Live data from Hacker News

Valid Signal privacy issues shrugged off while patches quietly rolled out

403forbiddenblog.blogspot.com

51–53 of 53 posts

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#51
post #13

(via mobile quickly, same as my tweet replies on this one) ~~ hi there! signal did not start silently rolling out patches because there is nothing here to patch. friday’s releases were part of our regular cadence of shipping features and improvements to the apps. by design, SNs don't change when doing a signal device transfer or when making a linked device change, because the key material doesn't change. we explained…

https://twitter.com/moxie/status/1401261363305926658?s=20

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#52
post #50

Earlier quoted context omitted.

Sure, but exactly how would you build something that's robust against that kind of access? If you leave cryptographic keys lying around unprotected they should be assumed to be compromised.

Signal has a PIN, too. If that's required for the transfer, then it would prevent this in the case of brief, surreptitious access. A hostage scenario is impossible

Well, maybe, but 'brief' is doing a lot of the heavy lifting in that sentence.

Re: Valid Signal privacy issues shrugged off while patches quietly rolled out

#53
post #50

Earlier quoted context omitted.

Signal has a PIN, too. If that's required for the transfer, then it would prevent this in the case of brief, surreptitious access. A hostage scenario is impossible

Well, maybe, but 'brief' is doing a lot of the heavy lifting in that sentence.

> There are many cases where an attacker can access a device for a short time and/or without the owner realizing that the phone was tampered with.

This is what you originally responded to. I paraphrased it. The "heavy lifting" meme that you've employed is rarely more than a shallow dismissal. Be better.

Post reply on HN