cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

  • time2lose@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    17 days ago

    Telegram and whatsapp never had encryption. Also - they just give your messages on law enforcement request, always have.

    Signal - how does it work with signal again?

    • FriendOfDeSoto@startrek.website
      link
      fedilink
      English
      arrow-up
      0
      ·
      17 days ago

      They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.

      Which is clever, to be fair. Whether or not that’s legal is already a court case. The law is so frightfully grey.

      • peopleproblems@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        17 days ago

        Its also a failure of the user’s access control and operating security.

        Once a third party has access to the secure environment, that environment is and will always be compromised.

        • undrwater@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          17 days ago

          Is the user made aware of this by the operator (signal, telegram, et al)?

          If not, it’s a big haul to get to competency. The operator should be educating users on how to limit compromise.

          • gandalf_der_13te@feddit.org
            link
            fedilink
            English
            arrow-up
            0
            ·
            13 days ago

            i just logged into signal on my desktop app about 4 hours ago, and about 90 minutes after that i got a message from signal to my phone to inform me about this.

  • peopleproblems@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    17 days ago

    Interesting they highlight Signal again as though this is a vulnerability.

    If someone else has access to a linked device… that’s you fucking up access controls.

    • not@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      16 days ago

      I want a version of Signal that doesn’t allow linked devices. Linking devices is a clear vulnerability.

      • peopleproblems@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        16 days ago

        Im going to go out on a limb here and suggest something that should be obvious - you don’t have to link devices

          • peopleproblems@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            15 days ago

            Signal does not use SMS.

            The vulnerability they call out in the article is a phishing attack. A phishing attack requires the user’s input. There is no defense, no security, no techniques or technology to prevent you from handing the key to your safe to someone else.

    • Brewchin@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      17 days ago

      I’ll never understand why people accept SMS 2FA as any kind of security. Might as well put it as an ad in a newspaper. 🤦🏻‍♂️

      • tumbling4986@lemmy.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        17 days ago

        Because many services only have SMS as 2FA option. Especially government services.

        Also it is impossible to use google without enabling the SMS 2FA option. No matter what, with only 2FA authenticator app or email, they will lock down the account by saying “unable to verify”.

        • cmnybo@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          0
          ·
          17 days ago

          I never set a phone number on two of my google accounts and they still work fine. Those accounts are old. Google didn’t ask for a phone number to sign up back then.

          I recall seeing something about them planning to get rid of SMS 2FA last year. It looks like it’s still an option though.

          • Zarobi@aussie.zone
            link
            fedilink
            English
            arrow-up
            0
            ·
            17 days ago

            Watch out, if those accounts are ever “locked”, you will get permanently locked out of the accounts. Happened to me because a data breach revealed my email address and some idiot tried brute forcing my password. Didn’t work but it broke the account. Secondary recovery email address and correct password wasn’t good enough. Support basically told me to give up and make a new account (???).

  • Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    17 days ago

    Signal failed to prevent soneone from accessing my unlocked phone and starting Signal! Everything was right there!

    • Zarobi@aussie.zone
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      17 days ago

      On iOS you can set an app to require additional credentials to open, to prevent this situation. I’d imagine Android had something similar. I did it for all my important apps, just in case. Don’t want someone able to access my bank account or nudes.

      • BarrelAgedBoredom@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        17 days ago

        Just poked around. As far as I can tell there aren’t any options to require additional credentials to open an app on android. Im on a pixel 10 running android 17. However there is a locked “app drawer” that hides the apps from your home screen/ main app drawer that you need to have an additional password to access.

          • BarrelAgedBoredom@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            17 days ago

            Yes, but that’s a signal option, not an android option. The original commenters said ios had a feature to require additional credentials and was wondering about android, not a specific app that happens to be on android

      • schnokobaer@feddit.org
        link
        fedilink
        English
        arrow-up
        0
        ·
        17 days ago

        Doesn’t help a whole lot if you hand the unlocked phone with the unlocked app to a police officer.

        • frongt@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          1
          ·
          16 days ago

          Because if you do, you just got Cellebrite’d. Your entire phone is compromised, now and going forward.

  • There have been too many of these types of events related to signal. And it has so many red flags. You are required to have a phone number which is essentially ur real identity. They used to federate with 3rd party servers but they killed that and all but wiped it from the internet. They try to shut down 3rd party clients. They don’t provide reproducible builds so we can’t trust the source. They received their initial funding from In-Q-Tel the CIA venture capital firm.

    Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.

    At minimum they have a full social graph of real identities with time-stamped message events. Sealed sender doesn’t negate this as signal knows ur ip address when u give them a message. They also know the destination of that message as that isn’t sealed. This is sufficient information to link sender and recipient and timestamp. That’s assuming the unreproducible builds don’t have backdoors.

    It’s all got a slightly fishy smell to it.

    Tldr: If u want actual secure messaging u should consider SimpleX

    • DomeGuy@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      17 days ago

      There are all of these stories about signal because it is notable when someone gets around it

      That there’s anything approaching secure communication on a cell-phone dominated Internet whose.operating systems are either “snobbish walled garden” or “ad agency living in the corpse of a search engine” is astonishing. In the same way that a gun safety that keeps a toddler from shooting themselves with an otherwise loaded gun is astonishing.

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        17 days ago

        can’t get around simplex encryption unless you have physical access to the device or have been physically invited by a member.

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          0
          ·
          17 days ago

          Ok so no better than Signal?

          You can do all the same things and use Tor, allow Sealed sender, and rotate username with phone number hidden.

          Why does Simplex want investors?

          • GreenKnight23@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            17 days ago

            what company doesn’t want to grow or maintain services? they host the primary servers that everyone uses, that costs money.

            you could host your own though. can you do that with signal?

              • GreenKnight23@lemmy.world
                link
                fedilink
                English
                arrow-up
                0
                ·
                17 days ago

                as I pointed out in your other comment. signal uses a database, fails to explain why a database is required, and doesn’t even make a mention of it in their technical information.

                why use a database at all? that just introduces more attack surface area and complexity for attackers to leverage.

                • Natanael@infosec.pub
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  16 days ago

                  Yeah precisely you didn’t check what it’s for. It doesn’t hold conversation data or even metadata.

        • DomeGuy@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          17 days ago

          You should trust signal tree the same way you trust a front door lock that has never been broken or picked despite repeated attempts to do both.

          .Just remember that police only go through the door when it’s easier than breaking a window or tearing through a wall.