Users of the Signal messaging app got hit by a hacker attack. We analyze what happened and why the attack demonstrates that Signal is reliable.

  • bkrl@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    2 years ago

    One may have all the encryption you want, but if the 2FA SMS whispers entry to the hackers, it’s clear that they’re not coming in through the security door but through the broken window…

    • Jones@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      2 years ago

      To be fair, even though they bypassed the 2FA, they did not get access to previous conversations and contact list. That’s the point of the article, right?

      • bkrl@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        2 years ago

        Even if the encryption does not collapse, it is still an app full of identifiers. That makes metadata available. An attacker could figure out who contacted whom.

        • Jones@lemmy.mlOP
          link
          fedilink
          arrow-up
          0
          ·
          2 years ago

          Whenever someone says “Signal is not good enough”, my answer is “what’s your threat model”? For me it’s a pretty damn good compromise given that all my friends and family are on it (as opposed to e.g. using WhatsApp or Telegram 99% of the time and a perfect alternative with one contact). The day I can realistically think about making my contacts move to a better alternative, I’ll do it. In the meantime, that’s the best I’ve got. And it’s not too bad, to be fair.

          • bkrl@lemmy.ml
            link
            fedilink
            arrow-up
            0
            ·
            2 years ago

            In the meantime, that’s the best I’ve got. And it’s not too bad, to be fair.

            Are you quite certain? Have you looked hard and concluded that Signal is the best alternative available today?

            I can tell you that my messenger doesn’t use identifiers, it doesn’t track me, it doesn’t care who my contacts are, it doesn’t ask for my email, phone number, and importantly it does everything Signal does.