this post was submitted on 12 Sep 2026
64 points (97.1% liked)

Technology

87956 readers
2606 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

top 15 comments
sorted by: hot top controversial new old
[–] peopleproblems@lemmy.world 18 points 57 minutes ago

Interesting they highlight Signal again as though this is a vulnerability.

If someone else has access to a linked device... that's you fucking up access controls.

[–] homesweethomeMrL@lemmy.world 4 points 29 minutes ago

Signal failed to prevent soneone from accessing my unlocked phone and starting Signal! Everything was right there!

[–] odama626@lemmy.world 1 points 1 minute ago

Signal in this was clickbait they literally just say oh well if someone can link in their device they can see 45 days of message history

[–] GreenKnight23@lemmy.world 2 points 21 minutes ago

you know what would solve this? simplex.

[–] time2lose@lemmy.world 15 points 2 hours ago (2 children)

Telegram and whatsapp never had encryption. Also - they just give your messages on law enforcement request, always have.

Signal - how does it work with signal again?

[–] FriendOfDeSoto@startrek.website 5 points 1 hour ago (1 children)

They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.

Which is clever, to be fair. Whether or not that's legal is already a court case. The law is so frightfully grey.

[–] peopleproblems@lemmy.world 5 points 55 minutes ago

Its also a failure of the user's access control and operating security.

Once a third party has access to the secure environment, that environment is and will always be compromised.

You don't ask too many questions about signal cos the answers don't make you any more confident.

[–] SnotFlickerman@lemmy.blahaj.zone 39 points 3 hours ago (1 children)

Open source FIDO2 keys, KeePassXC, and Aegis.

SMS 2fa has always been a bad deal

[–] Brewchin@lemmy.world 26 points 3 hours ago (1 children)

I'll never understand why people accept SMS 2FA as any kind of security. Might as well put it as an ad in a newspaper. 🤦🏻‍♂️

[–] Crumpled6273@lemmy.ca 17 points 2 hours ago* (last edited 2 hours ago) (1 children)

Because many services only have SMS as 2FA option. Especially government services.

Also it is impossible to use google without enabling the SMS 2FA option. No matter what, with only 2FA authenticator app or email, they will lock down the account by saying "unable to verify".

[–] cmnybo@discuss.tchncs.de 3 points 2 hours ago

I never set a phone number on two of my google accounts and they still work fine. Those accounts are old. Google didn't ask for a phone number to sign up back then.

I recall seeing something about them planning to get rid of SMS 2FA last year. It looks like it's still an option though.

[–] muntedcrocodile@hilariouschaos.com 0 points 1 hour ago* (last edited 1 hour ago) (1 children)

There have been too many of these types of events related to signal. And it has so many red flags. You are required to have a phone number which is essentially ur real identity. They used to federate with 3rd party servers but they killed that and all but wiped it from the internet. They try to shut down 3rd party clients. They don't provide reproducible builds so we can't trust the source. They received their initial funding from In-Q-Tel the CIA venture capital firm.

Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.

At minimum they have a full social graph of real identities with time-stamped message events. Sealed sender doesn't negate this as signal knows ur ip address when u give them a message. They also know the destination of that message as that isn't sealed. This is sufficient information to link sender and recipient and timestamp. That's assuming the unreproducible builds don't have backdoors.

It's all got a slightly fishy smell to it.

Tldr: If u want actual secure messaging u should consider SimpleX

[–] DomeGuy@lemmy.world 3 points 46 minutes ago (1 children)

There are all of these stories about signal because it is notable when someone gets around it

That there's anything approaching secure communication on a cell-phone dominated Internet whose.operating systems are either "snobbish walled garden" or "ad agency living in the corpse of a search engine" is astonishing. In the same way that a gun safety that keeps a toddler from shooting themselves with an otherwise loaded gun is astonishing.

[–] GreenKnight23@lemmy.world 1 points 19 minutes ago

can't get around simplex encryption unless you have physical access to the device or have been physically invited by a member.