Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

    • 0x0@infosec.pub
      link
      fedilink
      English
      arrow-up
      16
      ·
      3 days ago

      Signal doesn’t sync previous history so only new messages since linking are affected. I guess sending notifications to previous devices about link status would be helpful.

      Last I checked linked devices could only be computers, and linking didn’t involve phone numbers at all, so sim cloning and sms interception shouldn’t work, only qr linking, but I’m not sure that still is the case

      • plyth@feddit.org
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 days ago

        I guess sending notifications to previous devices about link status would be helpful.

        Understatement of the year.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      they did not disclose how have they done it for signal, and than mentioning linked devices. it could be that they got access to a linked computer of the user, and copied messages that way. there is not much signal could do against this. afaik the app already uses the system keystore to store api keys, and to partially encrypt its data, but the system keystore is often not so strong because its automatically unlocked

    • bedwyr@piefed.ca
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      2
      ·
      3 days ago

      I am curious to know if the NSA has backdoor access to signal. I bet they do.