Signal: Firm claims to have cracked chat app's encryption
web.archive.org
Signal: Firm claims to have cracked chat app's encryption
1–10 of 18 posts
Re: Signal: Firm claims to have cracked chat app's encryption
#2A more worrying attack would be something able to decrypt the traffic on the wire, or a man-in-the-middle.
Re: Signal: Firm claims to have cracked chat app's encryption
#3... yes?
Re: Signal: Firm claims to have cracked chat app's encryption
#4I'm not familiar with Android, but is this an easy step, or a "draw the rest of the fucking owl" step?
Re: Signal: Firm claims to have cracked chat app's encryption
#5It's hardly surprising that, with physical access to the device, the encrypted messages can be decrypted. Logic dictates that, for the app itself to be able to do so, the keys must be either stored locally or retrievable. A more worrying attack would be something able to decrypt the traffic on the wire, or a man-in-the-middle.
Re: Signal: Firm claims to have cracked chat app's encryption
#6Nice PR spin and non-story - yes, with access to the Android keystore secret, the database can be decrypted.
Doesn't work if the device has a functional root of trust, or Signal's password feature is used.
Re: Signal: Firm claims to have cracked chat app's encryption
#7Surprisingly to no one: if you have fully access to the Phone (including access to the user's keystore) you can use the Signal app (and thus read messages). Thanks for making "our world a safer place".
Re: Signal: Firm claims to have cracked chat app's encryption
#8> We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”. I'm not familiar with Android, but is this an easy step, or a "draw the rest of the fucking owl" step?
Re: Signal: Firm claims to have cracked chat app's encryption
#9This is pure marketing BS. "Decrypting Signal messages and attachments was not an easy task. It required extensive research on many different fronts to create new capabilities from scratch." is marketing speak for "we read some open source code and reimplemented it, and we want it to sound hard and difficult so you will pay us more money."
Cellebrite's stuff is based on 0-day vulnerabilities in phone OSes and hardware in order to extract the data. Once you have the data, the rest of it is parsing and formatting fluff to package up the data in an easily digestible form for law enforcement to use. This is about the latter. There is no vulnerability in Signal being cracked here. It's just doing the same thing Signal does to show you your own messages.
Re: Signal: Firm claims to have cracked chat app's encryption
#10Also in order to get to the Signal data storage you would first have to defeat the encryption of the device itself (ie. the encryption used by Android / IOS). I would assume that anyone who uses signal and really has something to hide has disabled fingerprint or face id and uses either a passphrase or pincode. It's going to be hard to ever access the signal storage that way.