6 ms·
Given that Signal is pushing new code updates all the time, isn't it trivial for them to push new binaries that harvest messages/keys/whatever-they-want?
by romaaeterna 1y ago
Given that Signal is pushing new code updates all the time, isn't it trivial for them to push new binaries that harvest messages/keys/whatever-they-want?
- yifanl 1y agoSure. If you don't trust Signal to not do that, then you likely aren't using Signal.
- JustFinishedBSG 1y agoYes but an app that never pushes update can also do that
- thrance 1y agoSignal is open-source [1]. You can compile the code yourself and review each PR if you're that paranoid. [1] https://github.com/signalapp/Signal-Android https://github.com/signalapp/Signal-Android
- Pesthuf 1y agoLooks like the build is even reproducible. That makes me trust Signal even more. https://github.com/signalapp/Signal-Android/blob/main/reproducible-builds/README.md https://github.com/signalapp/Signal-Android/blob/main/reprod...
- paxys 1y agoTheir client is open source and is routinely audited. Their Android builds are fully reproducible. You can also build and run the app yourself if you want instead of downloading it from the app stores. It is virtually impossible for them to ship a backdoor, at least on Android, without the security community noticing.
- romaaeterna 1y agoWhat exactly prevents them from doing a Windows build with an non-published change, signing it with the keys they control, and pushing it to an individual client through the upgrade servers which they control?
- deleted 1y ago[deleted]
- tabletcorry 1y agoDesktop clients communicate through mobile clients, so they don't have access to the key material.
- romaaeterna 1y agoI don't believe that is the case. You can turn your phone off and the Signal desktop client will continue to work just fine.
- VWWHFSfQ 1y ago> It is virtually impossible for them to ship a backdoor [..] without the security community noticing. OpenSSH was trivially backdoor'd [1] and distributed in several major distributions and the security community _did not_ notice until after it was already wild. [1] https://www.ssh.com/blog/a-recap-of-the-openssh-and-xz-liblzma-incident https://www.ssh.com/blog/a-recap-of-the-openssh-and-xz-liblz...
- xmodem 1y agoThat was an attack targeting an optional dependency that receives significantly less scrutiny than OpenSSH proper. Which to be fair, is probably also the most plausible path if you wanted to attack Signal. I would quibble with calling it "trivial" though.
- qualeed 1y ago1) That was not "trivial", by any stretch of the definition. It was a 3-year long campaign by a (suspected to be) nation-state (or similarly resourced) actor! I don't think you can get any farther away from "trivial" if you tried. 2) From your link, it says: "Ubuntu 24.04LTS was a month away from being shipped with this backdoor, with other distros being on the same boat. Maybe the best way to describe it is this: had it gone undetected, Linux servers would have been running with a bomb waiting to be activated remotely." and "Luckily this backdoor was discovered in an early stage, and most of the Linux user community stays safe" So, the security community _did_ notice.
- e44858 1y agoHow easy would it be for them to ship a backdoor on iOS? With Apple's DRM it should be difficult to decrypt the IPA and compare it to the source code.
- paxys 1y agoIf you are in the EU you can build the app from source and sideload it on your phone. Everyone else is out of luck. So yeah, either Signal or Apple can insert a backdoor into the app.
- maqp 1y agoIf your HW/OS doesn't allow verification of binaries, but your threat model requires doing that, then you need to use proper HW/OS that allows the verification. Also, iOS is proprietary so who knows what the OS is doing anyway. Also, this https://thehackernews.com/2014/01/DROPOUTJEEP-NSA-Apple-iPhone-hacking-tool.html https://thehackernews.com/2014/01/DROPOUTJEEP-NSA-Apple-iPho...
- dingaling 1y agoThere is a window of vulnerability between a theoretically malicious update being pushed and the security community noticing that it doesn't correspond to a build of the published source. That might only be a few hours, or even minutes - but milliseconds would be enough to do most of its work.
- paxys 1y agoSure, but only if you are blindly auto installing every update as soon as it is pushed. All you have to do to protect yourself is download the bundle, run a checksum and then install it.
- perching_aix 1y agoThen you audit and build it on your own? Or implement your own client? No free lunch. If comms security is that critical for you, outsourcing its assurance via trust is never going to cut it.
- romaaeterna 1y agoThey control the update servers. So it's possible to target a single user with a single build that no one else ever sees. What percentage of users verify every release?
- comex 1y agoIn theory, Binary Transparency (https://binary.transparency.dev/ https://binary.transparency.dev/) solves that among other things. To pass verification, an update has to prove that it's included in a public log of releases. But I guess Signal doesn't implement it?
- NoThisIsMe 1y agoIt's distributed in the Play Store, so Google controls the update servers, no? Edit: or Apple, whathaveyou
- jzb 1y agoCorrect me if I'm wrong here -- let's say the Signal folks are breached or have been secretly waiting for just the right moment to push out some malicious code. How would they coordinate rolling it out to client devices to take advantage of that gap? I mean, depending on what the exploit was, they might be able to whack some percentage of users -- but it would be caught fairly quickly. I'm curious what sort of attack you're theorizing that would be worthwhile here.
- deleted 1y ago[deleted]
- regularjack 1y agoWhich one do you trust more?