Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists.

We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
77 Indlæg 49 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • signalapp@mastodon.worldS signalapp@mastodon.world

    To protect people from such phishing, Signal actively warns users against sharing their SMS code and PIN.

    We also want to emphasize that Signal Support will *never* initiate contact via in-app messages, SMS, or social media to ask for your verification code or PIN. If anyone asks for any Signal related code, it is a scam. We make this clear when users receive their SMS code during initial signup.

    signalapp@mastodon.worldS This user is from outside of this forum
    signalapp@mastodon.worldS This user is from outside of this forum
    signalapp@mastodon.world
    wrote sidst redigeret af
    #4

    While we build robust technical safeguards, user vigilance is ultimately the best defense against phishing. We will continue to work on mitigating these risks via interface design and signposting throughout the app. In the meantime, please stay alert, and never share your SMS verification code or Signal PIN with anyone.

    https://support.signal.org/hc/en-us/articles/9932566320410-Staying-Safe-from-Phishing-Scams-and-Impersonation

    excelanalytics@mastodon.worldE dlink@posthat.caD kaito02@mastodon.socialK spitfire@mastodon.socialS 4 Replies Last reply
    0
    • signalapp@mastodon.worldS signalapp@mastodon.world

      We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously.

      To be clear: Signal’s encryption and infrastructure have not been compromised and remain robust. These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users’ accounts.

      cmthiede@social.vivaldi.netC This user is from outside of this forum
      cmthiede@social.vivaldi.netC This user is from outside of this forum
      cmthiede@social.vivaldi.net
      wrote sidst redigeret af
      #5

      @signalapp time to re-up their cyber awareness campaigns

      1 Reply Last reply
      0
      • signalapp@mastodon.worldS signalapp@mastodon.world

        We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously.

        To be clear: Signal’s encryption and infrastructure have not been compromised and remain robust. These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users’ accounts.

        P This user is from outside of this forum
        P This user is from outside of this forum
        patricus@gts.posix.live
        wrote sidst redigeret af
        #6

        @signalapp how to move signal account from a phone to an other? just a question.

        tedstechtips@mas.toT 1 Reply Last reply
        0
        • signalapp@mastodon.worldS signalapp@mastodon.world

          To protect people from such phishing, Signal actively warns users against sharing their SMS code and PIN.

          We also want to emphasize that Signal Support will *never* initiate contact via in-app messages, SMS, or social media to ask for your verification code or PIN. If anyone asks for any Signal related code, it is a scam. We make this clear when users receive their SMS code during initial signup.

          loke@functional.cafeL This user is from outside of this forum
          loke@functional.cafeL This user is from outside of this forum
          loke@functional.cafe
          wrote sidst redigeret af
          #7

          @signalapp as careful as this message is, I think it could be improved. If someone goes to a web page and get phished by being asked to type it into the page, the message will not dter them because it's not someone "asking for the code".

          I think the message should say something about where it's intended to be used.

          kkarhan@infosec.spaceK 1 Reply Last reply
          0
          • signalapp@mastodon.worldS signalapp@mastodon.world

            To protect people from such phishing, Signal actively warns users against sharing their SMS code and PIN.

            We also want to emphasize that Signal Support will *never* initiate contact via in-app messages, SMS, or social media to ask for your verification code or PIN. If anyone asks for any Signal related code, it is a scam. We make this clear when users receive their SMS code during initial signup.

            fqqd@chaos.socialF This user is from outside of this forum
            fqqd@chaos.socialF This user is from outside of this forum
            fqqd@chaos.social
            wrote sidst redigeret af
            #8

            @signalapp you dum dum you just publicly shared it

            benroyce@mastodon.socialB zrb@social.hildebrind.spaceZ 2 Replies Last reply
            0
            • signalapp@mastodon.worldS signalapp@mastodon.world

              These attacks, like all phishing, rely on social engineering. Attackers impersonate trusted contacts or services (such as the non-existent “Signal Support Bot”) to trick victims into handing over their login credentials or other information. To help prevent this, remember that your Signal SMS verification code is only ever needed when you are first signing up for the Signal app.

              sonjdol@ohai.socialS This user is from outside of this forum
              sonjdol@ohai.socialS This user is from outside of this forum
              sonjdol@ohai.social
              wrote sidst redigeret af
              #9

              @signalapp this might be worth a push message to all users

              1 Reply Last reply
              0
              • signalapp@mastodon.worldS signalapp@mastodon.world

                To protect people from such phishing, Signal actively warns users against sharing their SMS code and PIN.

                We also want to emphasize that Signal Support will *never* initiate contact via in-app messages, SMS, or social media to ask for your verification code or PIN. If anyone asks for any Signal related code, it is a scam. We make this clear when users receive their SMS code during initial signup.

                unaegeli@swiss.socialU This user is from outside of this forum
                unaegeli@swiss.socialU This user is from outside of this forum
                unaegeli@swiss.social
                wrote sidst redigeret af
                #10

                @signalapp

                Hmmm, and what about the monthly reminder to enter the personal smartphone code? How to differentiate this from the other?

                joelvanderwerf@mastodon.socialJ solitha@mastodon.socialS distrowatch@mastodon.socialD kainisenni@vocalounge.cafeK dec23k@mastodon.ieD 6 Replies Last reply
                0
                • P patricus@gts.posix.live

                  @signalapp how to move signal account from a phone to an other? just a question.

                  tedstechtips@mas.toT This user is from outside of this forum
                  tedstechtips@mas.toT This user is from outside of this forum
                  tedstechtips@mas.to
                  wrote sidst redigeret af
                  #11

                  @patricus @signalapp https://support.signal.org/hc/en-us/articles/10074659364122-Backups-and-Device-Transfers-on-Signal

                  1 Reply Last reply
                  0
                  • signalapp@mastodon.worldS signalapp@mastodon.world

                    While we build robust technical safeguards, user vigilance is ultimately the best defense against phishing. We will continue to work on mitigating these risks via interface design and signposting throughout the app. In the meantime, please stay alert, and never share your SMS verification code or Signal PIN with anyone.

                    https://support.signal.org/hc/en-us/articles/9932566320410-Staying-Safe-from-Phishing-Scams-and-Impersonation

                    excelanalytics@mastodon.worldE This user is from outside of this forum
                    excelanalytics@mastodon.worldE This user is from outside of this forum
                    excelanalytics@mastodon.world
                    wrote sidst redigeret af
                    #12

                    @signalapp recipients who are not native English speakers may not notice the giveaways in this and similar scams.

                    jakobnitschke@mastodon.socialJ kkarhan@infosec.spaceK 2 Replies Last reply
                    0
                    • unaegeli@swiss.socialU unaegeli@swiss.social

                      @signalapp

                      Hmmm, and what about the monthly reminder to enter the personal smartphone code? How to differentiate this from the other?

                      joelvanderwerf@mastodon.socialJ This user is from outside of this forum
                      joelvanderwerf@mastodon.socialJ This user is from outside of this forum
                      joelvanderwerf@mastodon.social
                      wrote sidst redigeret af
                      #13

                      @unaegeli @signalapp My guess: the reminder is a pop-up dialog. It's not a signal message, email, or text.

                      I, too, would like to hear Signal's answer to this question.

                      1 Reply Last reply
                      0
                      • unaegeli@swiss.socialU unaegeli@swiss.social

                        @signalapp

                        Hmmm, and what about the monthly reminder to enter the personal smartphone code? How to differentiate this from the other?

                        solitha@mastodon.socialS This user is from outside of this forum
                        solitha@mastodon.socialS This user is from outside of this forum
                        solitha@mastodon.social
                        wrote sidst redigeret af
                        #14

                        @unaegeli @signalapp I was just thinking of this.

                        It sounds like Signal is fairly unique in this setup. We're constantly being bombarded with verification requests, and it can be easy to forget one app works differently.

                        pupwrafie@bark.lgbtP 1 Reply Last reply
                        0
                        • fqqd@chaos.socialF fqqd@chaos.social

                          @signalapp you dum dum you just publicly shared it

                          benroyce@mastodon.socialB This user is from outside of this forum
                          benroyce@mastodon.socialB This user is from outside of this forum
                          benroyce@mastodon.social
                          wrote sidst redigeret af
                          #15

                          @FQQD @signalapp

                          😂

                          "in a stunning development today, a random mastodon user showed they were able to take over Signal's Signal account. details of the hack remain unclear"

                          kkarhan@infosec.spaceK 1 Reply Last reply
                          0
                          • fqqd@chaos.socialF fqqd@chaos.social

                            @signalapp you dum dum you just publicly shared it

                            zrb@social.hildebrind.spaceZ This user is from outside of this forum
                            zrb@social.hildebrind.spaceZ This user is from outside of this forum
                            zrb@social.hildebrind.space
                            wrote sidst redigeret af
                            #16

                            @FQQD @signalapp quick GET 'EM

                            kkarhan@infosec.spaceK 1 Reply Last reply
                            0
                            • signalapp@mastodon.worldS signalapp@mastodon.world

                              We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously.

                              To be clear: Signal’s encryption and infrastructure have not been compromised and remain robust. These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users’ accounts.

                              lizette603_23@mastodon.socialL This user is from outside of this forum
                              lizette603_23@mastodon.socialL This user is from outside of this forum
                              lizette603_23@mastodon.social
                              wrote sidst redigeret af
                              #17

                              @signalapp nobody should use Signal

                              voxel@infosec.spaceV 1 Reply Last reply
                              0
                              • lizette603_23@mastodon.socialL lizette603_23@mastodon.social

                                @signalapp nobody should use Signal

                                voxel@infosec.spaceV This user is from outside of this forum
                                voxel@infosec.spaceV This user is from outside of this forum
                                voxel@infosec.space
                                wrote sidst redigeret af
                                #18

                                @Lizette603_23 @signalapp Please stay kind and on topic, alright? Signal is open for feedback in their Discourse Forum.

                                lizette603_23@mastodon.socialL kkarhan@infosec.spaceK 2 Replies Last reply
                                0
                                • signalapp@mastodon.worldS signalapp@mastodon.world

                                  We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously.

                                  To be clear: Signal’s encryption and infrastructure have not been compromised and remain robust. These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users’ accounts.

                                  scathach@stereophonic.spaceS This user is from outside of this forum
                                  scathach@stereophonic.spaceS This user is from outside of this forum
                                  scathach@stereophonic.space
                                  wrote sidst redigeret af
                                  #19
                                  @signalapp These attacks wouldn't be possible if you stopped requiring phone numbers
                                  christmastree@mastodon.socialC 1 Reply Last reply
                                  0
                                  • excelanalytics@mastodon.worldE excelanalytics@mastodon.world

                                    @signalapp recipients who are not native English speakers may not notice the giveaways in this and similar scams.

                                    jakobnitschke@mastodon.socialJ This user is from outside of this forum
                                    jakobnitschke@mastodon.socialJ This user is from outside of this forum
                                    jakobnitschke@mastodon.social
                                    wrote sidst redigeret af
                                    #20

                                    @ExcelAnalytics @signalapp

                                    Thank you for pointing this out

                                    1 Reply Last reply
                                    0
                                    • signalapp@mastodon.worldS signalapp@mastodon.world

                                      We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously.

                                      To be clear: Signal’s encryption and infrastructure have not been compromised and remain robust. These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users’ accounts.

                                      ariarhythmic@ohai.socialA This user is from outside of this forum
                                      ariarhythmic@ohai.socialA This user is from outside of this forum
                                      ariarhythmic@ohai.social
                                      wrote sidst redigeret af
                                      #21

                                      @signalapp "SMS codes" sounds like a you problem, though.

                                      kkarhan@infosec.spaceK 1 Reply Last reply
                                      0
                                      • signalapp@mastodon.worldS signalapp@mastodon.world

                                        We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously.

                                        To be clear: Signal’s encryption and infrastructure have not been compromised and remain robust. These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users’ accounts.

                                        adulau@infosec.exchangeA This user is from outside of this forum
                                        adulau@infosec.exchangeA This user is from outside of this forum
                                        adulau@infosec.exchange
                                        wrote sidst redigeret af
                                        #22

                                        @signalapp Since Signal always asks for a PIN code for backups, it seems logical that threat actors are exploiting this behavior to trick users.

                                        kkarhan@infosec.spaceK 1 Reply Last reply
                                        0
                                        • solitha@mastodon.socialS solitha@mastodon.social

                                          @unaegeli @signalapp I was just thinking of this.

                                          It sounds like Signal is fairly unique in this setup. We're constantly being bombarded with verification requests, and it can be easy to forget one app works differently.

                                          pupwrafie@bark.lgbtP This user is from outside of this forum
                                          pupwrafie@bark.lgbtP This user is from outside of this forum
                                          pupwrafie@bark.lgbt
                                          wrote sidst redigeret af
                                          #23

                                          @solitha
                                          I mean it's hard for some non technical users to make them understand what is the "trusted context" and what is not I suppose?

                                          I mean we had that with mail for years, people should know to check the senders mail, yet still Phishing attacks are often successful.
                                          @unaegeli @signalapp

                                          solitha@mastodon.socialS 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper