cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

  • There have been too many of these types of events related to signal. And it has so many red flags. You are required to have a phone number which is essentially ur real identity. They used to federate with 3rd party servers but they killed that and all but wiped it from the internet. They try to shut down 3rd party clients. They don’t provide reproducible builds so we can’t trust the source. They received their initial funding from In-Q-Tel the CIA venture capital firm.

    Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.

    At minimum they have a full social graph of real identities with time-stamped message events. Sealed sender doesn’t negate this as signal knows ur ip address when u give them a message. They also know the destination of that message as that isn’t sealed. This is sufficient information to link sender and recipient and timestamp. That’s assuming the unreproducible builds don’t have backdoors.

    It’s all got a slightly fishy smell to it.

    Tldr: If u want actual secure messaging u should consider SimpleX

    • DomeGuy@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      17 hours ago

      There are all of these stories about signal because it is notable when someone gets around it

      That there’s anything approaching secure communication on a cell-phone dominated Internet whose.operating systems are either “snobbish walled garden” or “ad agency living in the corpse of a search engine” is astonishing. In the same way that a gun safety that keeps a toddler from shooting themselves with an otherwise loaded gun is astonishing.

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        16 hours ago

        can’t get around simplex encryption unless you have physical access to the device or have been physically invited by a member.

          • GreenKnight23@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            5 hours ago

            lol

            either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance

            it’s literally a quote in the post. physical access was only one way they accessed messages.

            • SupraMario@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 hours ago

              That’s not the point I was trying to make. You are acting like simplex is better than signal because it requires physical access… that’s how it works for signal as well…that was the point…

        • DomeGuy@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 hours ago

          breaking the encryption is hard , but getting around the encryption is entirely doable without physical access if you allow SMS or on-device sharing.

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          3
          ·
          edit-2
          10 hours ago

          Ok so no better than Signal?

          You can do all the same things and use Tor, allow Sealed sender, and rotate username with phone number hidden.

          Why does Simplex want investors?

          • GreenKnight23@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 hours ago

            what company doesn’t want to grow or maintain services? they host the primary servers that everyone uses, that costs money.

            you could host your own though. can you do that with signal?

        • DomeGuy@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          15 hours ago

          You should trust signal tree the same way you trust a front door lock that has never been broken or picked despite repeated attempts to do both.

          .Just remember that police only go through the door when it’s easier than breaking a window or tearing through a wall.

                • Natanael@infosec.pub
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  edit-2
                  10 hours ago

                  Signal supports Tor.

                  They have features like Sealed Sender, which is at least on par with the multiple server behavior of Simplex as it behaves the same (message passing multiple servers, carrying no sender origin data in plaintext)

                  Simplex knows the same thing. The pairwise identifiers is a sham - all your different identifiers point to the same Android/iOS notification server API key so they know the recipient is the same person, they can tell which exact phone receives a notification when somebody sends you a message (unless the devs use anonymized fetch on a polling schedule, which they don’t).

                  And because they don’t hide those sender stamps, Simplex leak more info than Signal with Sealed sender

                  Why is Simplex asking for investors?

                  Are Simplex even considering notification content security?