A response to recent reporting in Germany, in service of clarity and accountability:
-
@olliausstuhr @signalapp @Chantology
That's pretty much the same. You can't publically frame something if noone hears you. -
@expertenkommision_cyberunfall @signalapp To the first question: signal does not have access to your profile name or profile picture.
@skaphle
The server doesn't but the app does. Is there any reason to not want to make the app hide messages from accounts with such names?
@expertenkommision_cyberunfall @signalapp -
@davep @signalapp If they handed over verification code and pin then they would have to be seriously daft.
@jtb
*Anyone* can be tricked. If your'e caught at a bad time, distracted, stressed, you *will* fall for it.
@davep @signalapp -
@signalapp I wonder what the motivation behind this attack is. There's no money to be made from stealing Signal accounts, except maybe by extortion.
@jackemled @signalapp Gaining access to classified information from highest government officials, and being able to pose as these officials when contacting their colleagues, feels like something worth your time if you're interested in that sort of information.
-
@davep @signalapp If they handed over verification code and pin then they would have to be seriously daft.
@jtb @davep @signalapp we are talking about german politicians here, being daft is a job requirement
-
@stagerabbit @ahltorp @davep @signalapp ok maybe, but banks are saying all the time not to give out pin even to bank staff.
@jtb @stagerabbit @ahltorp @davep @signalapp Banks and others regularly call me up and ask me to identify myself to them, ie give the unknown caller my credentials. And cannot see the problem in training their customers to comply.
-
@davep @signalapp If they handed over verification code and pin then they would have to be seriously daft.
@jtb @davep @signalapp Well well. We speak of the president of the german parliament. No one would ever suspect her to be seriously daft.
-
@jtb Watch what you call the President of the German Parliament! /s
@guenther @jtb @davep @signalapp she is, actually, and has long been known to be
-
For the time being, please stay vigilant against phishing and account takeover attempts. Remember that no one from Signal Support will ever send you a message request or ask for your registration verification code or Signal PIN. For an added layer of protection, you can enable Registration Lock in your Signal Settings (Account -> Registration Lock). 8/
@signalapp I am trying to work out why Registration Lock is not on by default. In particular, why would you be able to set a PIN and not set Registration Lock? I can imagine a use case where someone didn't want a PIN at all, though that shouldn't be the default in a secure messaging app. But why PIN and no lock?
-
-
@nuk3 @signalapp I wonder what issue they have with Matrix?! They could just spin up their own sever.
As far as I know, the Bundeswehr already uses matrix

-
-
A response to recent reporting in Germany, in service of clarity and accountability:
First, it’s important to be precise when it comes to critical infrastructure like Signal. Signal was not “hacked” — in that our encryption, infrastructure, and the integrity of the app’s code was not compromised. 1/
-
-
As far as I know, the Bundeswehr already uses matrix

@nuk3 @stairjoke yes the BwMessenger and then there is also the BundesMessenger which is based on that.
-
We understand the trust that people put in Signal, and how devastating this kind of social engineering can be. While it’s true that all messaging platforms are susceptible to scammers and phishing that betrays people’s trust and convinces them to “unlock the front door” where no backdoor exists, we are looking to do everything we can to help people avoid and detect such scams. 7/
"all messaging platforms"?! /cc @c998a573 -
@energisch_ @signalapp with e2ee?
@yetzt rather automatically Block any accountname with Signal & Support in it?
@signalapp -
@jtb @stagerabbit @ahltorp @davep @signalapp Banks and others regularly call me up and ask me to identify myself to them, ie give the unknown caller my credentials. And cannot see the problem in training their customers to comply.
@EarthOrgUK @jtb @ahltorp @davep @signalapp Both my life insurance company and my overseas bank want me to send copies of my passport and proof of address over unencrypted email. When I complain, they say I should password protect the file and send the password in a separate unencrypted email to the same address.
Even if I find a way to send it securely, based on this, I doubt they store it securely.
-
@EarthOrgUK @jtb @ahltorp @davep @signalapp Both my life insurance company and my overseas bank want me to send copies of my passport and proof of address over unencrypted email. When I complain, they say I should password protect the file and send the password in a separate unencrypted email to the same address.
Even if I find a way to send it securely, based on this, I doubt they store it securely.
@EarthOrgUK @jtb @ahltorp @davep @signalapp And they've locked my account for KYC reasons until I do it. Damned if you do, damned if you don't.
-
@MFennVT @signalapp uncheck pin reminder in setting accounts.
@GOKUSHRM @MFennVT @signalapp why would you want to do that?