cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

  • GreenKnight23@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    5
    ·
    20 hours ago

    can’t get around simplex encryption unless you have physical access to the device or have been physically invited by a member.

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        8 hours ago

        lol

        either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance

        it’s literally a quote in the post. physical access was only one way they accessed messages.

        • SupraMario@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 hours ago

          That’s not the point I was trying to make. You are acting like simplex is better than signal because it requires physical access… that’s how it works for signal as well…that was the point…

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      13 hours ago

      Ok so no better than Signal?

      You can do all the same things and use Tor, allow Sealed sender, and rotate username with phone number hidden.

      Why does Simplex want investors?

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        8 hours ago

        what company doesn’t want to grow or maintain services? they host the primary servers that everyone uses, that costs money.

        you could host your own though. can you do that with signal?

          • GreenKnight23@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            2
            ·
            8 hours ago

            as I pointed out in your other comment. signal uses a database, fails to explain why a database is required, and doesn’t even make a mention of it in their technical information.

            why use a database at all? that just introduces more attack surface area and complexity for attackers to leverage.

            • Natanael@infosec.pub
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              5 hours ago

              Yeah precisely you didn’t check what it’s for. It doesn’t hold conversation data or even metadata.

                • Natanael@infosec.pub
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  edit-2
                  1 hour ago

                  WHAT DO YOU THINK IT’S USED FOR

                  they have 45 day store-and-forward of encrypted attachments, and the handle registration thing, and that’s it

                  Do you think they would want to go to federal jail for lying to federal agents when they insist they have no metadata about you?

                  Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.

                  https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md

                  Hypocrite

                  • GreenKnight23@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    22 minutes ago

                    I’m about to block you because you’re just spamming the same argument in two different threads.

                    simplex has a more secure and robust architecture when compared to signal. simplex router can literally run on a raspberry pi zero with 2gb of storage.

                    nothing is written to storage for simplex unless you configure it otherwise.

                    the defaults for signal selfhosting promotes convenience over security and does not appropriately protect admins from search and seizures.

                    signal is good, if all you want is to share memes with your friends, but if you want to build a network of trusted individuals for purposes that are actively targeted by corrupt governments, simplex wins hands down.

    • DomeGuy@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      10 hours ago

      breaking the encryption is hard , but getting around the encryption is entirely doable without physical access if you allow SMS or on-device sharing.