4 ms·
Is your claim that this is currently happening? If so, why has nobody detected it? Since such code would have to be distributed to user devices, it would be det
by thecrash 3y ago
Is your claim that this is currently happening? If so, why has nobody detected it? Since such code would have to be distributed to user devices, it would be detectable.
Also, did you know that Signal is distributed through multiple channels? The iOS App Store, Google Play, F-Droid, as well as directly through Signal's website. Given this, how could they target an individual with tampered binaries in a way that they couldn't notice? Seems pretty hard to me.
- xorcist 3y agoPegasus was much, much more intrusive than a targeted payload from the Play Store and it took years before that was discovered. Note that Signal is specifically not allowed to be distributed outside of their own apk download and Google/Apple. They have made that repeatedly clear and will take measures against such distribution. Security is not a scalar. It is probably better for the mass audience but worse if your adversaries includes Google employees. Take note of your threat model. From what we know of three letter agencies, they probably won't bother. They prefer spyware-like control of the end device. That way they don't need to target the encryption of individual apps, it is far more effective to collect communications after it is decrypted and read by the target.
- nunobrito 3y agoYou are entitled to your opinion. However, looking at history you find cases that went for decades to targeted individuals/govs. For example: https://web.archive.org/web/20080202225034/http://www.inteldaily.com/?c=169&a=4686 https://web.archive.org/web/20080202225034/http://www.inteld... With the exception of F-Droid, all options you mention cooperate closely with the US security agencies. In case you were not aware, some years ago in Germany you'd see Apple and the local government sending targeted updates for OSX laptops to be tracked.