Russia fucking up the worlds stuff this decade will be the material for history books. The are actively breaking Europe and almost noone seems to care.
If Europe is what it claims to be: an enlightened democracy with progressive intelligent populace it can not be broken by demented crap messages from twitter. If however it is fucked up and on a brink of collapse then sure. Little nudge can steer it into "right" direction. but then who is guilty in a first place.
Multiple Russia-aligned threat actors actively targeting Signal Messenger
241–250 of 329 posts
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#242Earlier quoted context omitted.
Would probably lead to notification fatigue. Showing a big snackbar when a new device is added is probably enough, especially if the app can detect there was no "action" on your phone that triggered it. Key transparency, once rolled out, would help to ensure there is no lingering "bad" device around, but phishing will always be a problem.
> Showing a big snackbar when A big... what? Can you tell me what this new lingo is for someone who doesn't use the latest and shittiest marketing lingo?
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#243Earlier quoted context omitted.
If I'm reading that right, the attack assumes the attacker has (among other things) a private key (IK) stored only on the user's device, and the user's password. Thus, engaging on this attack would seem to require hardware access to one of the victims' devices (or some other backdoor), in which case you've already lost. Correct me if I'm wrong, but that doesn't seem particularly dangerous to me? As always, security o…
“Just install this chrome browser extension” is all it takes now. Hell, you can even access cookies and previously visited sites from within the browser. All it takes is some funky ad, or chrome extension, or some llama-powered toolbar to gain access to be able to do exactly that. Background services on devices has been a thing for a while too. Install an app (which you grant all permissions to when asked) and bam, a…
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#244They provided some domains, but not all of them are taken. For example, signal-protect[.]host is available, kropyva[.]site is available, signal-confirm[.]site is registered in Ukraine. Some of them are registered in Russia. Never trust a country at war—any side. Party A blames B, Party B blames A, but both have their own agenda.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#245So a few days ago Elon Musk blocked all links to Signal from the X platform and now this... Could be a coincidence but the timing sure is sus.
Not really, the domain block was reportedly due to increased spam activity from that domain and performed automatically, so it would follow that a write up would come a few days later. That is if they are related, which is not a given.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#246Earlier quoted context omitted.
“Just install this chrome browser extension” is all it takes now. Hell, you can even access cookies and previously visited sites from within the browser. All it takes is some funky ad, or chrome extension, or some llama-powered toolbar to gain access to be able to do exactly that. Background services on devices has been a thing for a while too. Install an app (which you grant all permissions to when asked) and bam, a…
How is that related in any way to Signal?
This was classic phishing though
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#247Earlier quoted context omitted.
Not really, the domain block was reportedly due to increased spam activity from that domain and performed automatically, so it would follow that a write up would come a few days later. That is if they are related, which is not a given.
Musk calls everything he doesn't like "spam", so of course it was.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#248Signal (and basically any app) with a linked devices workflow has been risky for awhile now. I touched on this last year ( https://news.ycombinator.com/context?id=40303736 ) when Telegram was trash talking Signal -- and its implementation of linked devices has been problematic for a long time: https://eprint.iacr.org/2021/626.pdf . I'm only surprised it took this long for an in-the-wild attack to appear in open liter…
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#249Earlier quoted context omitted.
Is this serious? It raises questions about smartphones being standard equipment for soldiers, but they do give every soldier an effective, powerful computing and communication platform (that they know without additional training). The question is how to secure them, including against the risk described in the parent. That seems like a high risk to me I would expect someone is working on how to secure them enough that…
Phones aren’t secure but are more secure than the standard radios most have access to. Encrypted milspec comms aren’t the standard in a massive war. It’s weird but discord, signal and some mapping apps on smartphones are how this war is being fought.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#250I'd love to have more of my socializing happening on Signal. Anyone got a good way to convince the non-paranoid to use it?
I have so many WhatsApp group chats (here in Australia) that are critical for me these days, and that I don't control, and that have way too many people, and way too diverse a range of people, for me to have any hope whatsoever of migrating them all to Signal. School parents group chats (one for each class that my kids are in). Strata (aka Home Owners Association) committee group chat. Scouts group chat. Various friends groups chats. Boycotting WhatsApp is not an option for me, it would literally make me unable to function in a number of my day-to-day responsibilities.