Post B7wYyR0jsQoK9whr04 by blogdiva@mastodon.social
(DIR) More posts by blogdiva@mastodon.social
(DIR) Post #B7wX3SyDos6hmAnh20 by dangillmor@mastodon.social
0 likes, 0 repeats
Journalists: Your "tip lines" for whistleblowers need absolutely relentless attention to security. The Intercept's apparent failure here is horrifying -- and dangerous. https://www.dropsitenews.com/p/intercept-signal-tip-line-breach-hack
(DIR) Post #B7wYyR0jsQoK9whr04 by blogdiva@mastodon.social
0 likes, 0 repeats
@dangillmor again?!?!?
(DIR) Post #B7wZMNLHAX0NjNjD2e by mattblaze@federate.social
0 likes, 0 repeats
@dangillmor not the first time the Intercept screwed up tech for protecting sources.
(DIR) Post #B7wZj0nT9qCAT6i2Gu by thekerker@mstdn.social
0 likes, 0 repeats
@dangillmor I love how Drop Site is the one to report this.
(DIR) Post #B7weAeHSrjAoYpAn4a by starraven@mastodon.scot
0 likes, 0 repeats
@dangillmor No one will ever convince me Signal is secure.
(DIR) Post #B7wgSeOdNG5i2YEpY8 by disorderlyf@todon.eu
0 likes, 0 repeats
@dangillmor Actual vulnerability with Signal or shitty opsec?EDIT: "Signal user IDs associated with accounts that are left dormant are eventually recycled and made available to new users. The individual or organization who took control of the Signal tips line for confidential sources may have been able to take over after the ID went dormant, despite still being listed on the organization website, and began soliciting tips posing as The Intercept." So technically a vulnerability, but not something that would necessarily compromise any given Signal account. Seems odd their tip line would be so inactive as to allow that circumstances like that unless that threshold is very short.
(DIR) Post #B7x7hGEALpU66JMlbE by PamelaBarroway@mstdn.social
0 likes, 0 repeats
@dangillmor Yikes 😬