Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
link2xt@fosstodon.orgL

link2xt@fosstodon.org

@link2xt@fosstodon.org
About
Indlæg
5
Emner
1
Fremhævelser
0
Grupper
0
Følgere
0
Følger
0

Vis Original

Indlæg

Seneste Bedste Controversial

  • Here are the four paragraphs of conclusion from that clickbaity piece ("Is Signal safe?") by @protonprivacy about @signalapp that is doing rounds.
    link2xt@fosstodon.orgL link2xt@fosstodon.org

    @pelle @rysiek
    For reference, here is the issue about accidentally being discoverable by phone number:
    https://github.com/signalapp/Signal-Android/issues/14222

    This setting is not reliable and a single failure to set it results in your phone number to ACI (account ID) being revealed. Once revealed, it is difficult to reset ACI, you need to completely unregister and not just reinstall. On Signal server ACI and phone number are stored literally in the same database table of Signal server all the time.

    Ikke-kategoriseret signal privacy infosec

  • "Tool allows stealthy tracking of #Signal and #WhatsApp users through delivery receipts"
    link2xt@fosstodon.orgL link2xt@fosstodon.org

    The attack class is not really new though, for Signal "delivery receipts" it is known that they can be used to track when devices get online since at least 2018: https://anarc.at/blog/2018-07-27-signal-metadata/

    It is also very similar to "Silent SMS" problem.

    Ikke-kategoriseret signal whatsapp arcanechat chatmail deltachat

  • #Signal apparently requires opening Signal on the phone from time to time without stating the reason.
    link2xt@fosstodon.orgL link2xt@fosstodon.org

    So far it looks like this is just a banner to warn that Signal account *may* be deactivated in case of major upgrade, but otherwise everything works.

    Ikke-kategoriseret signal

  • #Signal apparently requires opening Signal on the phone from time to time without stating the reason.
    link2xt@fosstodon.orgL link2xt@fosstodon.org

    #Signal apparently requires opening Signal on the phone from time to time without stating the reason. This is version 7.82.0 of Desktop and I don't have Signal on the phone at the moment. "Learn more" leads here: https://support.signal.org/hc/en-us/articles/9021007554074-Open-Signal-on-your-phone-to-keep-your-account-active
    I previously thought this only happened during events like PQC migration. Mostly documenting it for myself here.

    Ikke-kategoriseret signal

  • "Tool allows stealthy tracking of #Signal and #WhatsApp users through delivery receipts"
    link2xt@fosstodon.orgL link2xt@fosstodon.org

    @david_chisnall In Delta Chat there are no device-to-device delivery receipts ("two empty checkmarks" in Signal: https://support.signal.org/hc/en-us/articles/360007320751-How-do-I-know-if-my-message-was-delivered-or-read) and no automatic error responses. There are read receipts, but they require displaying the message, so cannot be silent and are not sent for reactions. There is a known issue with long-living QR codes/invite links, but this cannot be used to probe online status of someone you just happen to be in the chat with, I posted about it here:
    https://support.delta.chat/t/careless-whisper-on-deltachat/4396/2

    Ikke-kategoriseret signal whatsapp arcanechat chatmail deltachat
  • Log ind

  • Har du ikke en konto? Tilmeld

  • Login or register to search.
Powered by NodeBB Contributors
Graciously hosted by data.coop
  • First post
    Last post
0
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper