RE: https://mastodon.world/@signalapp/116478659183004819
This is a good thread. I like how carefully they take responsibility for where they could have done better, and at the same time very clearly state what isn't a problem with Signal.
Signal feed
Post
Remote status
Context
6RE: https://mastodon.world/@signalapp/116478659183004819
This is a good thread. I like how carefully they take responsibility for where they could have done better, and at the same time very clearly state what isn't a problem with Signal.
Like, it's both very true that a phishing attack against Signal users isn't a vulnerability with Signal, and that given the high value of Signal accounts, they can and should do more to proactively resist phishing attacks. They don't let either one of those truths overshadow the other, and good on 'em.
@xgranade
it kinda is an issue with #signal tho.
they've been training users to fall for re-register #scams by constantly prompting users to re-enter your #PIN (and the PIN is only necessary because phone numbers are used for sign-up).
#signal are good at #victimblaming whenever there's a security incident.
they've been training users to fall for re-register #scams by constantly prompting users to re-enter your #PIN (and the PIN is only necessary because phone numbers are used for sign-up).
No, the PIN is required to reacquire the account if you lose all connected devices. If they used any other unique identifier as the account handle, the PINs would still be required.
@david_chisnall @xgranade
yes, exactly: #PIN is needed to reaqcuire your account β using your #phonenumber! β because without PIN, #signal account data would be vulnerable to #SIMswapattack, right?
@david_chisnall @xgranade
whatever #signal's reasons are for badgering users for a #PIN, it's clearly a design choice they made, because other secure messengers don't do this.
and clearly this design choice has some harmful consequences, which i don't think it's fair of them to just #victimblame away.
Replies
8whatever #signal's reasons are for badgering users for a #PIN, it's clearly a design choice they made, because other secure messengers don't do this.
The choice is either:
The PIN entry UI looks nothing like an incoming message.
@david_chisnall @xgranade
#signal has now decided to use official release notifications that look almost indistiguishable from a regular chat, just to train users even harder to fall for phishing attacks. π
@feld does it have forward secrecy yet?
Also note that Delta chat is not suitable if you need anonymity.
@feld thanks for the info. Itβll take me a moment to digest it.
Regarding anonymity/metadata, Iβm referring to the inherent connection patterns that can be observed with centralised vs decentralised systems.
@feld i do. βΊοΈ
( still stuck on amazon signal for a few chats, but getting there. )
We can't find the internet
Attempting to reconnect
Something went wrong!
Attempting to reconnect