Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

241–250 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#241
post #240

Russia fucking up the worlds stuff this decade will be the material for history books. The are actively breaking Europe and almost noone seems to care.

If Europe is what it claims to be: an enlightened democracy with progressive intelligent populace it can not be broken by demented crap messages from twitter. If however it is fucked up and on a brink of collapse then sure. Little nudge can steer it into "right" direction. but then who is guilty in a first place.

You should read up on how russian money buys influenve, eg. In Moldavia.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#242

Earlier quoted context omitted.

Would probably lead to notification fatigue. Showing a big snackbar when a new device is added is probably enough, especially if the app can detect there was no "action" on your phone that triggered it. Key transparency, once rolled out, would help to ensure there is no lingering "bad" device around, but phishing will always be a problem.

> Showing a big snackbar when A big... what? Can you tell me what this new lingo is for someone who doesn't use the latest and shittiest marketing lingo?

Snackbar isn't a particularly new term, it goes back, IIRC, to the first version of Material Design and is similar to a toast but different in that snackbars may support interaction whereas toasts are non-interactive.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#243

Earlier quoted context omitted.

If I'm reading that right, the attack assumes the attacker has (among other things) a private key (IK) stored only on the user's device, and the user's password. Thus, engaging on this attack would seem to require hardware access to one of the victims' devices (or some other backdoor), in which case you've already lost. Correct me if I'm wrong, but that doesn't seem particularly dangerous to me? As always, security o…

“Just install this chrome browser extension” is all it takes now. Hell, you can even access cookies and previously visited sites from within the browser. All it takes is some funky ad, or chrome extension, or some llama-powered toolbar to gain access to be able to do exactly that. Background services on devices has been a thing for a while too. Install an app (which you grant all permissions to when asked) and bam, a…

How is that related in any way to Signal?

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#244

They provided some domains, but not all of them are taken. For example, signal-protect[.]host is available, kropyva[.]site is available, signal-confirm[.]site is registered in Ukraine. Some of them are registered in Russia. Never trust a country at war—any side. Party A blames B, Party B blames A, but both have their own agenda.

Oceania had always been at war with Eastasia.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#245
post #33

So a few days ago Elon Musk blocked all links to Signal from the X platform and now this... Could be a coincidence but the timing sure is sus.

Not really, the domain block was reportedly due to increased spam activity from that domain and performed automatically, so it would follow that a write up would come a few days later. That is if they are related, which is not a given.

Musk calls everything he doesn't like "spam", so of course it was.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#246

Earlier quoted context omitted.

“Just install this chrome browser extension” is all it takes now. Hell, you can even access cookies and previously visited sites from within the browser. All it takes is some funky ad, or chrome extension, or some llama-powered toolbar to gain access to be able to do exactly that. Background services on devices has been a thing for a while too. Install an app (which you grant all permissions to when asked) and bam, a…

How is that related in any way to Signal?

My point is that anything you install on your device is a vector. Can install MITM attacks. Can read your data, etc. Sidecar attacks.

This was classic phishing though

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#247
post #33

Earlier quoted context omitted.

Not really, the domain block was reportedly due to increased spam activity from that domain and performed automatically, so it would follow that a write up would come a few days later. That is if they are related, which is not a given.

Musk calls everything he doesn't like "spam", so of course it was.

It’s still a social media platform, not every action taken is some nebulous part of Musks agenda. Odds are there was an influx of posts that qualify as spam from the signal.me domain that were marked by an automatic system as spam, because they were. Suggesting otherwise is baseless speculation.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#248
post #40

Signal (and basically any app) with a linked devices workflow has been risky for awhile now. I touched on this last year ( https://news.ycombinator.com/context?id=40303736 ) when Telegram was trash talking Signal -- and its implementation of linked devices has been problematic for a long time: https://eprint.iacr.org/2021/626.pdf . I'm only surprised it took this long for an in-the-wild attack to appear in open liter…

If one doesn't use the linked device feature, does that impact this threat surface?

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#249
post #44

Earlier quoted context omitted.

Is this serious? It raises questions about smartphones being standard equipment for soldiers, but they do give every soldier an effective, powerful computing and communication platform (that they know without additional training). The question is how to secure them, including against the risk described in the parent. That seems like a high risk to me I would expect someone is working on how to secure them enough that…

Phones aren’t secure but are more secure than the standard radios most have access to. Encrypted milspec comms aren’t the standard in a massive war. It’s weird but discord, signal and some mapping apps on smartphones are how this war is being fought.

At the start of the invasion in Ukraine it was possible for a while to listen to unencrypted radio comms from Russian convoys, hosted online live.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#250

I'd love to have more of my socializing happening on Signal. Anyone got a good way to convince the non-paranoid to use it?

I've still got Signal installed, but never use it, I only ever ended up chatting on it with a few ex-colleagues, who were fellow devs / nerds.

I have so many WhatsApp group chats (here in Australia) that are critical for me these days, and that I don't control, and that have way too many people, and way too diverse a range of people, for me to have any hope whatsoever of migrating them all to Signal. School parents group chats (one for each class that my kids are in). Strata (aka Home Owners Association) committee group chat. Scouts group chat. Various friends groups chats. Boycotting WhatsApp is not an option for me, it would literally make me unable to function in a number of my day-to-day responsibilities.

Post reply on HN