this post was submitted on 12 Sep 2026
164 points (95.1% liked)

Technology

87980 readers
2518 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

all 49 comments
sorted by: hot top controversial new old
[–] bedwyr@piefed.ca 4 points 48 minutes ago

A problem many aren't aware of, in an area that shares telecommunications info, two people within that area can be identified by the state sending encrypted messages by seeing when one person sends and another instantly receives a message. It could be easy enough to obscure that I would think by working differing lag times in.

I think it was in the intercept a few years back. I think this is it.

https://theintercept.com/2024/05/22/whatsapp-security-vulnerability-meta-israel-palestine/

[–] evilcultist@sh.itjust.works 2 points 44 minutes ago* (last edited 43 minutes ago)

Seems like signal could send a notification 24 hours after any new device is added to remind the user that it was done. Make it so it has to be dismissed on each device so dismissing it on one doesn’t make it vanish on the rest.

[–] Zak@lemmy.world 34 points 3 hours ago

What's described in the article is the same method Russia was using to compromise Ukrainian Signal accounts. It's just phishing.

[–] homesweethomeMrL@lemmy.world 59 points 5 hours ago (1 children)

Signal failed to prevent soneone from accessing my unlocked phone and starting Signal! Everything was right there!

[–] Zarobi@aussie.zone 2 points 4 hours ago (2 children)

On iOS you can set an app to require additional credentials to open, to prevent this situation. I'd imagine Android had something similar. I did it for all my important apps, just in case. Don't want someone able to access my bank account ~~or nudes~~.

[–] Igris@feddit.org 5 points 2 hours ago

You can lock Signal. It's in it's privacy settings.

[–] BarrelAgedBoredom@lemmy.zip 1 points 3 hours ago (3 children)

Just poked around. As far as I can tell there aren't any options to require additional credentials to open an app on android. Im on a pixel 10 running android 17. However there is a locked "app drawer" that hides the apps from your home screen/ main app drawer that you need to have an additional password to access.

[–] bigmamoth@lemmy.world 7 points 2 hours ago

It s litteraly on the signal option "Require acces code to open signal"

[–] Igris@feddit.org 1 points 2 hours ago

Some Android devices has app lock build in.

[–] Zak@lemmy.world 2 points 3 hours ago (1 children)

There's Private Space, but that's not ideal for a general-purpose messaging app because notifications are suspended when the space is locked. Signal also has the option to require the same authentication method as your screen lock in order to access the app.

[–] Ludicrous0251@piefed.zip 2 points 2 hours ago

All of this is great, but there's literally nothing stopping the next article from saying "user who left their phone unlocked with signal also unlocked 'got hacked'"

[–] peopleproblems@lemmy.world 80 points 6 hours ago (1 children)

Interesting they highlight Signal again as though this is a vulnerability.

If someone else has access to a linked device... that's you fucking up access controls.

[–] skisnow@lemmy.ca 4 points 2 hours ago* (last edited 2 hours ago) (1 children)

It's a vulnerability precisely because people always swarm to defend Signal in stories like this, as though using Signal means the authorities can't read your messages. Seems like every six months there's some story involving Signal users getting hacked, and every time there's a rush of wellacshuallys explaining why it wasn't really Signal's fault. (that last one is particularly egregious because I remember people defending it as "it wasn't Signal, it was their partner who they subcontracted and gave your personal data to", which is crazy levels of mental gymnastics.)

Security is more than just encryption. If you flag something up as "hey use this if you want to hide from the Government" and have a personal phone number attached to it, that's like a red rag to a bull.

[–] peopleproblems@lemmy.world 4 points 46 minutes ago (1 children)

IT DOESN'T ADVERTISE ITSELF AS A SECURE PLATFORM!!!!!!

It says PRIVACY. If you are dancing ass naked inside your house but you have your windows open... guess what?

[–] odama626@lemmy.world 14 points 5 hours ago

Signal in this was clickbait they literally just say oh well if someone can link in their device they can see 45 days of message history

[–] SnotFlickerman@lemmy.blahaj.zone 66 points 8 hours ago (2 children)

Open source FIDO2 keys, KeePassXC, and Aegis.

SMS 2fa has always been a bad deal

[–] urushitan@kakera.kintsugi.moe 5 points 3 hours ago* (last edited 3 hours ago) (2 children)

Signal doesn’t offer anything except sms 2fa and requires a phone number. It’s a terrible choice considering LEO can do what they did here and just get legal access to MITM your sms messages, spoof the 2fa, and take over your account, impersonating you. The other ones aren’t encrypted. So none of these they broke into are great choices for truly secure messaging.

[–] jungle@lemmy.world 1 points 13 minutes ago

The other ones aren’t encrypted.

Whatsapp is encrypted as far as I know. But then again, it's Meta, so my trust in that is near zero.

[–] Zak@lemmy.world 4 points 3 hours ago

They can only impersonate you that way if your contacts dismiss the warning about your safety number changing. If you're being directly targeted by the government of a wealthy country, using a specific app isn't enough to prevent surveillance; you'll need some actual opsec.

[–] Brewchin@lemmy.world 37 points 8 hours ago (1 children)

I'll never understand why people accept SMS 2FA as any kind of security. Might as well put it as an ad in a newspaper. 🤦🏻‍♂️

[–] Crumpled6273@lemmy.ca 35 points 7 hours ago* (last edited 7 hours ago) (2 children)

Because many services only have SMS as 2FA option. Especially government services.

Also it is impossible to use google without enabling the SMS 2FA option. No matter what, with only 2FA authenticator app or email, they will lock down the account by saying "unable to verify".

[–] Yaky@slrpnk.net 3 points 5 hours ago (1 children)

You can have a Google account without 2FA, but you need to create it using a factory-reset old Android phone (Android 8 or so).

[–] Imgonnatrythis@sh.itjust.works 2 points 4 hours ago

Why are people even complaining about this then?!

[–] cmnybo@discuss.tchncs.de 5 points 7 hours ago (1 children)

I never set a phone number on two of my google accounts and they still work fine. Those accounts are old. Google didn't ask for a phone number to sign up back then.

I recall seeing something about them planning to get rid of SMS 2FA last year. It looks like it's still an option though.

[–] Zarobi@aussie.zone 4 points 4 hours ago

Watch out, if those accounts are ever "locked", you will get permanently locked out of the accounts. Happened to me because a data breach revealed my email address and some idiot tried brute forcing my password. Didn't work but it broke the account. Secondary recovery email address and correct password wasn't good enough. Support basically told me to give up and make a new account (???).

[–] time2lose@lemmy.world 15 points 7 hours ago (3 children)

Telegram and whatsapp never had encryption. Also - they just give your messages on law enforcement request, always have.

Signal - how does it work with signal again?

[–] Greenusb@feddit.org 2 points 1 hour ago

WhatsApp uses signal protocol

[–] FriendOfDeSoto@startrek.website 14 points 6 hours ago (1 children)

They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.

Which is clever, to be fair. Whether or not that's legal is already a court case. The law is so frightfully grey.

[–] peopleproblems@lemmy.world 11 points 6 hours ago (1 children)

Its also a failure of the user's access control and operating security.

Once a third party has access to the secure environment, that environment is and will always be compromised.

[–] undrwater@lemmy.world 1 points 2 hours ago (1 children)

Is the user made aware of this by the operator (signal, telegram, et al)?

If not, it's a big haul to get to competency. The operator should be educating users on how to limit compromise.

[–] peopleproblems@lemmy.world 1 points 49 minutes ago
  1. It NEVER advertises itself as such.

  2. IIRC Signal DOES warn you about this, first when you make an account, and then when you try to save media files, and when you try to start a group chat. The others aren't remotely secure anyway and I have no interest in attempting to defend them.

You don't ask too many questions about signal cos the answers don't make you any more confident.

[–] GreenKnight23@lemmy.world 2 points 5 hours ago (2 children)

you know what would solve this? simplex.

[–] yestalgia@lemmy.world 9 points 4 hours ago (1 children)

"Just get everyone in your life to move to ______ and that will solve all your problems"

A suggestion as old as time

[–] GreenKnight23@lemmy.world -1 points 4 hours ago

it's one of the most secure message apps available.

messages are signed, encrypted and passed through servers, never left on the server. unless you were the intended recipient you will not decrypt it.

it's the truecrypt of instant messaging.

[–] fonix232@fedia.io 4 points 4 hours ago (1 children)

Oh really? Simplex would block someone from accessing your phone and thus Simplex' data?

[–] GreenKnight23@lemmy.world 1 points 3 hours ago* (last edited 3 hours ago) (1 children)

give me a list of messaging apps that stop attacks that leverage physical access.

use a better os that has encryption and kill codes if that's your concern.

[–] vald@mbin.linuxnation.social 1 points 2 hours ago (1 children)

give me a list of messaging apps that stop attacks that leverage physical access.

you know what would solve this? simplex.

um...

[–] GreenKnight23@lemmy.world 2 points 1 hour ago

either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance

why are you so against people using a more secure way to communicate?

[–] muntedcrocodile@hilariouschaos.com -1 points 6 hours ago* (last edited 6 hours ago) (2 children)

There have been too many of these types of events related to signal. And it has so many red flags. You are required to have a phone number which is essentially ur real identity. They used to federate with 3rd party servers but they killed that and all but wiped it from the internet. They try to shut down 3rd party clients. They don't provide reproducible builds so we can't trust the source. They received their initial funding from In-Q-Tel the CIA venture capital firm.

Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.

At minimum they have a full social graph of real identities with time-stamped message events. Sealed sender doesn't negate this as signal knows ur ip address when u give them a message. They also know the destination of that message as that isn't sealed. This is sufficient information to link sender and recipient and timestamp. That's assuming the unreproducible builds don't have backdoors.

It's all got a slightly fishy smell to it.

Tldr: If u want actual secure messaging u should consider SimpleX

[–] Doomsider@lemmy.world 1 points 3 hours ago

SimpleX looks neat, I will be watching this one.

Thanks!

[–] DomeGuy@lemmy.world 6 points 5 hours ago (2 children)

There are all of these stories about signal because it is notable when someone gets around it

That there's anything approaching secure communication on a cell-phone dominated Internet whose.operating systems are either "snobbish walled garden" or "ad agency living in the corpse of a search engine" is astonishing. In the same way that a gun safety that keeps a toddler from shooting themselves with an otherwise loaded gun is astonishing.

[–] GreenKnight23@lemmy.world 1 points 5 hours ago

can't get around simplex encryption unless you have physical access to the device or have been physically invited by a member.

[–] muntedcrocodile@hilariouschaos.com 0 points 4 hours ago (1 children)

Not to quote myself but:

Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.

[–] DomeGuy@lemmy.world 2 points 3 hours ago (1 children)

You should trust signal tree the same way you trust a front door lock that has never been broken or picked despite repeated attempts to do both.

.Just remember that police only go through the door when it's easier than breaking a window or tearing through a wall.

[–] muntedcrocodile@hilariouschaos.com 1 points 38 minutes ago

The US government has openly stated they killed people because of metadata and ur comfortable just giving that all away? U also didn't address any of my precise exact points you simply made a vague deflection.