Earlier quoted context omitted.
> This makes that entire goal moot I agree. Perhaps it's why I find the discussions like nonce-lengths and randomness sources almost insane (in the sense of willfully missing the forrest from the trees). Intelligence agencies have managed to penetrate the most secretive and powerful organizations known to man. Why would one think Signal's supply chain is impervious? I'd assume the opposite.
I don't think they are insane, they are quite useful when designing security mechanisms, while at the same time being utter noise for the end-user benefiting from that system. > If you're building a chip to generate prime numbers I do surely hope you know how to select randomness or make constant time & branch free algorithms, just like an engineer designing elevators better know what should be the tensile strength o…
Multiple Russia-aligned threat actors actively targeting Signal Messenger
261–270 of 329 posts
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#262Earlier quoted context omitted.
It sounds like all that's needed is a device that had been linked in the past. Unlinking doesn't have the security requirements you'd think it would and there's a phishing attack to make scanning a QR code trigger a device link (which seems really really bad if the user doesn't even have to take much action)
Your phone (primary device) and the linked ones have to share the IK since that is the "root of trust" for you account: with that you generate new device keys, renew them and so on. Those keys are backed by Keystore on Android, and some similar system on Windows/Linux, i'd assume the same for MacOS/iOS (but I don't know the details) so it's not as simple as just having access to your laptop, they'd need at least root…
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#263If somehow, the victims phone provider can be compromised or coerced into cooperating, the government actor can intercept the text message Signal and others use for verification and set up the victims account on a new device.
It's very easily done if the victim is located in an authoritarian county like Russia or Iran, they can simply force the local phone provider to co-operate.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#264Earlier quoted context omitted.
Would probably lead to notification fatigue. Showing a big snackbar when a new device is added is probably enough, especially if the app can detect there was no "action" on your phone that triggered it. Key transparency, once rolled out, would help to ensure there is no lingering "bad" device around, but phishing will always be a problem.
> Showing a big snackbar when A big... what? Can you tell me what this new lingo is for someone who doesn't use the latest and shittiest marketing lingo?
Is that what you call the words you don't understand?
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#265Earlier quoted context omitted.
Just explain what end to end encryption means. People are starting to get it and don’t want companies able to read their messages.
Isn’t WhatsApp end-to-end encrypted?
It seems to be but there is more to it than that.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#266Alphabet is working in tandem with the Ukrainian SBU? Interesting choice, just as the US President has called Zelensky a dictator (and for good reason, Poroshenko, the previous Ukrainian president, has basically said the same thing a few days ago). I wonder how long the Alphabet higher-ups will allow this thing to unfold, or maybe they're not so good at reading the geopolitical tea leaves.
You can't be serious that you consider that to be a good enough reasoning.
Zelensky's support / approval rating is well over 50% (according to polls). Zelensky defeated Poroshenko, getting 73% of the vote in the 2019 election.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#267Earlier quoted context omitted.
I believe you are making a mistake by thinking that since a malicious actor's domain is registered in Ukraine, it automatically must be doing something in the interests of Ukraine, or at least be known to its officials. Lots of Russian state actors have no problems working from within Ukraine, alas. Add to this purely chaotic criminal actors who will go with the highest bidder, territories temporarily controlled by R…
Fair point. Just because a domain is registered in Ukraine doesn't mean it's acting in Ukraine's interests. But that works both ways. If Russian actors can operate from Ukraine, then Ukrainian actors (or others) can also operate from Russia, or at least make it look that way. Cyber attacks originating from Ukraine and targeting Russia aren't uncommon either, which only adds to the complexity of attribution. The issue…
Stop the tiresome FUD please. This war is surprisingly straightforward by the standards of the last century, it's literally out of some decades-old textbook. Let's not drag this discussion here again. If you have specific issues with Google's attribution here, please state them, HN is pretty aware that attribution can be shaky. My only gripe with the article is the clickbait title: nobody says that someone is "targeting e-mail" about e-mail phishing.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#268There are many voices which try to tell you that signal is compromised. Notice that all of those voices have less open-source-ness than Signal in virtually all cases. Signal is doing its best to be a web scale company and also defend human rights. Individual dignity matters. This is not a simple conversation.
> web scale I didn't realize anyone still used that term with a straight face. "MongoDB is web scale, you turn it on and it scales right up."
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#269It is not plainly stated in the article, but as far as I understand, the first step of one of the attacks is to take the smartphone off a dead soldier’s body.
Is this serious? It raises questions about smartphones being standard equipment for soldiers, but they do give every soldier an effective, powerful computing and communication platform (that they know without additional training). The question is how to secure them, including against the risk described in the parent. That seems like a high risk to me I would expect someone is working on how to secure them enough that…
There's no particular need IMO to secure smartphones on the battlefield in anyway beyond standard counter-measures - i.e. encrypt the storage, use a passcode unlock.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#270There are many voices which try to tell you that signal is compromised. Notice that all of those voices have less open-source-ness than Signal in virtually all cases. Signal is doing its best to be a web scale company and also defend human rights. Individual dignity matters. This is not a simple conversation.