Live data from Hacker News

Multiple Russia-aligned threat actors actively targeting Signal Messenger

cloud.google.com

71–80 of 329 posts

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#71

I'd love to have more of my socializing happening on Signal. Anyone got a good way to convince the non-paranoid to use it?

Just explain what end to end encryption means. People are starting to get it and don’t want companies able to read their messages.

My Signal experience: ex gf in college asks what app I’m using to text. Tell her it’s Signal, E2EE, messages are only stored on her phone and nobody else can read them. She says cool and downloads the app. Four months later her phone breaks.

“Hey subjectsigma I got my new phone today. Where are all my messages?”

“… Do you have your old phone? That’s the only place they are.”

“No? Last time I got a new phone WhatsApp moved my messages over, and WA is E2EE so I thought it worked the same way.”

“Nope if you don’t have a backup or your old phone they’re gone. Sorry.”

“This is bullshit. Why does anyone use Signal. I can’t believe it deleted all my messages. I’m uninstalling it. Etc etc.”

We have a long way to go, my friend.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#73

Earlier quoted context omitted.

Yeah, this just gave me the last nudge I needed to give Signal a go.

[flagged]

Can you elaborate? I'm semi-familiar with the Signal protocol but I'm not sure what you are referring to here.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#74
post #44
post #9

It is not plainly stated in the article, but as far as I understand, the first step of one of the attacks is to take the smartphone off a dead soldier’s body.

Is this serious? It raises questions about smartphones being standard equipment for soldiers, but they do give every soldier an effective, powerful computing and communication platform (that they know without additional training). The question is how to secure them, including against the risk described in the parent. That seems like a high risk to me I would expect someone is working on how to secure them enough that…

I seem to recall uploaded selfies being a frequent source of problems. For example: https://www.rferl.org/a/trench-selfies-tracking-russia-milit...

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#75
post #72

Earlier quoted context omitted.

[flagged]

Obligatory request to provide a source to backup some serious claims?

If you're a signal user and didn't know about this already, that should tell you everything you need to know about signal.

See https://community.signalusers.org/t/proper-secure-value-secu...

Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." (https://signal.org/legal/)

Signal loves to brag about the times when the government came to them asking for information only to get turned away because Signal never collected any data in the first place. They still brag about it. It hasn't actually been true for years though. Now they're collecting the exact info the government was asking for and they're protecting that data with a not-very-secure/likely backdoored enclave on the server side, and (even worse) a pin on the client side.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#77

Earlier quoted context omitted.

Which is bad, how?

It's a joke, because virtue signaling (or whatever name you want to give it) is bad, but Signal the messenger app is good so it's a play on words.

It’s not bad. It just IS.

the only people that think it is bad are people who have a different opinion and feel attacked for whatever reason. I find it telling when people accuse others of virtue signaling because it is almost always someone who is jealous or insecure attacking said signaler.

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#78
post #73

Earlier quoted context omitted.

[flagged]

Can you elaborate? I'm semi-familiar with the Signal protocol but I'm not sure what you are referring to here.

See https://community.signalusers.org/t/proper-secure-value-secu...

Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." (https://signal.org/legal/)

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#79
post #9

It is not plainly stated in the article, but as far as I understand, the first step of one of the attacks is to take the smartphone off a dead soldier’s body.

The article says they phish people into linking adversarial devices to their Signal:

> [...] threat actors have resorted to crafting malicious QR codes that, when scanned, will link a victim's account to an actor-controlled Signal instance. If successful, future messages will be delivered synchronously to both the victim and the threat actor in real-time, [...]

Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger

#80
post #65
post #21

Earlier quoted context omitted.

What if they want to contact you and you use Signal?

Luckily, with the technological advances in the last months, it is now possible to install more than one app on a phone at a time.

It is also possible to communicate without using Meta services.
Post reply on HN