cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

  • FriendOfDeSoto@startrek.website
    link
    fedilink
    English
    arrow-up
    20
    ·
    17 hours ago

    They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.

    Which is clever, to be fair. Whether or not that’s legal is already a court case. The law is so frightfully grey.

    • peopleproblems@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      17 hours ago

      Its also a failure of the user’s access control and operating security.

      Once a third party has access to the secure environment, that environment is and will always be compromised.

      • undrwater@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        14 hours ago

        Is the user made aware of this by the operator (signal, telegram, et al)?

        If not, it’s a big haul to get to competency. The operator should be educating users on how to limit compromise.

        • peopleproblems@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          12 hours ago
          1. It NEVER advertises itself as such.

          2. IIRC Signal DOES warn you about this, first when you make an account, and then when you try to save media files, and when you try to start a group chat. The others aren’t remotely secure anyway and I have no interest in attempting to defend them.