The Signal messenger and protocol.

2673 readers
39 users here now

https://signal.org/

founded 6 years ago
MODERATORS
1
2
 
 

Hi all,

I found it really frustrating trying to move my animated stickers over from Whatsapp to Signal because Signal requires animated stickers to be in APNG format and also under 300 KB. Seems like almost no other program on this planet besides Signal supports APNGs and even if I managed to convert some files to the required format, the size restriction became an issue.

So I wrote a small CLI tool with Python to handle the conversion. It converts other animated image formats (e.g. GIF, WEBP) to APNGs and supports some simple options to reduce the file size as much as possible.

It's not perfect, but I thought I'd share this publicly so maybe even a few people will find this useful.

Thanks!

3
 
 

Their website and F-Droid repo is unreachable now. No update about this on Mastodon and apparently they haven't updated the app in 3 months.

Edit: Some updates from their Matrix channel

Edit2: They responded to the ticket

Thanks for reporting it. The domain automatic renewal failed because the credit card we used for payment was expired, and OpenCollective didn't issue a new card.

The domain is still ours, but the DNS services are suspended. We've already paid for the renewal (11 hours after the domain expired). Unfortunately, our registrar, Gandi, seems to need to take a manual action, and they haven't responded to our support requests yet. Today is bank public holiday in France.

4
 
 

...in case you missed that

5
1
submitted 2 months ago* (last edited 2 months ago) by Beehaw_Girl@beehaw.org to c/signal@lemmy.ml
 
 

I was a signal user until 2021, something glitched, probably because I had a weak data signal a few times so I thought signal was glitching so I abandoned it.

Well I need it again now because starting today July 6th Google is monopolizing all my native SMS apps and I don't like the vibe of that and I do not agree to click agree to every step of the process Google taking over all my SMS activities.

As far as I know the only way to use Signal is if both communicating parties are both on signal, so how can I make this my main SMS app with businesses and everything & everyone who texts my main phone number?

I don't have a lot of friends and so far I have one friend who agreed to go to signal with me, and I texted him and he didn't respond so I thought he either ghosted me or it's not working. How can I make signal work? It's not working.

6
 
 

Despite being on the latest update, very often I've been seeing Signal crash right after sending a message. It's not after every single message, but often enough, it just sends me back to the home screen. After crashing enough times, my phone automatically suggests cache-cleaning, which I then follow the prompt for, but which doesn't seem to fix things for long. I've never seen this error before and am wondering if it's just me or if others have seen this as well as of late.

7
8
 
 

I sent a message at 1:06pm and didn't hear back or message them again afterwards. Then around 5 pm I received this as a signal notification even though we weren't in the same location or messaging at the time.

I opened it and the verified/safety number is now permanently at the bottom of all of our messages.

I don't recall ever setting up a safety number with this person, but if I did it would have been like a year ago. Why would this suddenly pop up now?

9
1
submitted 3 months ago* (last edited 3 months ago) by xoron@programming.dev to c/signal@lemmy.ml
 
 

This is a technical demo of a fairly unique approach using a browser-based, local-first and webrtc approach.

Enkrypted.Chat

This is intended to introduce a new paradigm in client-side managed secure cryptography. We can avoid registration of any sort.

Features:

  • PWA
  • P2P
  • End to end encryption
  • Signal protocol
  • Post-Quantum cryptography
  • Multimedia
  • File transfer
  • Video calls
  • Local-first
  • No registration
  • No installation
  • No database
  • TURN server

Some open source versions of the core concepts.

Feel free to reach out for clarity instead of diving into the docs. Please use responsibly.

IMPORTANT: Caution should always be used for projects like this. While this is aiming to provide a secure experience, it isnt audited or reviewed. Shared for testing, feedback and demo purposes only. If youre unsure, this isnt for you.

10
 
 

The Federal Government and the EU Commission are still making every effort to enable their secret services and police to read all the chats of the population legally and technically. One obstacle is end-to-end encrypted messenger apps. “I use Signal every day,” Edward Snowden, a whistleblower, said in a statement in November 2015. More than ten years later, the messenger service, supported by a non-profit foundation, is still popular with whistleblowers, dissidents, journalists and also political officials and military officials.

So popular that since the end of 2024 at the latest, tricksters apparently want to systematically facilitate such people around their access data to the signal user account. In order to warn users even more clearly than before about the digital grandchild tricks and to raise awareness of the dangers, the operator of Signal announced new functions for the app on Monday. If you are contacted by non-personally verified signal users, several warnings should be displayed. “Signal will never send you a message and ask for your registration code, PIN, or recovery key,” reads a note. In addition, the so-called phishing ("password fishing") or other scams is warned. Russian traces

In order to establish contact with signal users, you need the mobile phone number or the user name or the user name selected by the target person himself or. QR code. The fraudsters of the recent wave of attacks pose as a signal support team and claim that the victim must communicate security codes, as the own account may be compromised. The IT security researcher Donncha Ó Cearbhaill, who works for Amnesty International in Berlin, made such a fraud attempt on 8. May on X public. In January, he was contacted by an alleged “Signal Security Support Chat-Bot.” The message claims a “suspicious activity on your device.” The sender also claimed that attempts had been noticed to gain access to “private data in signal” – followed by the request to reveal the personal verification code.

Ó Cearbhaill was able to look behind the scenes. So he was the target number 13.730 in the database of the perpetrators. “The automated system that governs the campaign” is called “ApocalypseZ” by the operators. The source code and the user interface are written exclusively in Russian. The attackers also translated the communication with the victims into Russian.” This assignment should fit the Cold War concept into this “security authorities”.

On 6. In February, the Federal Office for Information Security (BSI), which is subordinate to the CSU-controlled Ministry of the Interior, and the Federal Office for the Protection of the Constitution responsible for counterintelligence, had published a security notice on “phishing via messenger services”. In it, there is talk of a “probably state-controlled cyber actor” who carries out attacks via apps such as Signal. "The minor technical hurdles of this campaign of attack" therefore allow the conclusion that "non-state actors, in particular of cybercriminal groups" could also be responsible. However, the official assessment ends with the verdict: “In view of the high-profile target area, in the currently known cases, a state-controlled cyber actor is likely to be assumed to be the originator.”

Within the following months, it was practically clear for high-reach media: Russia was. On the 9. In March, the Reuters news agency reported on “Russian-backed hackers.” The media house Correctiv reported on 29. April that “the digital traces of the campaign would actually lead to Russia.” More specifically: to “a group that categorizes IT security experts from Google as ‘UNC5792” – whereby the “UNC” stands for unambiguously assigned actors or attacks. Correctiv further claimed that it had “established a connection to previous phishing campaigns against targets in Ukraine and the Republic of Moldova.”

There has been particular excitement since Der Spiegel reported that the phishing attack, often incorrectly referred to as a “hack”, was not only successful for “NATO members” but also for several members of the federal government and the Bundestag. On 22. April, the newspaper had reported that Bundestag President Julia Klöckner (CDU) was one of the victims. The domestic intelligence service had even become present to the chancellor. "In virtually all political groups" there are concerned MPs. According to the SPD group, Spiegelthere were “a few” there. Likewise with the Left Group. The Union Group did not wish to provide any information. Finally, the Attorney General has begun investigations at the Federal Court of Justice on suspicion of intelligence agent activity. The magazine later reported that Education Minister Karin Prien (CDU) and Building Minister Verena Hubertz (SPD) were also said to have gone on the glue to the fraudsters. Should this be true, the perpetrators may have gained access to various Bundestag, government and party-internal chat groups.

In one on 8. Spiegel, published online in May, criticized Signal's president, Meredith Whittaker, for publicly denigrating the politicians affected by the phishing attack for their alleged incompetence. Whittaker urged better funding for the messenger service in the face of the wide spread of signal among senior officials and secrets. He lives on donations. Arms startups like Helsing would get “billions for their promises,” she criticized. “We operate with Signal an already functioning critical infrastructure and are not supported accordingly.” This is “a serious mismatch.” Those who use Signal as intensively “as apparently NATO representatives or the federal government could think about how they can contribute,” she suggested.

In any case, the victims were manipulated by so-called social engineering in order to make the mistake of revealing their security codes. This can happen in any messenger service, the Signal President explained. When asked by Vice-President Andrea Lindholz (CSU) for a signal ban, Whittaker reacted with incomprehension. “All platforms of this magnitude are vulnerable.” The problem will be followed by migrant users “on all other services, and many of them are considerably more insecure per se.” “It is completely foreign to demand the prohibition of a single secure messenger service, while others remain completely unmentioned,” criticized the Left MP Donata Vogtschmidt on 29. April in a joint communication with her group colleague Sonja Lemke. The prohibition proposal distracts “from the real problem.” Lemke referred to inattentive behavior of app users that “no one can exclude.” Commercial competition

Lindholz has also called for the complete switch to apps from the manufacturer Wire. At the end of April, “via the Bundestag” this software had already been “pushed”, the left-wing politicians said. “Currently, it is the only messenger service that can be easily installed on the devices of the Bundestag,” explained Lemke. The company behind it has been lobbying »for years at the Bundestag«. It was heard in the Digital Committee that Wire was seeking to integrate its own product into the so-called Germany app.

The portal Heise Online had on the 28th. April reports on a letter from Klöckner, in which the President of the Bundestag recommended to all deputies the use of the Wire service. The report speaks of "an urgent appeal." The BSI had also already granted the product »Wire Bund« the approval for data of the secrecy level »observed matter – only for service use« at that time. Previously, the mirror had on 24. April reports that the Union faction is said to have already campaigned to use the messenger service Wire against its deputies in February after a warning letter from the constitutional protection.

In Berlin, the software provider apparently operates the technical development of the instant messenger through its Wire Germany GmbH. For the year 2023, it recorded a profit of around 270,000 euros, according to the annual financial statements. At 298,956 euros, the profit was slightly higher in the previous year. The company is 100 percent owned by Wire Group Holdings GmbH. Its managing director Benjamin François Schilz was named 9, according to the company. February 2024 brought on board as CEO to drive the “international expansion of Wire”. Schilz is also Managing Director of Wire Swiss GmbH, based in Zug. Wire has moved there after the seat in the USA was probably problematic mainly for image reasons – US companies are legally obliged to cooperate with intelligence agencies. Wire was originally founded by former employees of Apple, Skype, Nokia and Microsoft.

Wire had on the 11th. April 2024 his “strategic partnership” with the Schwarz Group announced. The goal: to drive “secure communication and data sovereignty in Germany and Europe”. The Schwarz Group includes the retail brands Lidl and Kaufland. The digital division is bundled in the Schwarz Digits KG. Commercial register entries show that as of 21. January, among others, Schwarz New Ventures GmbH is 26.4 percent, but also Roland Berger Industries GmbH, based in Munich, with 3.3 percent stake in Wire Group Holding. Zeta Holdings Luxembourg SA holds a further 10.2 percent. Wire Germany registered before the 1. January 2025 under Zeta Project Germany.

The two Left MPs suspect that the Wire push from Union circles “is also due to further lobbying of the Schwarz Group, which wants to place its product and which markets itself as a pioneer of digital sovereignty in Europe.”

11
 
 

Signal has introduced new in-app confirmations and warning messages as additional safeguards against phishing and social engineering attempts that could lead to various forms of fraud.

12
 
 

A friend of mine uses IOS. He has a version of signal 7.72.2. The issue is that he got an alert that signal would stop working the following day. (This happened 30 April)

"This version of Signal expires tomorrow. Update to the latest version."

The thing is, he went into the apple app store, updated it to the latest version (7.72.2) and still, he seems to not be able to use the app properly.

Now he can not send texts, only receive and I simply don't understand why because he did update to the latest version within the app store.

How does one fix this? Any suggestions?

13
 
 

#signal #privacy #expiration
I can't believe that. There is no fonctionnality to delete messages (text, images, videos) older than, for example, 6 months, one year, two years, and so on.
Ephemeral message is not a solution: max is 4 weeks, and only for new messages, not oldest.
That's completely crazy isn't it?
When When When ?

What @aboutsignal @signalapp @signal @signalapp

14
 
 

Title

I know there are some ways to imeoove it by allowing the app to always run in the background, but still it's very annoying and it happens constantly to me and many others. What is the root problem? Why don't other messaging apps have this problem?

15
 
 

Does anyone even use this? Or does anyone here have friends who regularly post on signal Stories?

Personally I have never seen anyone use it.

16
17
18
19
20
 
 

cross-posted from: https://lemmy.world/post/44029008

From the official Dutch Intelligence and Security Service


information.

“Despite their end-to-end encryption option, messaging apps such as Signal and WhatsApp should not be used as channels for classified, confidential or sensitive information,” states Director of the MIVD, vice-admiral Peter Reesink.

Individual accounts

An interesting aspect of this Russian campaign is that it does not exploit any technical vulnerabilities of the messaging services. The attackers instead make malicious use of legitimate security features of the apps. Director-General of the AIVD Simone Smit states, “It is not the case that Signal or WhatsApp as a whole have been compromised. Individual user accounts are being targeted.”

To increase resilience against this Russian campaign, MIVD and AIVD have published a Cyber Advisory explaining how to identify and respond to attacks. The advisory also give instructions for Signal users on how to identify potentially compromised contacts.

All Signal users can personally check whether there are any potentially compromised contacts in their group chats. If you see any people who appear twice in the list of members (under the same or a slightly different name), this may be evidence of either a compromised account or a new account created by a victim.If you suspect this to be the case, report this to the information security department of your organisation. Together you can try to verify (preferably using a channel other than Signal or WhatsApp, such as an email or a telephone call) whether it is correct that the account in question appears twice in the chat group contact list. Should this not be the case, ask the group administrator to remove both accounts from the group chat, after which the legitimate account holder can request to rejoin the group. Please remain vigilant for group members who are not recognised by the rest of the group. The actor may occasionally change the display name of a compromised account to remain unnoticed in chat groups, for example to names such as 'Deleted account'. If a member’s display name changes, the group will receive a notification. When the change is the legitimate transition to 'Deleted account', no notification is sent. Actor-controlled accounts can also gain entry to the group via an obtained Group Link, of which the group always receives a notification. In all such unauthorised scenarios, ask the group administrator to remove the offending accounts from the chat.If there is any indication that the group administrator themselves may have been compromised, it is advisable to exit the group and create a new one. |

21
22
1
submitted 6 months ago* (last edited 6 months ago) by steam_lover@sh.itjust.works to c/signal@lemmy.ml
23
1
submitted 6 months ago* (last edited 6 months ago) by xoron@programming.dev to c/signal@lemmy.ml
 
 

IMPORTANT: AI is used in this project, so lets get that out of the way. im not sure how to quantify it. i use different AI models on different tasks in the code as well as the documentation. i dont want to mislead or inspire undue confidence in this implementation. its open-source for transparency. not ready for general use.

its always worth mentioning this project is far from finished and i hope with feedback i can make it better. i have put efforts towards directing it towards unit-tests, audit and formal-proofs. none of that is good-enough, but i hope they can compliment each other and can act as a starting point for verifying the implementation is correct. the functionality is built around the requirements of my project. it isnt professionally audited or reviewed. use responsibly.

my motivation on this project is that im mainly working on a p2p messaging app. i hope you can understand the pushback i get when i promote my messaging app as “secure”, so this transparency with the signal protocol is nessesary. im sure people have better things to do with their time than review unstable and unfinished code. i only put it out there for you to take a look if you're interested. as a solo dev, there isnt anyone reviewing my code. if i dont share it like this, no one will come across it.


The implementation is in rust and compiles to WASM for browser-based usage.

The aim is for it to align with the official implementation (https://github.com/signalapp/libsignal). That version was not used because my use case required client side browser-based functionality and i struggled to achieve that in the official one where javascript is used but is targeting nodejs.

There are other nuances to my approach like using module federation, which led to me moving away from the official version.

This signal-protocol implementation is purpose-built for a p2p messaging app. i posted about it a couple months ago here: https://programming.dev/post/43579394

24
1
submitted 6 months ago* (last edited 6 months ago) by steam_lover@sh.itjust.works to c/signal@lemmy.ml
25
view more: next ›