Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. No, Signal has not been hacked.

No, Signal has not been hacked.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
8 Indlæg 4 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • hassignalbeenhacked@infosec.exchangeH This user is from outside of this forum
    hassignalbeenhacked@infosec.exchangeH This user is from outside of this forum
    hassignalbeenhacked@infosec.exchange
    wrote sidst redigeret af
    #1

    No, Signal has not been hacked. However, we do recommend turning off showing Signal content in notifications because the content is stored in memory on device. Apparently, this memory can be retrieved if an attacker has physical access to an unlocked device and has the right tool.

    https://activistchecklist.org/signal/#signal-disable-notifications

    jesterchen@social.tchncs.deJ 1 Reply Last reply
    1
    0
    • hassignalbeenhacked@infosec.exchangeH hassignalbeenhacked@infosec.exchange

      No, Signal has not been hacked. However, we do recommend turning off showing Signal content in notifications because the content is stored in memory on device. Apparently, this memory can be retrieved if an attacker has physical access to an unlocked device and has the right tool.

      https://activistchecklist.org/signal/#signal-disable-notifications

      jesterchen@social.tchncs.deJ This user is from outside of this forum
      jesterchen@social.tchncs.deJ This user is from outside of this forum
      jesterchen@social.tchncs.de
      wrote sidst redigeret af
      #2

      @HasSignalBeenHacked uhm... if an attacker has access to the unlocked device...... why wouldn't he just open signal? (And no, I did actually not read the article, usually I do before asking stuff like that, but news like these have often bugged me in some CVE related disclosures as well.)

      hassignalbeenhacked@infosec.exchangeH caitp@mstdn.socialC 2 Replies Last reply
      0
      • jesterchen@social.tchncs.deJ jesterchen@social.tchncs.de

        @HasSignalBeenHacked uhm... if an attacker has access to the unlocked device...... why wouldn't he just open signal? (And no, I did actually not read the article, usually I do before asking stuff like that, but news like these have often bugged me in some CVE related disclosures as well.)

        hassignalbeenhacked@infosec.exchangeH This user is from outside of this forum
        hassignalbeenhacked@infosec.exchangeH This user is from outside of this forum
        hassignalbeenhacked@infosec.exchange
        wrote sidst redigeret af
        #3

        @jesterchen Yeah, that’s a great point. However, here’s an article in the news today that folks are talking about. Someone deleted the signal app but the notifications were still retrievable.

        https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/

        jesterchen@social.tchncs.deJ 1 Reply Last reply
        0
        • jesterchen@social.tchncs.deJ jesterchen@social.tchncs.de

          @HasSignalBeenHacked uhm... if an attacker has access to the unlocked device...... why wouldn't he just open signal? (And no, I did actually not read the article, usually I do before asking stuff like that, but news like these have often bugged me in some CVE related disclosures as well.)

          caitp@mstdn.socialC This user is from outside of this forum
          caitp@mstdn.socialC This user is from outside of this forum
          caitp@mstdn.social
          wrote sidst redigeret af
          #4

          @jesterchen @HasSignalBeenHacked this is about the news that agencies were able to access the notification database for the device using digital forensic techniques, i.e. special tools that can access the iOS filesystem -- push notifications turn out to be held unencrypted in a database on the iOS filesystem, and are thus pretty easy for enforcement to get at.

          But it doesn't mean that they are able to access the Signal application itself, if the device was off

          kete@mstdn.socialK 1 Reply Last reply
          0
          • hassignalbeenhacked@infosec.exchangeH hassignalbeenhacked@infosec.exchange

            @jesterchen Yeah, that’s a great point. However, here’s an article in the news today that folks are talking about. Someone deleted the signal app but the notifications were still retrievable.

            https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/

            jesterchen@social.tchncs.deJ This user is from outside of this forum
            jesterchen@social.tchncs.deJ This user is from outside of this forum
            jesterchen@social.tchncs.de
            wrote sidst redigeret af
            #5

            @HasSignalBeenHacked thanks for your reply. As I said: usually I read articles first,...

            The new link is behind a paywall, but what I can see leads to new questions: Do people really believe, data is lost as soon as I delete something? And this is not even asking about other places where data might be stored. If I delete files, usually they're not physically deleted, only the allocation get's destroyed... and yeah, what typical user does know something like that, I know... (and that is long before clear vs. purge vs. cryptographically destroy like in NIST SP 800-88r2 or such).

            And as long as the device is unlocked, the encryption won't help.......

            And I know how difficult it is to explain the "basics" of this. So thanks again for the clarification.

            jesterchen@social.tchncs.deJ 1 Reply Last reply
            0
            • jesterchen@social.tchncs.deJ jesterchen@social.tchncs.de

              @HasSignalBeenHacked thanks for your reply. As I said: usually I read articles first,...

              The new link is behind a paywall, but what I can see leads to new questions: Do people really believe, data is lost as soon as I delete something? And this is not even asking about other places where data might be stored. If I delete files, usually they're not physically deleted, only the allocation get's destroyed... and yeah, what typical user does know something like that, I know... (and that is long before clear vs. purge vs. cryptographically destroy like in NIST SP 800-88r2 or such).

              And as long as the device is unlocked, the encryption won't help.......

              And I know how difficult it is to explain the "basics" of this. So thanks again for the clarification.

              jesterchen@social.tchncs.deJ This user is from outside of this forum
              jesterchen@social.tchncs.deJ This user is from outside of this forum
              jesterchen@social.tchncs.de
              wrote sidst redigeret af
              #6

              @HasSignalBeenHacked And thanks for the list to the checklist above. I will share it. 🙂

              1 Reply Last reply
              0
              • caitp@mstdn.socialC caitp@mstdn.social

                @jesterchen @HasSignalBeenHacked this is about the news that agencies were able to access the notification database for the device using digital forensic techniques, i.e. special tools that can access the iOS filesystem -- push notifications turn out to be held unencrypted in a database on the iOS filesystem, and are thus pretty easy for enforcement to get at.

                But it doesn't mean that they are able to access the Signal application itself, if the device was off

                kete@mstdn.socialK This user is from outside of this forum
                kete@mstdn.socialK This user is from outside of this forum
                kete@mstdn.social
                wrote sidst redigeret af
                #7

                @caitp @jesterchen @HasSignalBeenHacked
                I don't even have this option, Notification Content, in GrapheneOS.

                caitp@mstdn.socialC 1 Reply Last reply
                0
                • kete@mstdn.socialK kete@mstdn.social

                  @caitp @jesterchen @HasSignalBeenHacked
                  I don't even have this option, Notification Content, in GrapheneOS.

                  caitp@mstdn.socialC This user is from outside of this forum
                  caitp@mstdn.socialC This user is from outside of this forum
                  caitp@mstdn.social
                  wrote sidst redigeret af
                  #8

                  @kete @jesterchen @HasSignalBeenHacked it's a part of the Signal app's settings, I'm not sure if that's what you're referring to, could be iOS-specific

                  1 Reply Last reply
                  0
                  • malte@radikal.socialM malte@radikal.social shared this topic
                  Svar
                  • Svar som emne
                  Login for at svare
                  • Ældste til nyeste
                  • Nyeste til ældste
                  • Most Votes


                  • Log ind

                  • Har du ikke en konto? Tilmeld

                  • Login or register to search.
                  Powered by NodeBB Contributors
                  Graciously hosted by data.coop
                  • First post
                    Last post
                  0
                  • Hjem
                  • Seneste
                  • Etiketter
                  • Populære
                  • Verden
                  • Bruger
                  • Grupper