signal on Android: Images sent to wrong contacts

#212
post #200
post #26

Earlier quoted context omitted.

Delta chat starts from reading email and theb works backwards: https://delta.chat/en/

Cool, my contacts can keep using their gmail account and leak all communication metadata to Google without me having any say on that if I want to talk to them. Where can I sign up?

Maybe gently encourage your contacts to use another provider?

Re: Signal on Android: Images sent to wrong contacts

#213
post #82

Hi there, Signal-Android developer here. I updated the issue to reflect this, but this bug has been fixed. I was tracking it on a separate issue, and had forgotten to close this one. We do, in fact, take issues like this very seriously. This bug was extraordinarily rare, and because we have no metrics/remote log collection, there was an initial period where we had to spend time adding logging and collecting user-subm…

Can you provide a link to the commit that fixes it? Shouldn't there have been an announcement to inform users what has been leaked and under which circumstances? How can user A send an image to user B that neither of them took? Isn't everything end-2-end encrypted? Then how can unencrypted data from user C end up on the device of user B?

If it’s a client bug that just switches out recipients, then the messages will just get encrypted for the wrong recipient.

Re: Signal on Android: Images sent to wrong contacts

#214

Hi there, Signal-Android developer here. I updated the issue to reflect this, but this bug has been fixed. I was tracking it on a separate issue, and had forgotten to close this one. We do, in fact, take issues like this very seriously. This bug was extraordinarily rare, and because we have no metrics/remote log collection, there was an initial period where we had to spend time adding logging and collecting user-subm…

You should have shut down the servers while this was happening - especially because you couldn't track it down. Shame on you for not caring about your users or their privacy when they were specifically using Signal for privacy. Edit: Anyone downvoting this also simply doesn't understand how serious this privacy leak really is. Shame on you too.

> Edit: Anyone downvoting this also simply doesn't understand how serious this privacy leak really is. Shame on you too.

Wouldn't showing a warning suggesting not to post sensitive images while the bug is being investigated be better than straight up shutting down the service while solving the privacy issue?

Wouldn't closing the service have made people leave for other (probably worse) services, the one relying on privacy, privacy-minded people and "regular users" alike, and have worse consequences for privacy than this bug?

(not currently a Signal user, and I did not downvote your comment)

Re: Signal on Android: Images sent to wrong contacts

#215
post #157

Earlier quoted context omitted.

Sure, but there's a small theoretical difference with democracy. You have to live under some system of government. You don't have to use a secure messenger. You can choose to have sensitive conversations in person or not have them at all. I agree that in practice, a lot of people are going to use their phones for relatively sensitive conversations, and in practice, Signal remains the best choice for doing so. But the…

> You can choose to have sensitive conversations in person or not have them at all. I don't think this is fair. Most of the solution to this is "not having them at all." That's not a good solution and still doesn't solve your problem since you can still be listened to. > There's iMessage/FaceTime, for instance. Which also has gotten in trouble recently with Pegasus as there was a 0-click exploit in iMessage. Honestly…

I think what I'm trying to get at is that incorrectly believing you have access to a secure messenger can be worse than acting as if you don't, if those are your options. The whistleblower might choose not to make contact, but if the alternative is making contact and immediately going to prison (because someone else on your contact list saw a classified screenshot from you and told the authorities), maybe that's better. The activists might choose not to protest, but if the alternative is being caught before they even start their protest (because your group was forwarding a little advertisement image or annotated map around among trusted people, and someone untrusted got it), maybe that's better.

Take Reality Winner, for instance (the mechanics of that case were entirely unrelated to secure messengers, but it makes a relevant example overall). The effect on the world of her whistleblowing seems to have been minimal, and the cost to her was significant. Was it worthwhile? If she had been told the risks of the government identifying her were higher and decided not to leak anything, wouldn't that have been a better outcome?

I'm not saying there's perfect security. Vulnerable users absolutely need to be making risk assessments and deciding what they're comfortable with, and we should be clear nothing is risk-free. I'm just saying my sense of Signal's risk, in absolute terms, is higher than it was before I learned about this, and that matters to vulnerable users, not just the fact that it probably remains the lowest-risk messenger of the various options.

I agree with you overall, and the Pegasus exploit does reflect badly on Apple (and probably should reflect more badly on them than seems to be happening).

Re: Signal on Android: Images sent to wrong contacts

#216
post #210
post #183

Earlier quoted context omitted.

"For the sake of argument" does not mean "I invite you to debate this", it means the exact opposite: "let's assume this is correct/we agree/etc. for a while and debate what comes after". So in this case you are doing the exact opposite of what the phrase "for the sake of argument" is requesting. https://idioms.thefreedictionary.com/for+the+sake+of+argumen... > I know you want to go to Stanford, but just for the sake…

It sounds to me like NullPrefix accepted the hypothetical bug, for the sake of the argument, and then addressed the rarity assumptions made about that bug. "For the sake of argument" doesn't mean "No debating" it means "Let's assume some thing x is taken as a given and go from there."

The whole point was that "given this assumed rare bug, one can know it's pretty rare". Whether the example is actually rare enough is completely beside the point. If it's not rare enough for you, replace it. The argument comes next: given a rare bug, a developer can make an assumption of how rare it is. Debating the example of rareness is splitting hairs.

Re: Signal on Android: Images sent to wrong contacts

#217
Can we get a better understanding of the root cause and blast radius?

You say, "if someone had conversation trimming on, it could create a rare situation where a database ID was re-used in a way that could result in this behavior."

Is this someone user A or user B? Where is this database and what is it storing? Are these images previously sent or received from either A or B, or are they possibly from some thread between users C and D? How does this agree with end-to-end encryption?

How can you expect people to use your product with a bug this severe and no analysis of the impact or a statement as to who might have been affected?

Re: Signal on Android: Images sent to wrong contacts

#218

Earlier quoted context omitted.

Selective quoting? "As soon as we were able to pick up a scent, it was all we worked on, and we were able to get a fix out very quickly."

Oh sorry, I interpreted it differently. Tho it still doesn't change anything, they prolonged investigating this issue for months and only put mayor work behind it when they "pick[ed] up a scent on it". Although they knew about it from day one (one Signal staff replied on the same day the issue was posted).

Yeah but he explained, that they could not track down the bug, without having the luxory of default user tracking and metrics. So what can you do, when you have a non reproducible bug, but limited ressources(and other problems around)? You wait for the bug to show up again and then have more data to work with.

Re: Signal on Android: Images sent to wrong contacts

#219

Earlier quoted context omitted.

> we were able to get a fix out very quickly. Is 6 months really what Signal considers quick for a bug that leaks private data?

Selective quoting? "As soon as we were able to pick up a scent, it was all we worked on, and we were able to get a fix out very quickly."

It's not at all selective. This should have been "all they worked on" from the moment they got several confirmations, not from the moment people beat them over the head with data. If they couldn't fix it they should have pulled the app.

This is a company that aggressively markets itself to people needing privacy, and mistakes can ruin lives. And before you say it, they have tens of millions of dollars in funding.

Re: Signal on Android: Images sent to wrong contacts

#220

Earlier quoted context omitted.

The chat client misinterprets something and attaches a file to the message. The encryption works fine, the business logic of the app failed. E2EE won't protect you from a client accidentally encrypting and submitting files in the wrong chats.

But what exactly went wrong with signal here? Could someone remotely instruct my signal client to share media? Previously sent or arbitrary files?

The app accidentally attached seemingly random media to messages. The other end has no control over what images they receive when. There was no hack or remote control at play, just a bug.
Post reply on HN