Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

321–329 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#321
post #171

Earlier quoted context omitted.

> you should have to manually confirm with like "Yes I want to link to this device". And then if you thought you were scanning a group invite code you'd realize you weren't. (Yeah, you'd still have to realize that, but I think it's a meaningful step up over just "you scanned a code to join a group and instead it silently linked a different device".) Remember that Signal is designed for non-technical users. Many/most…

> Do you have reason to think there is not confirmation? The reason is just that in the article it says: > threat actors have resorted to crafting malicious QR codes that, when scanned, will link a victim's account to an actor-controlled Signal instance That phrasing suggests to me that the scanning of the QR code, on its own, performs the linking. That may not be the case, but if so I'd say the wording is misleading…

In fairness, I think it's misleading to you due to the details you are interested in. They don't say otherwise and they can't lay out every detail that anyone might be interested in; it's not an RFC.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#322
post #269
post #44

Earlier quoted context omitted.

Is this serious? It raises questions about smartphones being standard equipment for soldiers, but they do give every soldier an effective, powerful computing and communication platform (that they know without additional training). The question is how to secure them, including against the risk described in the parent. That seems like a high risk to me I would expect someone is working on how to secure them enough that…

A radio on a soldier is already a dangerous communications device - with a radio you can call in artillery strikes, for example. There's no particular need IMO to secure smartphones on the battlefield in anyway beyond standard counter-measures - i.e. encrypt the storage, use a passcode unlock.

Smartphones store data; radios (depending on the radio) do not. The Russian military likely has tools for bypassing typical security.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#323
post #296

Earlier quoted context omitted.

It's the principle. Germans started the most destructive war in human history, but they are not vilified as much as the Russians!

If Russia retreats from the occupied territories, heaps guilt on itself for the next 80 years and does not start new wars, it won't be vilified 80 years from now. Also, of course, Germany and WW2 are mentioned constantly in Russia itself even today, while most new wars in the past 40 years have been started by the US or Russia.

What Germany did is many orders of magnitude worse than what Russia does in Ukraine. If you think both are similar, you have no heart, and possibly no brain either!

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#324

> In each of the fake group invites, JavaScript code that typically redirects the user to join a Signal group has been replaced by a malicious block containing the Uniform Resource Identifier (URI) used by Signal to link a new device to Signal (i.e., "sgnl://linkdevice?uuid="), tricking victims into linking their Signal accounts to a device controlled by UNC5792. Missing from their recommendations: Install No Script:…

No Script is a browser extension. Signal is an Android/Ios/Electron app so no

In each of the fake group invites, JavaScript code that typically redirects the user to join a Signal group has been replaced by a malicious block containing the Uniform Resource Identifier (URI) used by Signal to link a new device to Signal (i.e., "sgnl://linkdevice?uuid="), tricking victims into linking their Signal accounts to a device controlled by UNC5792.

Source: https://cloud.google.com/blog/topics/threat-intelligence/rus...

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#325
Am I reading this right? You can initiate device linking in Signal by clicking on an external URL? This is so stupid, I don't even have words for this. In a security-focused app you should not be able to link anything, without manually going into the devices/link menu and clicking "link new device".

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#326

Earlier quoted context omitted.

> Zelensky defeated Poroshenko And yet he still felt the need to start politically repressing Poroshenko with sanctions and branding him a traitor, that's the mark of having a dictator in command of things.

Maybe because Poroshenko is an oligarch and a piece of shit?

Still a former elected president, isn't he?

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#327
post #178

Earlier quoted context omitted.

For me it's the other way around: I tolerate SMS but I draw the line at Whatsapp.

Sounds like someone who never had to pay for each SMS.

Sounds like someone shouldn't have skipped those perspective-taking classes in kindergarten.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#328

Earlier quoted context omitted.

Just explain what end to end encryption means. People are starting to get it and don’t want companies able to read their messages.

My Signal experience: ex gf in college asks what app I’m using to text. Tell her it’s Signal, E2EE, messages are only stored on her phone and nobody else can read them. She says cool and downloads the app. Four months later her phone breaks. “Hey subjectsigma I got my new phone today. Where are all my messages?” “… Do you have your old phone? That’s the only place they are.” “No? Last time I got a new phone WhatsApp…

I don’t understand why people need old messages so badly. If they disappeared it would be fine with me. I set my iPhone messages to auto delete after a few months to save space and it works fine. A text is ephemeral, if I need to save something I use email.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#329
post #206

They provided some domains, but not all of them are taken. For example, signal-protect[.]host is available, kropyva[.]site is available, signal-confirm[.]site is registered in Ukraine. Some of them are registered in Russia. Never trust a country at war—any side. Party A blames B, Party B blames A, but both have their own agenda.

[flagged]

Could you please stop posting in the flamewar style? We've had to ask you this many times already.

https://news.ycombinator.com/newsguidelines.html

Post reply on HN