cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

  • peopleproblems@lemmy.world
    link
    fedilink
    English
    arrow-up
    164
    ·
    7 days ago

    Interesting they highlight Signal again as though this is a vulnerability.

    If someone else has access to a linked device… that’s you fucking up access controls.

    • not@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      6 days ago

      I want a version of Signal that doesn’t allow linked devices. Linking devices is a clear vulnerability.

      • peopleproblems@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        ·
        6 days ago

        Im going to go out on a limb here and suggest something that should be obvious - you don’t have to link devices

        • not@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          6 days ago

          But “Law enforcement” can do it by spoofing sms. I want one account, one device.

          • peopleproblems@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            ·
            5 days ago

            Signal does not use SMS.

            The vulnerability they call out in the article is a phishing attack. A phishing attack requires the user’s input. There is no defense, no security, no techniques or technology to prevent you from handing the key to your safe to someone else.

    • skisnow@lemmy.ca
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      42
      ·
      edit-2
      7 days ago

      It’s a vulnerability precisely because people always swarm to defend Signal in stories like this, as though using Signal means the authorities (or other bad actors) can’t read your messages. Seems like every six months there’s some story involving Signal users getting hacked, and every time there’s a rush of wellacshuallys explaining why it wasn’t really Signal’s fault. (that last one is particularly egregious because I remember people defending it as “it wasn’t Signal, it was their partner who they subcontracted and gave your personal data to”, which is crazy levels of mental gymnastics.)

      Security is more than just encryption. If you flag something up as “hey use this if you want to hide from the Government” and have a personal phone number attached to it, that’s like a red rag to a bull.

      (edit: LOL, it’s hilarious how many people think they’re making great rebuttals in the replies when all they’re doing is proving my point. One child even flew directly into screaming at me. Signal fanbois are even worse than Apple supporters)

  • anon_8675309@lemmy.world
    link
    fedilink
    English
    arrow-up
    71
    ·
    7 days ago

    The headline makes people think signal is somehow broken.

    It’s not. Just be careful and monitor your account. And don’t let anyone gain physical control of your device.

  • Optional@lemmy.world
    link
    fedilink
    English
    arrow-up
    101
    arrow-down
    3
    ·
    7 days ago

    Signal failed to prevent soneone from accessing my unlocked phone and starting Signal! Everything was right there!

    • Zarobi@aussie.zone
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      1
      ·
      7 days ago

      On iOS you can set an app to require additional credentials to open, to prevent this situation. I’d imagine Android had something similar. I did it for all my important apps, just in case. Don’t want someone able to access my bank account or nudes.

      • Azzu@leminal.space
        link
        fedilink
        English
        arrow-up
        14
        ·
        7 days ago

        If someone can get unlocked access to your phone, your security practices are already insufficient. If you really want to prevent something like this, you need to make this first step impossible, not add a bandaid on top of it.

        • Zarobi@aussie.zone
          link
          fedilink
          English
          arrow-up
          6
          ·
          7 days ago

          Real life isn’t that clean. Security is about layers and making things as difficult as possible; there is never a single step which will fully protect you from everything

      • schnokobaer@feddit.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 days ago

        Doesn’t help a whole lot if you hand the unlocked phone with the unlocked app to a police officer.

        • frongt@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          6 days ago

          Because if you do, you just got Cellebrite’d. Your entire phone is compromised, now and going forward.

      • BarrelAgedBoredom@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        3
        ·
        7 days ago

        Just poked around. As far as I can tell there aren’t any options to require additional credentials to open an app on android. Im on a pixel 10 running android 17. However there is a locked “app drawer” that hides the apps from your home screen/ main app drawer that you need to have an additional password to access.

          • BarrelAgedBoredom@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            7 days ago

            Yes, but that’s a signal option, not an android option. The original commenters said ios had a feature to require additional credentials and was wondering about android, not a specific app that happens to be on android

        • Teknikal@anarchist.nexus
          link
          fedilink
          English
          arrow-up
          2
          ·
          7 days ago

          I have App Locker in settings iy let’s me use a fingerprint unlock on any apps I want, I assume it’s a stock Android feature.

        • Zak@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          7 days ago

          There’s Private Space, but that’s not ideal for a general-purpose messaging app because notifications are suspended when the space is locked. Signal also has the option to require the same authentication method as your screen lock in order to access the app.

          • Ludicrous0251@piefed.zip
            link
            fedilink
            English
            arrow-up
            7
            ·
            7 days ago

            All of this is great, but there’s literally nothing stopping the next article from saying “user who left their phone unlocked with signal also unlocked ‘got hacked’”

    • SergeantSushi@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      7 days ago

      I think you’re the only person here so far who read the linked article.

      I also found the netzpolitik article that was referenced but not linked to in the original article.

      This describes police adding a linked device to a person’s WhatsApp account while gathering evidence (translated with Google Translate).

      On January 12, 2020, Mr. and Mrs. P. were questioned. During the questioning, they voluntarily handed over the mobile phones they were carrying to the interviewing officers for a brief period so that messages from their daughter contained on the devices could be viewed and, among other things, photographed.

      While the photographs were being taken, the computer-based application WhatsApp Web was covertly activated via a website made available online by the Federal Criminal Police Office (BKA), allowing the messages to be read on a BKA computer (sic!). This did not involve any intrusion via a Trojan horse or similar software.

      The only link to Signal here is the nation state campaign which used social engineering via a phishing message from ‘Signal Support’.

      This nation state campaign was originally reported by a researcher at Citizen Lab.

      • Zak@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        6 days ago

        I did notice some comments that may be from people who did not read and understand the article. These attacks are not sophisticated or hard to defend against, which is probably why the German police want to limit public awareness.

        I find their view shortsighted/narrow; the attacks they’re using (including SIM swapping) are also widely used by criminals for fraud and identity theft. Police agencies should not discourage the public from being more cybersecurity-aware.

  • Agent641@lemmy.world
    link
    fedilink
    English
    arrow-up
    43
    arrow-down
    1
    ·
    6 days ago

    The burglar broke in by knocking on the door and waiting for someone to come to the door and open it and then asking if they could come in and were let in and asked if they could just take stuff and the person said sure go nuts.

    • deltapi@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      6 days ago

      Almost. More like they asked to use the bathroom then unlatched the bathroom window, left, and returned later through that window when the homeowner wasn’t paying attention

  • deltapi@lemmy.world
    link
    fedilink
    English
    arrow-up
    39
    arrow-down
    3
    ·
    7 days ago

    To me, this proves that the police can still get the information they need without us handing over our encryption keys and requiring ‘service providers’ to MITM for them.

    • cley_faye@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      ·
      6 days ago

      Except they had to get the keys, at least for Signal, as described in the article. Only you can allow a new device. If you get a notification for a new device and you go “sure, let me flash that code for you”, you’re giving the key. And a moron.

      Can’t say about the other services.

      • deltapi@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        6 days ago

        Yeah, what I’m saying is that this proves there’s no need for chat control. Law enforcement can already get what they want by being sneaky.

        • tias@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          4
          ·
          6 days ago

          There’s also no need for chat control because there is almost always enough information anyway, but the police doesn’t act on it. Their incompetency and lack of resources won’t be helped by adding even more information to sift through.

          • deltapi@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            5 days ago

            Yes, I agree. I’m saying that the article posted here provides actual evidence that they already have the tools they need, therefore…

  • evilcultist@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    31
    ·
    7 days ago

    Seems like signal could send a notification 24 hours after any new device is added to remind the user that it was done. Make it so it has to be dismissed on each device so dismissing it on one doesn’t make it vanish on the rest.

  • conorab@lemmy.conorab.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    4 days ago

    I might be mistaken but I don’t think Signal uses SMS alone to gain access to a chat so the attack vector for the Signal part based on what the article is saying is that the police are just getting access to a device that’s already authorised (and has the keys) then just adding in another device which they control. This sounds like Signal functioning as expected. The article does refer to police not wanting to give away too many details to maybe there’s something that hasn’t been disclosed, but the cited methods (assuming SMS is off the table for Signal) sound like normal behaviour.

  • bedwyr@piefed.ca
    link
    fedilink
    English
    arrow-up
    22
    arrow-down
    1
    ·
    7 days ago

    A problem many aren’t aware of, in an area that shares telecommunications info, two people within that area can be identified by the state sending encrypted messages by seeing when one person sends and another instantly receives a message. It could be easy enough to obscure that I would think by working differing lag times in.

    I think it was in the intercept a few years back. I think this is it.

    https://theintercept.com/2024/05/22/whatsapp-security-vulnerability-meta-israel-palestine/

    • nodiratime@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      7 days ago

      Remailer (Mixmaster) were meant to address that problem back when E-Mails were more popular.

  • odama626@lemmy.world
    link
    fedilink
    English
    arrow-up
    20
    ·
    7 days ago

    Signal in this was clickbait they literally just say oh well if someone can link in their device they can see 45 days of message history

    • faerbit@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      5
      ·
      6 days ago

      It goes above that.

      or intercepting SMS messages via telephone surveillance.

      Read the fucking article before commenting.

  • 87Six@lemmy.zip
    cake
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    7 days ago

    They reaaally want us to thibk Signal is equal to Whatsapp don’t they

    • yestalgia@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      arrow-down
      1
      ·
      7 days ago

      “Just get everyone in your life to move to ______ and that will solve all your problems”

      A suggestion as old as time

    • fonix232@fedia.io
      link
      fedilink
      arrow-up
      8
      arrow-down
      1
      ·
      7 days ago

      Oh really? Simplex would block someone from accessing your phone and thus Simplex’ data?

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        3
        ·
        7 days ago

        give me a list of messaging apps that stop attacks that leverage physical access.

        use a better os that has encryption and kill codes if that’s your concern.

        • vald@mbin.linuxnation.social
          link
          fedilink
          arrow-up
          7
          arrow-down
          2
          ·
          7 days ago

          give me a list of messaging apps that stop attacks that leverage physical access.

          you know what would solve this? simplex.

          um…

          • GreenKnight23@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            3
            ·
            7 days ago

            either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance

            why are you so against people using a more secure way to communicate?

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              2
              ·
              7 days ago

              the only time they mention signal is when they explain they used linked devices to obtain signal messages. not SMS! if you lose your phone or whatever, and log in on a new device, your messages won’t magically reappear, they are lost, and all your contacts get a warning that your safety numbers have changed.

              • GreenKnight23@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                6 days ago

                simplex messages stay on your phone. you can’t switch phones and have them follow you because there’s no way to sign in because there’s no account for you to sign in with.

                simplex doesn’t require a phone number or email. the trust is made between users, keeping users safer because it requires physical access between users. sure you can share your code over SMS or otherwise, but that’s a user issue that breaks usage policy, not a problem with the software.

                • WhyJiffie@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  6 days ago

                  simplex messages stay on your phone

                  I think that’s what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data.