cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

  • peopleproblems
    link
    fedilink
    English
    arrow-up
    173
    ·
    5 days ago

    Interesting they highlight Signal again as though this is a vulnerability.

    If someone else has access to a linked device… that’s you fucking up access controls.

    • not@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      4 days ago

      I want a version of Signal that doesn’t allow linked devices. Linking devices is a clear vulnerability.

      • peopleproblems
        link
        fedilink
        English
        arrow-up
        11
        ·
        4 days ago

        Im going to go out on a limb here and suggest something that should be obvious - you don’t have to link devices

        • not@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          4 days ago

          But “Law enforcement” can do it by spoofing sms. I want one account, one device.

          • peopleproblems
            link
            fedilink
            English
            arrow-up
            3
            ·
            3 days ago

            Signal does not use SMS.

            The vulnerability they call out in the article is a phishing attack. A phishing attack requires the user’s input. There is no defense, no security, no techniques or technology to prevent you from handing the key to your safe to someone else.

    • skisnow@lemmy.ca
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      45
      ·
      edit-2
      4 days ago

      It’s a vulnerability precisely because people always swarm to defend Signal in stories like this, as though using Signal means the authorities (or other bad actors) can’t read your messages. Seems like every six months there’s some story involving Signal users getting hacked, and every time there’s a rush of wellacshuallys explaining why it wasn’t really Signal’s fault. (that last one is particularly egregious because I remember people defending it as “it wasn’t Signal, it was their partner who they subcontracted and gave your personal data to”, which is crazy levels of mental gymnastics.)

      Security is more than just encryption. If you flag something up as “hey use this if you want to hide from the Government” and have a personal phone number attached to it, that’s like a red rag to a bull.

      (edit: LOL, it’s hilarious how many people think they’re making great rebuttals in the replies when all they’re doing is proving my point. One child even flew directly into screaming at me. Signal fanbois are even worse than Apple supporters)

      • FauxLiving
        link
        fedilink
        English
        arrow-up
        37
        arrow-down
        3
        ·
        4 days ago

        as though using Signal means the authorities can’t read your messages.

        Nobody who understands the topic thinks this.

        Signal exists to prevent the contents from being read off the wire and from having the capability of compelling Signal’s parent company from turning over stored messages.

        It doesn’t exist to hand hold you so you don’t get phished, or prevent you from running it on a vendor phone full of spyware. You’re responsible for making sure your hardware is secure and that you’re not socially engineered.

      • peopleproblems
        link
        fedilink
        English
        arrow-up
        33
        arrow-down
        2
        ·
        4 days ago

        IT DOESN’T ADVERTISE ITSELF AS A SECURE PLATFORM!!!

        It says PRIVACY. If you are dancing ass naked inside your house but you have your windows open… guess what?

        • imminent_nebula@lemmy.ca
          link
          fedilink
          English
          arrow-up
          13
          ·
          4 days ago

          A lot of these types use ‘perfect being the enemy of good’ as their attack vector. If it’s not private and anonymous why bother? If you can’t cut out all big tech companies, if you can’t stop buying any American goods, if you can’t feed all the poor or house all the homeless, etc. It’s an effective way to attack progression by making people believe they should just stop fighting, they’ll never win. You nailed it, Signal is private, it doesn’t claim to be anything else.

          • peopleproblems
            link
            fedilink
            English
            arrow-up
            2
            ·
            4 days ago

            You just pointed something out there that I haven’t really considered. But its also the difference between abolitionists and reformists too- namely, abolition should be the goal, but don’t let that stop you from making reforms too.

          • peopleproblems
            link
            fedilink
            English
            arrow-up
            21
            arrow-down
            1
            ·
            4 days ago

            A rabid fan of a message application? Just for trying to point out that if the police get your unlocked phone then they have compromised your messages?

      • Natanael@infosec.pub
        link
        fedilink
        English
        arrow-up
        17
        arrow-down
        2
        ·
        edit-2
        4 days ago

        Why are you lying about what security guarantees Signal say they offer?

        https://support.signal.org/hc/en-us/articles/9932632052378-How-to-protect-yourself-on-Signal

        https://support.signal.org/hc/en-us/articles/9932566320410-Staying-Safe-from-Phishing-Scams-and-Impersonation

        Even your example of the Twilio hack is far less relevant now since they added transparency logs, which means it is much harder to impersonate you without detection even if the hacker can control the telco

        https://support.signal.org/hc/en-us/articles/10223569377562-Automatic-Key-Verification