47 ms·
Signal is secure, as proven by hackers
- tppol 4y agoDoes anyone know why Signal has decided to not let people sign up without a phone number? That would avoid any such vector relating to SMS, albeit at the expense of making it more difficult to recover an account from a new device.
- palata 4y agoThe problem is the social graph. You need to know the ID of all your contacts at some point, right? Either that's stored on the server (e.g. your Facebook friends), but then the server has access to it, or it's stored locally in your app, but if you lose your phone then you lose your graph. Signal has been working on a way to store your graph securely on their servers, but it's hard, and not there yet. The great point about your contact list is that it is decentralised, and it exists already (so you don't have to exchange an ID with all your friends manually).
- Snitch-Thursday 4y agoIt feels like everyone keeps repeating the same dialog tree that 'but thou must store their contacts list' and I don't see why. Solution? Store your contacts list on your device. Back it up with your offline chat backups (android does external chat backups now, IOS should be enabled plus give em icloud backups to boot). with a new signal app on a new phone, you restore your chat backups and poof your contacts list gets loaded back. your new signal instance reconnects with the other clients and poof, Signal's excuse for using phone numbers and storing your contacts list on their servers is demolished. It seems so simple to me, but I feel like I'm failing to understand something about why this is so hard.
- palata 4y agoBecause you forget that you need to build your contact list (if you don't use the phone numbers), which for 99% of users (including me) is a major pain. Then your backup idea works, but kind of sucks in terms of UX (at least in Signal's point of view), and therefore they decided to go with phone number first, and work on going towards usernames later. Don't worry, you haven't invented anything. It's just that your idea is not at the level of UX provided by WhatsApp/Signal, and the solution is more complex than you think.
- ysnp 4y agoThey have mentioned a few times that it is to reduce spam. See: https://github.com/signalapp/Signal-Desktop/issues/2383#issuecomment-758085898 https://github.com/signalapp/Signal-Desktop/issues/2383#issu... and in this paywalled article https://www.sueddeutsche.de/wirtschaft/signal-meredith-whittaker-whatsapp-messenger-datenschutz-1.5652005 https://www.sueddeutsche.de/wirtschaft/signal-meredith-whitt... where they roughly say >We are currently working with high priority on the fact that you can assign usernames and hide your mobile number. However, it will still be necessary in order to register. There are several reasons for this, including the fight against spam.
- aliqot 4y ago"secure" is not a binary state. Title is low-brow and weak. "secure from a small group of specific hackers" is not as catchy though.
- Nagyman 4y agoThis "article" was written to subtlety advertise Kaspersky's security app. > And, of course, install a security app on your smartphone.
- quyleanh 4y agoI would like to have a deep analysis about Telegram. The founder Durov always says like Telegram is secure and it encrypt the message while it's not.
- lijogdfljk 4y agoWhen using encrypted chats is it not secure? I thought the biggest problem is that we simply don't know - but your comment seems to suggest it's been proven insecure even when using encrypted chats?
- palata 4y agoThe problem is that people misunderstand the security model in Telegram, and believe that it's e2ee. Except that most features are not, only secret chats are e2ee, and people mostly don't use those (because the whole point of Telegram is the nice group features).
- lloeki 4y ago> only secret chats are e2ee IIRC audio and video calls are E2EE as well (in addition, the four emoji that appear on a call allows both parties to check that no one is eavesdropping)
- palata 4y agoThat's not an addition: e2ee requires a way to verify keys. Without that it's not proper e2ee.
- orangepurple 4y agoThe main reason to not use e2ee is being able to access, send, and receive messages concurrently on multiple computers at the same time.
- palata 4y agoYes, and that's a choice. You can choose UX (Telegram) over privacy (Signal), and I am fine with it. Just don't pretend that Telegram is private.
- nalaz 4y ago
- coretx 4y ago
- jandrese 4y agoFor that matter how can you have any assurance of security on a device with an opaque binary blob running underneath the OS? If you are paranoid enough nothing is secure.
- palata 4y agoThis. You have to trust something at some point. What you trust just depends on your threat model.
- MichaelCollins 4y ago> You have to trust something at some point. No, you can instead acknowledge that you can't trust any of it and behave accordingly. You don't have to settle on trusting something.
- palata 4y agoNot sure what your point is. You're saying that you can live without trusting anything at all? Say you don't trust that absorbing any kind of liquid is safe, how do you survive more than a few days? Do you prove it first? Based on what, if you don't trust anything? Trust is all around us, we constantly choose to trust (or not) things.
- jandrese 4y agoThis is not a new issue. Philosophers have pondered for centuries about the possibility of a godlike deceiver that is constantly fooling your senses. How can you be sure you aren't plugged into the Matrix right now? Even worse, their arguments against said deceiver are weak, some saying that your own eyeballs can be ultimately trusted, others suggesting that since God is good he wouldn't let it happen. Ultimately you have to trust in something or it is literally impossible to function. Even if that trust is only in your own senses. In practical terms you have to trust a lot more to function in society. Maybe a good first pass is to trust in things that most other people trust in, so that if there is a deceiver there will be a lot of other people mad with you and a greater chance of not only punishing the deceiver, but detecting them in the first place. You can't fool all of the people all of the time.
- scifibestfi 4y ago> By using end-to-end encryption, user messages are stored only on their devices, not on Signal’s servers or anywhere else. How do we know with certainty that the messages are not stored anywhere else? Don't they go through servers to get to the end user?
- EGreg 4y agoSince you aren’t installing something that can be checked against an audited open source build, you always have to TRUST the publisher of the software. You just take their word for it. They could always phone home any kind of data using steganography! I replied to Moxie’s opposition to decentralized open source software, with arguments like this.
- jrm4 4y agoI'm 100% in agreement that we should see the source, but it seems to me there could be a "black boxy" way to check for this? As in set up e.g. an emulator and sniff all traffic in and out?
- palata 4y agoThere is always trust involved. The question is: what's your threat model? You can compile Signal yourself, but maybe you don't trust your OS, or your hardware, or your cleaning lady, or your wife. Signal cannot do anything if your phone got compromised by Pegasus, but they never claimed they could. That's exactly equivalent with decentralised software.
- tialaramex 4y agoBecause this is end-to-end encryption, what's transmitted is only arguably "the message", we can't - and there is every reason to think never will be able to - decrypt it without the symmetric key and only the sender and recipient have the key. So from an information theoretic point of view, arguably no, the message was never stored anywhere else, even though Signal is indeed a store-and-retrieve arrangement. The encrypted message was stored briefly by Signal, but only its sender and intended recipient could decrypt it. The keys are ephemeral, so if you have exactly bit-for-bit copies of encrypted Signal messages I sent when I was arranging to play Red Dead Redemption 2 with friends, nobody knows how to decrypt those. I can't decrypt them, the people who received them can't decrypt it, even though we saw them at the time, and even though you have the encrypted messages and even if you have our phones, the keys are gone so that's that.
- throwaway0x7E6 4y ago>As such, the cybercriminals managed to pull off the attack by impersonating the victim of the attack for roughly 13 hours. If Registration Lock had been enabled, they could not have logged in to the app knowing only the phone number and verification code. and if Signal did not require a phone number, this wouldn't have happened at all
- dorfsmay 4y agoThat's my biggest issue with signal.
- tptacek 4y agoMaybe not, but Signal would be vulnerable to a much bigger problem: its server would, like other secure messengers, end up keeping an effectively plaintext database of every pair of users that communicates.
- verdverm 4y agoOr they could create a phone number like id that you then share with others, like a phone number. They would not need to store this
- tptacek 4y agoThat only works if you don't care whether anyone actually uses your messenger. In the real world, people will only adopt a messenger that remembers their contact list across multiple devices.
- palata 4y agoThey thought about that, but it's harder than you think. They even explain why on their blog.
- paranoidrobot 4y agoI don't see how that would follow? Lets assume that today that Signal is able to deliver messages securely between users, without maintaining a plaintext association between sender and receiver's phone numbers. Why would switching identifiers from phone numbers to some other identifier require that they change how that works? (Other than the obvious 'substitute out a phone number for some other identifier' thing)
- AtNightWeCode 4y ago"And second, the numbers themselves aren’t stored there in plain text, but rather in the form of a hash code." Very strange. There is no additional security by hashing phone numbers. Not that I trust anything form this source but anyway.
- permo-w 4y agoit seems like there very obviously is additional security in that
- dotancohen 4y agoNot at all. The numeral-only search space is too small, the rainbow table fits on an inexpensive thumb drive.
- permo-w 4y agoit’s still useful if you use a private hashing algorithm
- AtNightWeCode 4y ago> However the data is stored, first, in special storages called secure enclaves, which even Signal developers can’t access. And second, the numbers themselves aren’t stored there in plain text, but rather in the form of a hash code. I was out of context. You can use salt, pepper or both but if these attacks are done buy Signal developers it would most likely be easy to crack the hashes. In the case of a data leak it can help depending on how difficult it is to figure out how the hashing works.
- palata 4y agoWrong. That's exactly the point of the secure enclave.
- AtNightWeCode 4y ago
- rconti 4y agoIf only Signal found a way to keep the desktop app linked for more than 30 days. There have been a series of FRs that constantly get ignored and "you're using it wrong" from the developers. Thankfully the one friend that was using Signal finally gave up on it since everybody else was always missing his messages, so I no longer have to re-link every single computer every time I use the app. (with a 30 day expiry and 3 computers, it meant virtually 100% of the time I tried to use the desktop app I had to relink to my phone).
- hcurtiss 4y agoWhat OS? I've used the Signal desktop app on Windows paired to iOS for more than a year and have never once had to re-link.
- cassianoleal 4y agoSame on macOS + iOS. Years, in fact. Not once I had to re-link.
- artificialLimbs 4y agoI last used Signal desktop on Windows with Android a couple years ago for several months and never had to re-link.
- barbazoo 4y agoIt's quite common on a Windows machine in our house. Not sure which version.
- TheCapeGreek 4y agoI've had Signal on a Win11 machine for about 4 months now and haven't had this come up.
- dunefox 4y agoI, however, get this regularly.
- ufmace 4y agoThe weird part about this - why does Signal let anybody access the same account with just a SMS verification? I would think it would be better to send the verification message to be added to an account through their Signal account. Telegram does this already.
- cesarb 4y agoThere will always be a tension between security and usability. A common situation is when a phone stops working (for instance, it fell into a puddle) or is lost or stolen. If it stops working, you can just pop the SIM and put it on a new phone (assuming the new phone accepts SIM cards of the same size, instead of requiring an even smaller one); if it's lost (or your SIM card is too big for the new phone), you can go to one of the phone company's stores, present your identity card, and get a new SIM card associated with the same phone number. Either way, you don't have access to the Signal account anymore, since it was on the broken/lost/stolen phone; the SMS verification (plus the optional password) is the only way to recover it.
- ufmace 4y agoI thought about that, and I'm not sure it actually changes anything. So you want to register a new device with your Signal account and you don't have the previous device, either because you're a malicious attacker or you lost or destroyed it. Covering the attacker case, presumably you already can't access the message history. I don't see how you could reasonably do anything different for the lost device case, but I guess it's not that big a deal to lose message history. But if the message history is already gone either way, why not make it a entirely new and separate account?
- palata 4y agoBecause of their threat model. Signal has very good e2e encryption, but somebody could take over the account over SMS (note: they would not access any encrypted message, and that would reset the key so the contacts would know that a change happened and could verify the key if it matters for them). Telegram, on the other hand, is mostly not e2e encrypted, so their cloud can read all of your messages. Pick your favourite.
- behnamoh 4y agoYou can't prove that something is secure by "hackers". You can only prove it's not secure.
- O__________O 4y agoIf Signal is secure really depends on your threat model. While they never classified them as data breaches, they had all the numbers in their system extracted number of times. If someone was using a real phone number, even if Signal was secure — just knowing the number alone would give an attacker addition information. When Moxie was in charge, he repeatedly refused to allow new users to signup without phone, even though in there numerous ways this could have been done and are being done by their competition. Lastly, all three Signal board members have held the top leadership role in past year, which is highly unusual, in fact, never heard of anything like it.
- tptacek 4y agoSignal's non-phone-number-keeping competition keeps a plaintext database of every pair of users that has ever communicated. The reason Signal uses phone numbers is the same as it has always been: to avoid having that database at all, or features that depend on it.
- cosentiyes 4y agoWhat features depend on the use of a phone number? Sign up and contact discovery? I don’t understand why a plaintext database is the alternative.
- tptacek 4y agoYour Signal contact list is your device's contact list, keyed by phone numbers.
- O__________O 4y agoFor clarity, this assumes you allow Signal access to the device’s contact list, which is not required.
- palata 4y agoFor clarity, you allow the open source client app (which you can audit and compile yourself) to securely share your contact list with a secure enclave (which is open source so you can audit it as well).
- bArray 4y agoSurviving one attack != secure
- stiray 4y agoWhatever the security of Signal is, all my trust into any service ends when it requires from me personally identifiable information, which could be easely replaced by other methods (I am system software developer for ~31 years, don't even try to feed me with bs). And as such, Signal/Telegram/Whatever that requires me to enter phone number, has zero trust from me. I don't care who analyzed the protocols security, what the safety measures are, what cipher algorithms you use, how many hackers tried to break in and failed, what other PR/SEO methods you use. Just the fact, that you require information that is so deeply PII as phone number is a reason that overrides everything else. From my standpoint, software that requires that, is honeypot. (btw, this is my personal opinion, you don't have to agree - I can (from any device, without giving any PII, now or 20 years in past) login into IRC network (vpn/... is outside this topic) and use asymmetric cryptography (with exchanging public key safely by some other method, stenography anyone?) to chat completely secure. I can send email (with exchanging public key safely by some other method, stenography anyone?) and communicate completely secure. I can use Counterstrike chat on random server to do the same. So what does the Signal does for me in terms of safety of exchanged information? Show me a nicer UI so I can use graphic smileys?)
- malikNF 4y agoThe argument I hear in favour of this practice by messaging apps is that, this design helps your friends find you easily by your number. But I agree with you, asking for the phone number and telling me this app is secure is ridiculous. Let me register with something less intrusive, if I want to go the phone number way, then let me use that. Give me an option.
- palata 4y agoNot ridiculous at all, depends on your threat model. It's perfect for me.
- malikNF 4y agoSo why do we need e2e encrypted messaging? Why do we worry about the "secure" part of messaging? One of the main reasons for me is, it's hard to trust a centralized authority. Can you trust your information stored at your messaging app's servers stay secure forever? Can you trust that company to never get compromised? So yeh, they go through all the hassle of making things "secure" but attach everything to something(phone number) most of us can't get without revealing our actual details. So yeh, its ridiculous to go through all this hassle to make things private and secure, but force people to use something that de-anonymizes everything about them.
- cesarb 4y agoI don't see it mentioned in the article (though I might have missed it), but: > As such, the cybercriminals managed to pull off the attack by impersonating the victim of the attack for roughly 13 hours. All the contacts of that victim would have received a warning that the victim had changed their encryption keys (WhatsApp has that warning too, but unlike Signal it's disabled by default), and IIRC, that warning shows up before you try to send a message. Even if they're not the kind of people who checks whether the encryption keys match (it's very easy to do if you're meeting in person, but not many people do), that warning can be enough to alert the contact that something odd is going on.
- s_ting765 4y agoThis old article only proves how vulnerable Signal is by relying on the security (or lack thereof) of other 3rd party service providers. The phone number requirement should be removed if Signal wants to be taken seriously. Maybe the next hit might affect more users than 1900 people.
- upofadown 4y agoAs I am fond of saying: identity is the issue with end to end encrypted messaging. So this is interesting in that it is a direct attack on the weakness of using access to a phone number as proof of identity.
- deleted 4y ago[deleted]
- newscracker 4y ago> And although the attack was formally a success, there is no reason to get scared and stop using Signal. This conclusion — “no reason to…” — sounds strange and premature. Such attacks may not get older messages, but contacts of the person whose phone number has been used can still message the new device, which the hacker would get and could launch further attacks on the contacts. Since practically almost nobody verifies “safety number” changes, the contacts of the phone number that has been taken over may not realize they’re chatting with someone else. Isn’t that reason enough to be scared? This problem exists for any app that relies on an external identifier, especially one like a phone number that’s easier to take over (including through SIM jacking). Signal may be secure for specific definitions, but your contacts may not be safe with such takeovers.
- antman 4y agoI just want to backup my Signal online a rar and a pass, easy to restore in another phone or manually, without the rest of the joke steps. Using PII which is also a joke, “secure” implies “private” also, else it is just “encrypted”. When someone knocks on your door in a Ukrainian or African or … village and asks for the pass, you give it. The non private money sending also a joke of privacy. A monero-like solution would be good enough. Less features than whatsup or viber or telegram so why bother? It is really easy to copy each others’ features, but each app’s developers think that they are the smartest people in the room.
- merely-unlikely 4y agoSignal imo should secure its desktop apps better. The sqlite database of messages is stored right next to the json file containing the encryption key. Admittedly you would have to get access to the hard drive before reading it and I'm not sure other messaging apps do any better, but still an attack surface left open. This also means you can't trust disappearing messages. It's better than not having the feature. But it's trivial to setup an auto-archiving script on all incoming messages.
- tomjakubowski 4y agoI don't think there is any defense against archiving disappearing messages - someone can always take a picture of the screen.
- 2-718-281-828 4y agoHere's one major problem with Signal - you cannot delete contacts. Following scenario: 1) X communicates with Y using Signal trying to hide from Iranian police 2) Y is getting arrested and who ever is found to have his phone number is getting in to trouble as well 3) X deletes Y from its contacts 4) Y stays in X's contacts on Signal no matter what now what should X do? delete Signal? theoretically the police could reinstall it and see who you had in your contacts. There have been several issues opened for this problem on GitHub for years. They all get closed by their bot after couple of weeks. I have several ghost numbers and even ghost user names on my Signal clients. Super annoying and cluttering my list of contacts. For me Signal is just one option to avoid WhatsApp. But boy do I prefer Telegram ...
- egberts1 4y agoSignal contact ≠ Phone contact address book. By disabling Signal’s access to phone contact address book, Signal server would not have a hash value of each and every (10,000+) phone numbers in your phone’s contact address book. This disabling comes with small costs of: - being notified that someone in your phone’s contact address book has just recently signed up with Signal. (Pop your finger from your mouth) - of ease of NEW lookups of a friend using your expansive 10,000+ contact address book that your phone maintains. Ummm, your focus is the secured messaging with just the targeted friends of yours, and not one of your crazed ex-girlfriend nor deranged boss. You still have a separate but more secured form of a contact address book maintained by Signal (and yes, remote Signal server has a hash value of these smaller but limited set of Signal-capable phone numbers of your friends). The key thing is no one else can see the content of your messaging … over Signal … except who you converse with … by Signal app, unless your phone ends up in the hand of a digital forensic guy before you did the steps of doing “Settings->Account->Delete Account”. On a separate topic, you should refrain from using Avatar and discourage your friends from doing so. That’s an out-of-band lookup that is available for nation-state or hacker to profile further with.
- stereoradonc 4y agoMisleading title. There was no "hack of Signal" but the authentication services, instead.
- vlovich123 4y agoSomething I’ve been hearing about on podcasts is how the Jan 6 insurrection trials has a bunch of Signal messages in evidence. Does anyone know how these were obtained?
- hn_go_brrrrr 4y agoThey took them from someone's phone.
- vlovich123 4y agoSure, but phones are themselves encrypted. Did they brute force access to the phones or did the people give up the messages voluntarily?
- O__________O 4y agoLast I checked, beyond the phones, iCloud backups are subject to warrants and not encrypted or are local backups encrypted. If you get an unencrypted Signal backup, possible to extract the user’s Signal encryption key and rebuild the backups to extract the messages. Phones themselves are as secure as know vulnerabilities of whatever version of the phone hardware and OS version.
- YeBanKo 4y agoImo Signal never actually transition from a protocol for secure messaging into an actual secure messaging app.
- rini17 4y agoHow comes the linux desktop client of signal is such a bloated mess, which can't be used standalone but only via phone app?
- alfnor 4y agoSignal alternatives that are open source and cross-platform (at least Android and iOS compatibility): https://jami.net/ https://jami.net/ https://berty.tech/ https://berty.tech/ https://cwtch.im/ https://cwtch.im/ https://simplex.chat/ https://simplex.chat/ https://status.im/ https://status.im/