Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

291–300 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#291

One thing I'm realizing more and more (I've been building an encrypted AI chat service which is powered by encrypted CRDTs) is that "E2E encryption" really requires the client to be built and verified by the end user. I mean end of the day you can put a one-line fetch/analytics-tracker/etc on the rendering side and everything your protocol claimed to do becomes useless. That even goes further to the OS that the rende…

> "E2E encryption" really requires the client to be built and verified by the end user

But the OS might be compromised with a screen recorder or a keylogger. You'd need the full client, OS and hardware to be built by the end user. But then the client that they're sending to might be compromised... Or even that person might be compromised.

At the end of the day you have to put your trust somewhere, otherwise you can never communicate.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#292

Earlier quoted context omitted.

Bulgarian gypsies (what?) didn’t start a war against Germany, Nikolay.

It's the principle. Germans started the most destructive war in human history, but they are not vilified as much as the Russians!

[dead]

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#294

Phone verification is a common method used here. If somehow, the victims phone provider can be compromised or coerced into cooperating, the government actor can intercept the text message Signal and others use for verification and set up the victims account on a new device. It's very easily done if the victim is located in an authoritarian county like Russia or Iran, they can simply force the local phone provider to…

> government actor can intercept the text message Signal and others use for verification and set up the victims account on a new device

Yes, but if they only control the phone number, you they will register a new account (different cryptographic keys) for you, which is why everyone previously chatting with you will get that "Your Safety Number with Bob changed" message.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#295
post #59

Earlier quoted context omitted.

It isn't a viewpoint. It's a fact. I'm using signal for almost a decade now and only managed to get a dozen or so people to use it in any capacity. Most keep using whatsapp as their primary method of communication anyway.

Meanwhile, I have been using Signal since the TextSecure days, too, and practically all my contacts are using it these days.

Good for you, tell us how you did it!

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#296

Earlier quoted context omitted.

Bulgarian gypsies (what?) didn’t start a war against Germany, Nikolay.

It's the principle. Germans started the most destructive war in human history, but they are not vilified as much as the Russians!

If Russia retreats from the occupied territories, heaps guilt on itself for the next 80 years and does not start new wars, it won't be vilified 80 years from now.

Also, of course, Germany and WW2 are mentioned constantly in Russia itself even today, while most new wars in the past 40 years have been started by the US or Russia.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#297

Earlier quoted context omitted.

I agree with you that the cart seems to be moving ahead of the horse, in that there is an increasing fixation on the theoretical status of the encryption scheme rather than the practical risk of various outcomes. An important facet of this is that systems that attempt to be too secure will prevent users from reading their own messages and hence will induce those users to use "less secure" systems. (This has been a pr…

At a casual glance, any E2EE system can be reduced to your ironclad legally guaranteed (ILG) system by having the platform keep a copy of the key(s), for instance. So it doesn't have to be a one-or-the-other choice.

How does giving the platform the keys guarantee legal consequences for them if they use the keys to read your messages?

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#298
> Android supports alphanumeric passwords, which offer significantly more security than numeric-only PINs or patterns.

Ironic, coming from Google. As Android is THE only OS where usage of alphanumeric passwords is nearly impossible, as Android limits the length of a password to arbitrary 16 characters, preventing usage of passphrases.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#299
post #269

Earlier quoted context omitted.

A radio on a soldier is already a dangerous communications device - with a radio you can call in artillery strikes, for example. There's no particular need IMO to secure smartphones on the battlefield in anyway beyond standard counter-measures - i.e. encrypt the storage, use a passcode unlock.

The Russian military would beg to differ, see the sibling's comment: https://news.ycombinator.com/item?id=43106162

That's referring to people literally posting selfies online (with the result of giving away their location by either metadata or geo-guessing).

Which is a process and procedure issue, more then a security issue on the phones themselves (except in so far as it's really obvious there's a solid need for an OS for a battlefield device which strips all that stuff out by default).

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#300
post #105

Earlier quoted context omitted.

Russians aren't allowed to bring phones on the frontlines apparently but Ukranians often do still as they have the combat management app which is critical to operations. I've always wondered if this is why there's far more published footage of Ukranian combat video than Russian. Beyond the donation incentive they attached to videos when publishing them on Youtube/Telegram.

> I've always wondered if this is why there's far more published footage of Ukranian combat video than Russian. I'm sure Russia's meat wave tactics have more of a role. If you're sending your troops in suicide missions, including guys without weapons and even in crutches, you're not exactly too keen in having them carrying mobile phones to document the experience or even, heavens forbid, survive by surrendering.

This meatwave meme needs to die. Again ,if Ukrainians are being beaten by guy in crutches,it says so much about this NATO armed and trained force
Post reply on HN