cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

  • deltapi@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    41 minutes ago

    To me, this proves that the police can still get the information they need without us handing over our encryption keys and requiring ‘service providers’ to MITM for them.

  • anon_8675309@lemmy.world
    link
    fedilink
    English
    arrow-up
    21
    ·
    2 hours ago

    The headline makes people think signal is somehow broken.

    It’s not. Just be careful and monitor your account. And don’t let anyone gain physical control of your device.

  • bedwyr@piefed.ca
    link
    fedilink
    English
    arrow-up
    15
    ·
    5 hours ago

    A problem many aren’t aware of, in an area that shares telecommunications info, two people within that area can be identified by the state sending encrypted messages by seeing when one person sends and another instantly receives a message. It could be easy enough to obscure that I would think by working differing lag times in.

    I think it was in the intercept a few years back. I think this is it.

    https://theintercept.com/2024/05/22/whatsapp-security-vulnerability-meta-israel-palestine/

    • nodiratime@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      3 hours ago

      Remailer (Mixmaster) were meant to address that problem back when E-Mails were more popular.

  • evilcultist@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    13
    ·
    5 hours ago

    Seems like signal could send a notification 24 hours after any new device is added to remind the user that it was done. Make it so it has to be dismissed on each device so dismissing it on one doesn’t make it vanish on the rest.

    • SergeantSushi@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 hour ago

      I think you’re the only person here so far who read the linked article.

      I also found the netzpolitik article that was referenced but not linked to in the original article.

      This describes police adding a linked device to a person’s WhatsApp account while gathering evidence (translated with Google Translate).

      On January 12, 2020, Mr. and Mrs. P. were questioned. During the questioning, they voluntarily handed over the mobile phones they were carrying to the interviewing officers for a brief period so that messages from their daughter contained on the devices could be viewed and, among other things, photographed.

      While the photographs were being taken, the computer-based application WhatsApp Web was covertly activated via a website made available online by the Federal Criminal Police Office (BKA), allowing the messages to be read on a BKA computer (sic!). This did not involve any intrusion via a Trojan horse or similar software.

      The only link to Signal here is the nation state campaign which used social engineering via a phishing message from ‘Signal Support’.

      This nation state campaign was originally reported by a researcher at Citizen Lab.

  • peopleproblems@lemmy.world
    link
    fedilink
    English
    arrow-up
    113
    ·
    11 hours ago

    Interesting they highlight Signal again as though this is a vulnerability.

    If someone else has access to a linked device… that’s you fucking up access controls.

    • skisnow@lemmy.ca
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      20
      ·
      edit-2
      4 hours ago

      It’s a vulnerability precisely because people always swarm to defend Signal in stories like this, as though using Signal means the authorities (or other bad actors) can’t read your messages. Seems like every six months there’s some story involving Signal users getting hacked, and every time there’s a rush of wellacshuallys explaining why it wasn’t really Signal’s fault. (that last one is particularly egregious because I remember people defending it as “it wasn’t Signal, it was their partner who they subcontracted and gave your personal data to”, which is crazy levels of mental gymnastics.)

      Security is more than just encryption. If you flag something up as “hey use this if you want to hide from the Government” and have a personal phone number attached to it, that’s like a red rag to a bull.

      (edit: LOL, it’s hilarious how many people think they’re making great rebuttals in the replies when all they’re doing is proving my point. One child even flew directly into screaming at me. Signal fanbois are even worse than Apple supporters)

  • Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    77
    arrow-down
    2
    ·
    10 hours ago

    Signal failed to prevent soneone from accessing my unlocked phone and starting Signal! Everything was right there!

    • Zarobi@aussie.zone
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      9 hours ago

      On iOS you can set an app to require additional credentials to open, to prevent this situation. I’d imagine Android had something similar. I did it for all my important apps, just in case. Don’t want someone able to access my bank account or nudes.

      • Azzu@leminal.space
        link
        fedilink
        English
        arrow-up
        6
        ·
        4 hours ago

        If someone can get unlocked access to your phone, your security practices are already insufficient. If you really want to prevent something like this, you need to make this first step impossible, not add a bandaid on top of it.

      • schnokobaer@feddit.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 hours ago

        Doesn’t help a whole lot if you hand the unlocked phone with the unlocked app to a police officer.

      • BarrelAgedBoredom@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        3
        ·
        8 hours ago

        Just poked around. As far as I can tell there aren’t any options to require additional credentials to open an app on android. Im on a pixel 10 running android 17. However there is a locked “app drawer” that hides the apps from your home screen/ main app drawer that you need to have an additional password to access.

          • BarrelAgedBoredom@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            3 hours ago

            Yes, but that’s a signal option, not an android option. The original commenters said ios had a feature to require additional credentials and was wondering about android, not a specific app that happens to be on android

        • Teknikal@anarchist.nexus
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          I have App Locker in settings iy let’s me use a fingerprint unlock on any apps I want, I assume it’s a stock Android feature.

        • Zak@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 hours ago

          There’s Private Space, but that’s not ideal for a general-purpose messaging app because notifications are suspended when the space is locked. Signal also has the option to require the same authentication method as your screen lock in order to access the app.

          • Ludicrous0251@piefed.zip
            link
            fedilink
            English
            arrow-up
            4
            ·
            7 hours ago

            All of this is great, but there’s literally nothing stopping the next article from saying “user who left their phone unlocked with signal also unlocked ‘got hacked’”

  • odama626@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    ·
    10 hours ago

    Signal in this was clickbait they literally just say oh well if someone can link in their device they can see 45 days of message history

  • 87Six@lemmy.zip
    link
    fedilink
    English
    arrow-up
    6
    ·
    8 hours ago

    They reaaally want us to thibk Signal is equal to Whatsapp don’t they

    • urushitan 漆たん@kakera.kintsugi.moe
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      8 hours ago

      Signal doesn’t offer anything except sms 2fa and requires a phone number. It’s a terrible choice considering LEO can do what they did here and just get legal access to MITM your sms messages, spoof the 2fa, and take over your account, impersonating you. The other ones aren’t encrypted. So none of these they broke into are great choices for truly secure messaging.

      • Natanael@infosec.pub
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        Signal offers direct key verification (which you need to do out of band) or transparency log key verification (your device can check that senders who you add by number hasn’t had their key change)

        The attack here was getting an unlocked device in hand and using the internal sync feature without the user’s knowledge, and the solution to that is always to check your phone after an untrusted person handled it unlocked (or with Cellebrite type devices) - or to simply not offer access to the Signal app while unlocked (perhaps even uninstalling it first).

        There is no app which is fully secure against an untrusted third party getting physical access to your unlocked phone, especially not if you have a weak PIN or just fingerprint unlock

      • jungle@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 hours ago

        The other ones aren’t encrypted.

        Whatsapp is encrypted as far as I know. But then again, it’s Meta, so my trust in that is near zero.

        • boonhet@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 hours ago

          Telegram secret chats are too, but regular ones are not and you can’t have a secret group chat.

      • Zak@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        8 hours ago

        They can only impersonate you that way if your contacts dismiss the warning about your safety number changing. If you’re being directly targeted by the government of a wealthy country, using a specific app isn’t enough to prevent surveillance; you’ll need some actual opsec.

    • Brewchin@lemmy.world
      link
      fedilink
      English
      arrow-up
      49
      arrow-down
      1
      ·
      13 hours ago

      I’ll never understand why people accept SMS 2FA as any kind of security. Might as well put it as an ad in a newspaper. 🤦🏻‍♂️

      • tumbling4986@lemmy.ca
        link
        fedilink
        English
        arrow-up
        44
        ·
        12 hours ago

        Because many services only have SMS as 2FA option. Especially government services.

        Also it is impossible to use google without enabling the SMS 2FA option. No matter what, with only 2FA authenticator app or email, they will lock down the account by saying “unable to verify”.

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          You can remove SMS 2FA from a Google account if you have passkeys or hardware security keys registered

        • Yaky@slrpnk.net
          link
          fedilink
          English
          arrow-up
          3
          ·
          10 hours ago

          You can have a Google account without 2FA, but you need to create it using a factory-reset old Android phone (Android 8 or so).

        • cmnybo@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          8
          arrow-down
          2
          ·
          12 hours ago

          I never set a phone number on two of my google accounts and they still work fine. Those accounts are old. Google didn’t ask for a phone number to sign up back then.

          I recall seeing something about them planning to get rid of SMS 2FA last year. It looks like it’s still an option though.

          • Zarobi@aussie.zone
            link
            fedilink
            English
            arrow-up
            7
            arrow-down
            1
            ·
            9 hours ago

            Watch out, if those accounts are ever “locked”, you will get permanently locked out of the accounts. Happened to me because a data breach revealed my email address and some idiot tried brute forcing my password. Didn’t work but it broke the account. Secondary recovery email address and correct password wasn’t good enough. Support basically told me to give up and make a new account (???).

            • overstep8556@jlai.lu
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 hours ago

              I guess in this case they block the account if it has no 2FA set up. If the account has TOTP set up it may be enough to avoid being blocked, even under brute forcing and without phone number.

  • time2lose@lemmy.world
    link
    fedilink
    English
    arrow-up
    22
    arrow-down
    5
    ·
    12 hours ago

    Telegram and whatsapp never had encryption. Also - they just give your messages on law enforcement request, always have.

    Signal - how does it work with signal again?

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 hours ago

      Telegram has shitty 1-to-1 encryption but no group encryption.

      WhatsApp claims to use the same encryption algorithms as Signal, but you can’t audit it.

    • FriendOfDeSoto@startrek.website
      link
      fedilink
      English
      arrow-up
      19
      arrow-down
      1
      ·
      11 hours ago

      They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.

      Which is clever, to be fair. Whether or not that’s legal is already a court case. The law is so frightfully grey.

      • peopleproblems@lemmy.world
        link
        fedilink
        English
        arrow-up
        12
        ·
        11 hours ago

        Its also a failure of the user’s access control and operating security.

        Once a third party has access to the secure environment, that environment is and will always be compromised.

        • undrwater@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 hours ago

          Is the user made aware of this by the operator (signal, telegram, et al)?

          If not, it’s a big haul to get to competency. The operator should be educating users on how to limit compromise.

          • peopleproblems@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            5 hours ago
            1. It NEVER advertises itself as such.

            2. IIRC Signal DOES warn you about this, first when you make an account, and then when you try to save media files, and when you try to start a group chat. The others aren’t remotely secure anyway and I have no interest in attempting to defend them.

    • yestalgia@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      9 hours ago

      “Just get everyone in your life to move to ______ and that will solve all your problems”

      A suggestion as old as time

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        3
        ·
        9 hours ago

        it’s one of the most secure message apps available.

        messages are signed, encrypted and passed through servers, never left on the server. unless you were the intended recipient you will not decrypt it.

        it’s the truecrypt of instant messaging.

    • fonix232@fedia.io
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      9 hours ago

      Oh really? Simplex would block someone from accessing your phone and thus Simplex’ data?

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        8 hours ago

        give me a list of messaging apps that stop attacks that leverage physical access.

        use a better os that has encryption and kill codes if that’s your concern.

        • vald@mbin.linuxnation.social
          link
          fedilink
          arrow-up
          5
          arrow-down
          2
          ·
          7 hours ago

          give me a list of messaging apps that stop attacks that leverage physical access.

          you know what would solve this? simplex.

          um…

          • GreenKnight23@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            2
            ·
            6 hours ago

            either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance

            why are you so against people using a more secure way to communicate?

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              11 minutes ago

              the only time they mention signal is when they explain they used linked devices to obtain signal messages. not SMS! if you lose your phone or whatever, and log in on a new device, your messages won’t magically reappear, they are lost, and all your contacts get a warning that your safety numbers have changed.

  • There have been too many of these types of events related to signal. And it has so many red flags. You are required to have a phone number which is essentially ur real identity. They used to federate with 3rd party servers but they killed that and all but wiped it from the internet. They try to shut down 3rd party clients. They don’t provide reproducible builds so we can’t trust the source. They received their initial funding from In-Q-Tel the CIA venture capital firm.

    Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.

    At minimum they have a full social graph of real identities with time-stamped message events. Sealed sender doesn’t negate this as signal knows ur ip address when u give them a message. They also know the destination of that message as that isn’t sealed. This is sufficient information to link sender and recipient and timestamp. That’s assuming the unreproducible builds don’t have backdoors.

    It’s all got a slightly fishy smell to it.

    Tldr: If u want actual secure messaging u should consider SimpleX

    • DomeGuy@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      11 hours ago

      There are all of these stories about signal because it is notable when someone gets around it

      That there’s anything approaching secure communication on a cell-phone dominated Internet whose.operating systems are either “snobbish walled garden” or “ad agency living in the corpse of a search engine” is astonishing. In the same way that a gun safety that keeps a toddler from shooting themselves with an otherwise loaded gun is astonishing.

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        4
        ·
        10 hours ago

        can’t get around simplex encryption unless you have physical access to the device or have been physically invited by a member.

        • DomeGuy@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          53 minutes ago

          breaking the encryption is hard , but getting around the encryption is entirely doable without physical access if you allow SMS or on-device sharing.

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          3
          ·
          4 hours ago

          Ok so no better than Signal?

          You can do all the same things and use Tor, allow Sealed sender, and rotate username with phone number hidden.

          Why does Simplex want investors?

        • DomeGuy@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          8 hours ago

          You should trust signal tree the same way you trust a front door lock that has never been broken or picked despite repeated attempts to do both.

          .Just remember that police only go through the door when it’s easier than breaking a window or tearing through a wall.

                • Natanael@infosec.pub
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  3 hours ago

                  Signal supports Tor.

                  They have features like Sealed Sender, which is at least on par with the multiple server behavior of Simplex as it behaves the same (message passing multiple servers, carrying no sender origin data in plaintext)

                  Simplex knows the same thing. The pairwise identifiers is a sham - all your different identifiers point to the same Android/iOS notification server API key so they know the recipient is the same person, they can tell which exact phone receives a notification when somebody sends you a message (unless the devs use anonymized fetch on a polling schedule, which they don’t).

                  And because they don’t hide those sender stamps, Simplex leak more info than Signal with Sealed sender

                  Why is Simplex asking for investors?

                  Are Simplex even considering notification content security?