Diagon Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@jeffw@lemmy.world to Technology@lemmy.worldEnglish • 15 days ago

How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

www.wired.com

external-link
message-square
45
fedilink
367
external-link

How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

www.wired.com

@jeffw@lemmy.world to Technology@lemmy.worldEnglish • 15 days ago
message-square
45
fedilink
The company behind the Signal clone used by at least one Trump administration official was breached earlier this month. The hacker says they got in thanks to a basic misconfiguration.
  • Ulrich
    link
    fedilink
    English
    -66•15 days ago

    works in almost exactly the same way as Signal, except that it also archives copies of all the messages passing through it, shattering all of its security guarantees.

    Pretty sure Signal does that as well, which is not a security issue.

    • @disguy_ovahea@lemmy.world
      link
      fedilink
      English
      47•15 days ago

      Signal uses end-to-end encryption (E2EE). The only copies of messages are on the sender’s and recipient’s devices.

      https://support.signal.org/hc/en-us/articles/360007320391-Is-it-private-Can-I-trust-it#%3A~%3Atext=Signal+conversations+are+always+end%2C%2C+every+call%2C+every+time.

      • Ulrich
        link
        fedilink
        English
        -62•15 days ago

        Copies of messages are also known as archives.

        • tehsYs
          link
          fedilink
          English
          50•15 days ago

          Signal does not archive messages on server side

          • Ulrich
            link
            fedilink
            English
            -55•
            edit-2
            15 days ago

            They weren’t talking about the server:

            This app…works in almost exactly the same way as Signal, except that it also archives copies of all the messages passing through it, shattering all of its security guarantees.

            • @ShittyBeatlesFCPres@lemmy.world
              link
              fedilink
              English
              52•15 days ago

              Later in the article, it talks specifically about the server-side archives being stored in plain text. That’s why the hacker was able to access messages. This isn’t about the local copies on phones.

              • Ulrich
                link
                fedilink
                English
                -62•15 days ago

                Yeah I didn’t read past the misinformation

                • @AbidanYre@lemmy.world
                  link
                  fedilink
                  English
                  39•
                  edit-2
                  14 days ago

                  Kinda seems like you’re the misinformation.

                  • Ulrich
                    link
                    fedilink
                    English
                    -29•
                    edit-2
                    14 days ago

                    You’re confused, I am not the author of this article. I did not write the statement above, just copied and pasted it here.

                • @doodledup@lemmy.world
                  link
                  fedilink
                  English
                  17•14 days ago

                  Maybe you should start reading up on stuff you don’t know about before adding nonsense to internet threads.

                  • NekuSoul
                    link
                    fedilink
                    English
                    11•14 days ago

                    This is now the third post in the last 24 hours where I stumble into a needlessly long thread because this user is completely obtuse and can’t handle being wrong or a different opinion.

                  • Ulrich
                    link
                    fedilink
                    English
                    -28•
                    edit-2
                    14 days ago

                    Don’t know what you mean. I didn’t add any “nonsense”. Just a direct quote from the article in question.

            • OmegaSunkey
              link
              fedilink
              English
              7•15 days ago

              It’s why Molly has local database encryption.

              • @0xD@infosec.pub
                link
                fedilink
                English
                -2•15 days ago

                That doesn’t really do anything. Attackers need local access to the device to get the database itself. Chances are, they’ll get the key right with it.

                • @HappyTimeHarry@lemm.ee
                  link
                  fedilink
                  English
                  7•15 days ago

                  Molly encrypts it using a passphrase instead of a locally stored key for exactly that reason.

                  • @0xD@infosec.pub
                    link
                    fedilink
                    English
                    1•14 days ago

                    The passphrase or the unencrypted database are still open in memory. Though that is, of course, a more complicated attack but they could simply read it through the app itself.

            • @disguy_ovahea@lemmy.world
              link
              fedilink
              English
              4•15 days ago

              The only backup option I see for Signal is through Android, but it’s optional. There is no backup support for iOS or desktop.

              https://support.signal.org/hc/en-us/articles/360007059752-Backup-and-Restore-Messages

Technology@lemmy.world

!technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
  • 4.73K users / day
  • 9.86K users / week
  • 17K users / month
  • 36.8K users / 6 months
  • 70.5K subscribers
  • 9.74K Posts
  • 290K Comments
  • Modlog
  • mods:
  • @L3s@lemmy.world
  • enu
  • Technopagan
  • L4sBot
  • L3s
  • @L4s@hackingne.ws
  • BE: 0.19.3
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org