22 ms·
Signal on Android: Images sent to wrong contacts
- cube00 5y agoThat's a lot of faith that you'll never log anything sensitive by making the user's debug logs public if they want to report an issue.
- johnchristopher 5y ago> [..] his Signal randomly sending images to me that he didn't intend to, even without initiating the addition of any attachments on the GUI... he even sees one of my messages displayed on his side with a random image attached to it, as if i have sent that image to him, even though that image is not even present on my phone. https://github.com/signalapp/Signal-Android/issues/10247#issuecomment-879377861 https://github.com/signalapp/Signal-Android/issues/10247#iss... Yikes. > [..] I've also recently had a probably unrelated issue where my mic was still audible to the other party after I hung up the call. https://github.com/signalapp/Signal-Android/issues/10247#issuecomment-879466491 https://github.com/signalapp/Signal-Android/issues/10247#iss... Double yikes.
- rvz 5y ago> I've also recently had a probably unrelated issue where my mic was still audible to the other party after I hung up the call. That one there is a cataclysmic security land mine. Absolutely unacceptable. That was the last straw after [0]. I don't think I can recommend Signal at this time. To Downvoters: So these bugs are all fine then? They are not security issues then? Not only having images being sent to the wrong contacts but also having the microphone still on after ending the call and being audible to the other party? That's fine right? If this happened on any other messaging app, I would expect a massive outcry and urgency to fix these critical issues. [0] https://news.ycombinator.com/item?id=27951076 https://news.ycombinator.com/item?id=27951076
- ubercow13 5y agoYes. Signal's only selling point is privacy. Both of these bugs are huge privacy breaches that kill its value proposition. Which type of privacy breach is more likely to have tangible and direct negative effects on an average user's life - a nation state storing their communications in a database, Facebook graphing their contacts and using them for friend recommendations, or their friends/family/boss/acquaintances being sent random private photos from their phone and audio of private conversations they have in their home, without them knowing? One of the main worries with companies having access to your unencrypted private data is that no matter how careful they are with it, it can still end up in the wrong hands. Signal is directly sending your data into the wrong hands.
- dmosley 5y agoI agree these bugs that Signal has are serious. With hat said, your examples aren't that great for counters. "a nation state storing their communications in a database" - The power differential and historic missteps of governments makes this ludicrous to think of as "OK" in comparison. "Facebook graphing their contacts and using them for friend recommendations" - but, it's not just for friend recommendations and possibly more importantly, it's not just their users, is it? Not to mention it's ignoring the purposeful opinion-biasing they have openly taken part in to manufacture consent for any number of issues. While these bugs are bad and should be prioritized for fix, they are seemingly random. Sure they can possibly be exploited (possible, haven't seen proof of concept for purposeful exploitation), but random bugging vs clear and present danger on current and historical precedents of governments and technocratic oligarchs? Me thinks your trust may be a bit misplaced or you're just being obtuse for sake of obtuseness.
- deleted 5y ago[deleted]
- markovbot 5y ago>The power differential and historic missteps of governments makes this ludicrous to think of as "OK" in comparison. wasn't that kind of the point?
- bakoo 5y agoThe first issue was fixed and just closed, and seems like it was very difficult to track down.
- FabHK 5y agoIt was closed 4 minutes ago; when was it fixed? ETA: Ah, 4 days ago (more than half a year after it was opened).
- johnchristopher 5y agoIt's fixed in 5.17 and this is the release number I see on the Google playstore. Unfortunately for my ubuntu 18.04 LTS and this is in no way Signal's fault (but maybe the desktop version doesn't have that bug ?): $ apt-cache policy signal-desktop signal-desktop: Installé : 5.10.0 Candidat : 5.10.0 Table de version : *** 5.10.0 500 500 https://updates.signal.org/desktop/apt xenial/main amd64 Packages 100 /var/lib/dpkg/status 5.9.0 500 500 https://updates.signal.org/desktop/apt xenial/main amd64 Packages 5.8.0 500 500 https://updates.signal.org/desktop/apt xenial/main amd64 Packages
- maqp 5y agoWould rolling into the beta help here? https://support.signal.org/hc/en-us/articles/360007318471-Signal-Beta https://support.signal.org/hc/en-us/articles/360007318471-Si...
- johnchristopher 5y agoI don't think so: $ apt-cache policy signal-desktop-beta signal-desktop-beta: Installé : (aucun) Candidat : 5.11.0-beta.1 Table de version : 5.11.0-beta.1 500 500 https://updates.signal.org/desktop/apt xenial/main amd64 Packages
- maltalex 5y ago> webworxshop opened this issue on 4 Dec 2020 Triple yikes. Though it looks like the issue was finally closed minutes ago: > Hi there, sorry, this issue was fixed in 5.17 (which hit 100% production on 7/21). There was another issue tracking this and it looks like I forgot to close this one. Still, that's a lot of time for such a bug to exist!
- crossroadsguy 5y agoStopped doing calls on Signal after my Android contacts started telling me that they see active calls minutes after I successfully hung up from my side (iOS). Not to mention the countless UX bugs. I’m back on WhatsApp and not telling anyone anymore to move to Signal or any app whatsoever. I’m done.
- Multicomp 5y agoI've not experienced reports of this for myself. I'll ask my driend group to do a comparison between our shared room and see if there are any problems. to be fair i mostly use groups so maybe the behavior is limited to 1x1 messaging?
- rvz 5y agoI was just talking about Signal one hour ago whether if it was available on PinePhones or the Librem 5 which seems very unclear, and now this happens on Android devices. Does this mean that not only I can't yet recommend a PinePhone or Librem 5 yet, but for current Android users I can't even recommend Signal to anyone due to this issue?
- CodeGlitch 5y agoEmail. Why are we still trying to push these instant messaging apps that are a privacy and security nightmare? (I realise email has security issues too).
- Santosh83 5y agoEmail has weaker EtoE encryption than these IM solutions. Even with GPG. Too much metadata is leaked. However the decentralised nature of email is one crucial advantage it has over these apps.
- CodeGlitch 5y agoI agree about the EtoE encryption weaknesses. However since I can send email from my own email server to another email server without it touching a 3rd party (not including the ISPs and DNS servers) means EtoE is not such a massive issue. I can't make phone calls or video calls over email, but for text, small files and images it's perfect (given how long email has been around it goes to show how good it is).
- beermonster 5y agoYou could in theory (but this is like putting plasters on a colander) relocate some of the MIME meta data (Subject:, To:, From:) to the email body and then encrypt it. So basically obfuscate the MIME headers and use some kind of guid@domain type addresses for the MTA routing.
- h_anna_h 5y ago"Weaker E2EE" as in "PFS is not commonly used with email". As for the metadata, no metadata is leaked that signal does not also leak.
- m1r3k 5y agoA non-techie relative of mine told me about images being sent to wrong people and them asking why they sent the photo. I first assumed it was just user error but apparently that's quite a bit data leak on signals side.
- johnchristopher 5y agoWhile I suppose the protocol is not at fault and it's a UI and client bug it's still a huge problem. Just today I was thinking ”it's been weeks since they moved the GIF button to a different place but there's still the old button at the old place and when you click on it there's a pop-up "wrong, the button is somewhere else now"”. Why even keep the old button in the old place ? And it led me to thinking "what else could be wrong/buggy in the UI and the UX that is not obvious to them ?". edit: according to this comment https://news.ycombinator.com/item?id=27951648 https://news.ycombinator.com/item?id=27951648 there is only one dev working on the Android client ? Hats off to that person, it's incredible. So I should have written: And it led me to thinking "what else could be wrong/buggy in the UI and the UX that they haven't had time to catch and fix yet ?".
- kitsunesoba 5y agoThis underscores why it’s important to allow third party clients to connect. When only the first-party client is allowed, the failings of its UI drag down the core, too — it doesn’t matter how good the core is if it’s permanently mated to a half-baked UI.
- rakoo 5y agoAnd when third parties can connect, the protocol can't evolve because every change becomes "good to simplement" but it takes an enormous amount of time, resources And influence to change to "mandatory to implement". As always it's a delicate balance between security And ease of use, and Signal has always been up front in favoring the former.
- Santosh83 5y agoIs this some kind of cache bug? Pretty serious, whatever it is, and judging by the linked issue, they either haven't taken it seriously, or worse, they aren't able to pinpoint the bug.
- hypertele-Xii 5y agoRe-using of message IDs.
- jerkstate 5y agoSignal has been adding lots of silly social media like features lately, not surprising that they are messing up the core value prop. I’m shopping for a new encrypted messenger. They used to say every program expands in scope until it can read email, now every app expands until you can add Snapchat filters to your selfies.
- jMyles 5y agoEvery time something like this comes up, I say something like, "Who wants to switch to Matrix (ie, Element, and before that, Riot Chat)?" But then, I myself don't end up doing it, largely because of the network effect on Signal. I think we need to just remember to always keep 3-5 of them open so we can have some horizontal evolution.
- beermonster 5y agoI’ve tried Element. I think Signal is probably easier to setup and use for most non-technical people on comparison.
- TheChaplain 5y agoIt's necessary if you want to attract the mainstream users, who could not care less for e2e security but values stickers, filters and stories above all else.
- hellcow 5y agoMatrix is a solid replacement. Element isn't as easy to use but it's coming along. Quality-of-life features normal users expect like stickers, gifs, etc. are woefully lacking, but the important stuff (y'know, actual messaging) is solid. The most important thing to me is if Element screws up like Signal and starts pushing a shitcoin, I can swap clients without affecting my network.
- dindresto 5y agoAlso, Matrix supports other client implementations than Element, like https://fluffychat.im/ https://fluffychat.im/
- colesantiago 5y agoSignal is becoming a joke that we should reconsider using, and now has dangerous bugs that is at the edge of compromising people's privacy. Has this app/service really been audited properly? We now need to consider serious alternatives that we should get behind like Element [0] or Session [1] but I am open to user friendly alternatives other than Signal (at worst even Quill [2] or Delta Chat [3]). [0] https://element.io https://element.io [1] https://getsession.org https://getsession.org [2] https://quill.chat https://quill.chat [3] https://delta.chat https://delta.chat
- deleted 5y ago[deleted]
- eganist 5y ago> Has this app/service really been audited properly? Yes, repeatedly: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243 https://community.signalusers.org/t/wiki-overview-of-third-p... Edit: that said, this did make me revisit a question I asked signal via their Careers portal a long while back. Reposted here: https://news.ycombinator.com/item?id=27952315 https://news.ycombinator.com/item?id=27952315
- colesantiago 5y agoAnd yet there are serious bugs like this that slip through the net, a simple benchmark of any chat app should not be showing other people's messages like what Signal is doing. I would expect that an app that has repetitive audits would have resulted in this bug being fixed already.
- detaro 5y agoAt least the main audits are clearly described as auditing internal components, so it's not surprising app-level errors aren't covered by them.
- colesantiago 5y ago
- alerighi 5y agoAnd they say that I don't value privacy since I use Telegram and not Signal... in reality Telegram may not be end to end encrypted like Signal, but I never recall doing a think like that. It means poor attention to the security of the application, and poor testing.
- maqp 5y agoSo let me see if I got this straight... You will never use an app that HAD 0.000000001% chance of outputting a file on your phone to wrong peer over 100% end-to-end encrypted channel... but... You knowingly use an app that leaks 100% of your group chats, including attachments, 100% of your 1:1 desktop messages to the service provider, who can be bought, or hacked at any time without you (or them) knowing, and that doesn't provide any kind of active protection mechanism against similar bugs than this one... ...on the grounds... ...that such bug hasn't happened, yet? Is that what I'm reading?
- MacD83 5y agoI'm rooting for Delta Chat [1] which puts a nice chat UI on top of email. It is such a brilliant and simple solution. It is decentralized unlike Signal which recently had big reliability problems when new users flooded in. [1] https://delta.chat https://delta.chat
- sschueller 5y agoIsn't this going to pollute my mail server with thousands of individual chat "emails" instead of a few large emails?
- detaro 5y agoDealing with thousands of messages in a folder somewhere is not really problem for mail servers.
- deleted 5y ago[deleted]
- spinax 5y agoI had to dig a little bit to get a better view of "will this make a mess of my email if I try/test it without commitment?"; the tl;dr is basically: (a) there is a DeltaChat subfolder in your IMAP storing the messages; (b) the app looks for a "Chat-Version" header on emails to know to move it to (a) folder (and you can set a server side rule to also do that); (c) a number of popular email providers (IMAP is used) are listed with some notes to help you get started: https://providers.delta.chat/; https://providers.delta.chat/; and (d) it's using the Autocrypt/PGP standards and you can apparently import your existing PGP key if you want It's all in the FAQ or other docs, just highlighting the things which I wanted to know straightaway before making a mess by accident just to give it a try.
- Forbo 5y agoWhich unfortunately suffers from the same metadata leaks as email.
- Sytten 5y agoI like signal but having to explain to my parents why they cant use it on their android tablet or that they cant register without a phone number makes me reconsider if I should just use another software.
- 63 5y agoSeveral years ago I had this same issue occur in Facebook Messenger. I was using a pretty slow outdated device even for the time. I went to take a picture to send with the in-app camera. I actually pressed send before the picture rendered on my screen and somehow what was sent was not the picture I took, but a picture of some man's forehead who neither of us had ever seen before. It seemed like a pretty huge bug that could be a serious problem if anyone could reliably recreate it, which I could not. I went about trying to report it but ran into so many problems and broken links searching for Facebook's bug reporting that I gave up. Here's hoping it's been fixed, though I haven't used Messenger for at least a few years now anyway.
- wizzwizz4 5y agohttps://news.ycombinator.com/item?id=27951529 https://news.ycombinator.com/item?id=27951529 appears to be the same bug.
- proactivesvcs 5y agoIt also happened to Skype around 2011ish. IIRC it was so frequent that I simply stopped using the software until a fix was released.
- mackrevinack 5y agoso that's where the picture of my forehead went to. give it back!
- MrAwesome 5y agoSeveral years ago, when I worked at FB, I ran into a similar bug on an early internal version of a Messenger rewrite. Sent pictures to one chat, showed up in another. My bug report on it kicked off an absolute maelstrom of dev activity and investigation. High level engineers showed up in the comments. Lots of immediate followup. The severity was clearly understood and resolving it was clearly prioritized. I exclusively use Signal now, but the discrepancy between what I see here and what I saw there is pretty disheartening. This kind of bug is not only a massive privacy risk, but it also massively erodes user confidence and trust.
- godelski 5y agoI don't think Signal has many devs[0] and if you look at the contributors[1] you can see that Grayson is pretty much the only dev for the Android app. So seeing a second dev get involved is probably them freaking out. [0] Personally I believe this is a big bump in the road for Signal and is why a lot of people are frustrated. About promises about things like usernames (it is no longer early 2021), channels, and everything else. A few devs can only do so much. A dozen (maybe 2 dozen?) devs can still only do so much. How do you compete with other platforms like Telegram that has hundreds of employees or WhatsApp with far more than that? [1] https://github.com/signalapp/Signal-Android/graphs/contributors https://github.com/signalapp/Signal-Android/graphs/contribut...
- woxko 5y agoBug report is eight months old now. I don't think they're freaking out much.
- godelski 5y agoBut the issue is fixed. Forgetting to close a bug report is different than not fixing the bug
- jeroenhd 5y agoTrue, but the issue was fixed in 5.17, which was released only 10 days ago [1]. For an issue opened December last year, that's still quite a lot of time before a fix could be found. [1] https://github.com/signalapp/Signal-Android/commit/a47448b6c6c26a0d7f7156ce54eeaf2a6a34ed5d https://github.com/signalapp/Signal-Android/commit/a47448b6c...
- jayavanth 5y agoFixed: https://github.com/signalapp/Signal-Android/issues/10247#issuecomment-886239978 https://github.com/signalapp/Signal-Android/issues/10247#iss...
- lwhi 5y agoLooks like this was fixed [1]. Doesn't fill me with confidence if this type of issue can occur though. [1] https://github.com/signalapp/Signal-Android/issues/10247#issuecomment-886239978 https://github.com/signalapp/Signal-Android/issues/10247#iss...
- muststopmyths 5y agoWell, from a glass half-full perspective this provides a user with perfect plausible deniability about any illegal content found on Signal on their phone, or a message claiming to be from them to another user. Maybe it's a feature, not a bug ? :)
- tag2103 5y agoFixed on 7/21. Forgot to close the issue: https://github.com/signalapp/Signal-Android/issues/10247 https://github.com/signalapp/Signal-Android/issues/10247
- beermonster 5y agoFixed in 5.17, though I only have 5.16.1 available to me despite the fact it’s supposed to be available from a few days ago.
- kiwijamo 5y agoMy Android phone has 5.17.3. What platform are you on?
- beermonster 5y agoiOS
- proactivesvcs 5y agoThis bug seems to only have affected Android. 5.17 is still in beta for iOS.
- beermonster 5y agoThanks for the clarification:-)
- greysonp 5y agoHi there, Signal-Android developer here. I updated the issue to reflect this, but this bug has been fixed. I was tracking it on a separate issue, and had forgotten to close this one. We do, in fact, take issues like this very seriously. This bug was extraordinarily rare, and because we have no metrics/remote log collection, there was an initial period where we had to spend time adding logging and collecting user-submitted logs to try to track it down. As soon as we were able to pick up a scent, it was all we worked on, and we were able to get a fix out very quickly.
- TekMol 5y agoCan you provide a link to the commit that fixes it? Shouldn't there have been an announcement to inform users what has been leaked and under which circumstances? How can user A send an image to user B that neither of them took? Isn't everything end-2-end encrypted? Then how can unencrypted data from user C end up on the device of user B?
- agilob 5y agoNo PR with name that would suggest the fix in the client https://github.com/signalapp/Signal-Android/pulls?q=is%3Apr+author%3Agreyson-signal+is%3Aclosed https://github.com/signalapp/Signal-Android/pulls?q=is%3Apr+... and no PR from OP in the opensource part of the server https://github.com/signalapp/Signal-Server/pulls?q=is%3Apr+is%3Aclosed+author%3Agreyson-signal https://github.com/signalapp/Signal-Server/pulls?q=is%3Apr+i...
- deleted 5y ago[deleted]
- seg_lol 5y ago*edit, I think this issue was specific to the Android client, the desktop client has a totally different sqlite schema. The child comment to your comment is deleted, but I think autoincrement IDs shouldn't be used under an ambient authority context. It would make more sense to have IDs based on an LSF or Feistel sequence, perhaps split into a master ID and a conversation sequence. Autoincrement on this field makes it easy for off by one errors. Even just moving to guids and maintaining a proper parent child relationship would have prevented this. Or maybe there should be a database per conversation (set of all parties). https://github.com/signalapp/Signal-Android/commit/83086a5a2b8cae3ac40dea75d8c9533457a31858 https://github.com/signalapp/Signal-Android/commit/83086a5a2... https://github.com/signalapp/Signal-Android/commit/b9657208fea1c7bcfb90b7400037a7858ba56516 https://github.com/signalapp/Signal-Android/commit/b9657208f... Row IDs shouldn't have so much power.
- hrjfjjfjfjd 5y agoHow can an unencrypted copy of some media end up at the wrong user? Isn't that supposed to be end-to-end encrypted, especially when stored on the signal servers?
- jeroenhd 5y agoThe chat client misinterprets something and attaches a file to the message. The encryption works fine, the business logic of the app failed. E2EE won't protect you from a client accidentally encrypting and submitting files in the wrong chats.
- hrjfjjfjfjd 5y agoBut what exactly went wrong with signal here? Could someone remotely instruct my signal client to share media? Previously sent or arbitrary files?
- jeroenhd 5y agoThe app accidentally attached seemingly random media to messages. The other end has no control over what images they receive when. There was no hack or remote control at play, just a bug.
- maqp 5y agoThey would have to compromise your client which is in no way different from compromising your device. The NSO / Pegasus systems do just that. They allow arbitrary command execution, which includes sending any file on your phone to any contact over Signal. Nothing software can do to protect from that. If you need 100% guarantee something doesn't leak over electronics, don't store it electronically. Ask them Slavs https://www.theguardian.com/world/2013/jul/11/russia-reverts-paper-nsa-leaks https://www.theguardian.com/world/2013/jul/11/russia-reverts...
- drexlspivey 5y agoIt was a bug on the client that encrypted and sent the message to the wrong user. If it was a bug in the server that messed up the routing it would be impossible for the wrong recipient to see the message.
- maltalex 5y agoI love Signal and have advocated for its use. But I have to say that this issue is trust-breaking. I lovingly forgive the occasional bug or unpolished feature and I understand that the team behind Signal are human and that programming is hard. But sending messages to the wrong people is very high on the list of things a messenger should never ever ever do! Having an issue like this remain open for 7.5 months hints at a systemic issue, which is probably be related to Signal being underfunded/understaffed. But regardless of the reason and of everyone's good intentions, the fact remains that similar issues can and probably will happen again, and may again take months to fix.
- godelski 5y agoFWIW the problem did not remain open for 7.5 months (GitHub issue did, but not the problem). The dev is in the thread and explains.
- detaro 5y agoBug reported 2020-12-04, fixed release tagged 2021-07-15 (if I'm identifying the commit correctly, same day the fix is merged, which one would hope for a high-priority bug like that). That's technically 7.3 months, not 7.5, true, but ...
- piaste 5y agoThe bugfix comments says: > The TL;DR is that if someone had conversation trimming on, it could create a rare situation where a database ID was re-used in a way that could result in this behavior. How is this bug even possible with E2E encryption? If picture.png exists on user A's phone and gets sent to user B, shouldn't it be client-side encrypted in such a way that user C, even if they receive it via some database ID screwup, are unable to view it (because it was encrypted with user B's public key)?
- okdjnfweonfe 5y agoits probably not using chat keys for the db, for the sake of being indexable
- jtbayly 5y agoBut it’s showing up on both sides of the conversation. (Both user’s devices show the same wrong unsent pic.)
- alksjdalkj 5y agoThis is a good reminder that no matter how security and privacy-focused a project is, we still don't know how to reliably develop software without bugs - and all it takes is one bug to negate all of those security and privacy features.
- yawaworht1978 5y agoDo users se wrongly sent images in outbox/sent? Did the transfer always happened immediately or with a delay? Did the transfer or chat always had to have a gif sent?
- xirtam 5y agoCan we get a better understanding of the root cause and blast radius? You say, "if someone had conversation trimming on, it could create a rare situation where a database ID was re-used in a way that could result in this behavior." Is this someone user A or user B? Where is this database and what is it storing? Are these images previously sent or received from either A or B, or are they possibly from some thread between users C and D? How does this agree with end-to-end encryption? How can you expect people to use your product with a bug this severe and no analysis of the impact or a statement as to who might have been affected?
- lopatin 5y agoI have no horse in this race. I don't use Signal or any of its competitors, so allow me to ask some basic questions. Could some users explain why you currently use Signal, and additionally, why you would continue to do so? It appears to me that not only this bug, but more importantly, the laissez-faire resolution of it is the opposite of what a privacy based app should do. Based on their homepage, it looks like they're proud of the fact that Snowden uses the app. I'm interested if he, as a person with "real shit" to hide, still does.
- ghoward 5y agoPersonally, I use it because it was the best choice a couple of years ago, and I (somewhat recently) managed to convince family to use it too. However, after this, I am probably going to set up my own Matrix server and use that as much as possible, encrypted of course.
- afroboy 5y agoI live in authoritarian country. so yeah Signal is the answer and my country does fear it and trying to block it. They don't fear whatsapp, telegram or facebook but they do fear signal. And weird this bug never encountered with me.
- deleted 5y ago[deleted]
- herpderperator 5y agoA lot of people are talking about the bug but not the fix. Is anyone else incredibly surprised that the fix was just adding auto_increment to the primary key column for two tables[0][1]? Not having these as auto_increment seems like incredible oversight to me. In what common scenario would you want a setup like that? [0] https://github.com/signalapp/Signal-Android/commit/83086a5a2b8cae3ac40dea75d8c9533457a31858 https://github.com/signalapp/Signal-Android/commit/83086a5a2... [1] https://github.com/signalapp/Signal-Android/commit/b9657208fea1c7bcfb90b7400037a7858ba56516 https://github.com/signalapp/Signal-Android/commit/b9657208f...
- eternalban 5y agoI'm not up on my signal protocol but using PGP, sending encrypted messages to the wrong person would result in them getting an encrypted message they can not decipher. If a bug in signal allows a third party to decrypt a message intended for another person, does that means that signal servers see plaintext messages?
- stereoradonc 5y agoI have had random Signal contacts and phone numbers appear in my Signal installation. It was scary to see other phone numbers mixed up. Despite all the PR they do (and paid trolls on social media websites), I still don't understand the fascination for this "non-profit" "e2ee" application. There are better options out there. Why stick with a buggy app that can't get it basics right?
- lucasyvas 5y agoAll facts aside about how it's now resolved and only surfaced using a certain setting, etc... This an absolutely horrific bug - worse than even an encryption snafu. Can you imagine depending on Signal's privacy features, possibly with your life, and encountering this bug? Fuck - this could ruin someone that hasn't even done anything wrong. If I knew this bug existed and I was on this team, I would have been in all out panic mode all these months. Literally shitting my pants.
- Causality1 5y agoOne among many reasons I use different apps for different people in my life. My partner is the only person I message on one, my friends on another, my family only over text messages, and my coworkers only over email or phone calls.
- lucasyvas 5y agoI've never thought of doing this, but I often feel a pang of uncertainty whenever I open my phone's share sheet. Like.. when I pick person A, is the app going to screw it up and send it to person B somehow? I honestly have nothing life ruining going on, but huge embarrassment sometimes if a mistake were made? Definitely. This bug is a worst fear realized.
- Causality1 5y agoI also make sure that if I'm using a platform with more than one person each contact must be visually distinct. For example, all my friends are on WhatsApp and they each have their own chat background image. You can't slip up that way.
- callemnotme 5y agoLooking at the comments here, the amount of badmouthing signal for arguments sake feels suspiciously like some organizations' motives.
- nazrulmum10 5y agoCan you explain exactly how auto-incrementing IDs were the crux here? Were they overflow-wrapping or did the tables forget to actually use them?
- andrewalan 5y agoHi i must confess i am one of the best hacker who can help track cheating spouse , you don't have to stress yourself anymore, if you have the strange feelings your spouse is cheating on you, check us out at andrewalangeekbup.com or text/whatsapp +1-559-634-0249