7 ms·
The paper shows that if you obtain someones password, private key, and phone number, and clone their device, you can impersonate them. They talk about "reverse-
by pjs_ 2y ago
The paper shows that if you obtain someones password, private key, and phone number, and clone their device, you can impersonate them. They talk about "reverse-engineering", but TBH I think that mostly means "reading uncommented code in a Github repo". They complain a lot about the lack of documentation in the Signal code (fair). They provide a patch of about 30 LOC which constitutes their exploit. It's basically a bunch of print statements, to print the private key and other secrets. The rest of the paper doesn't really have any technical content.
By default the cloned device will be detectable in the user's device list, but they point out that if you manage to pwn and patch the Signal server, you could plausibly remove the clone from the list.