▲ 411 ▼ German police read Signal, Telegram, WhatsApp messages without breaking encryption (cybernews.com) submitted 4 weeks ago* by schizoidman@lemmy.zip to c/technology@lemmy.world 114 comments fedilink hide all child comments cross-posted from : https://lemmy.zip/post/71321898 Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance
[–] GreenKnight23@lemmy.world 1 point 4 weeks ago (23 children) you know what would solve this? simplex. permalink fedilink source hideshow 23 child comments replies: [–] yestalgia@lemmy.world 12 points 4 weeks ago (11 children) "Just get everyone in your life to move to ______ and that will solve all your problems" A suggestion as old as time permalink fedilink source parent hideshow 11 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago (10 children) it's one of the most secure message apps available. messages are signed, encrypted and passed through servers, never left on the server. unless you were the intended recipient you will not decrypt it. it's the truecrypt of instant messaging. permalink fedilink source parent hideshow 10 child comments replies: [–] Natanael@infosec.pub 2 points 4 weeks ago (9 children) Signal does all that already permalink fedilink source parent hideshow 9 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (8 children) signal has a closed source server that can't be audited. permalink fedilink source parent hideshow 8 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (7 children) https://github.com/signalapp/Signal-Server That changed permalink fedilink source parent hideshow 7 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago (6 children) what does it need a database for? simplex is literally a message broker. no data remains on the server. permalink fedilink source parent hideshow 6 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (4 children) Signal doesn't keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don't have your metadata. permalink fedilink source parent hideshow 4 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (3 children) then why does it have a database? permalink fedilink source parent hideshow 3 child comments replies: [–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Because sometimes, people are not online 24/7 and messages still need to reach them when possible. permalink fedilink source parent [–] fonix232@fedia.io 7 points 4 weeks ago (10 children) Oh really? Simplex would block someone from accessing your phone and thus Simplex' data? permalink fedilink source parent hideshow 10 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago* (9 children) give me a list of messaging apps that stop attacks that leverage physical access. use a better os that has encryption and kill codes if that's your concern. permalink fedilink source parent hideshow 9 child comments replies: [–] vald@mbin.linuxnation.social 5 points 4 weeks ago (8 children) give me a list of messaging apps that stop attacks that leverage physical access. you know what would solve this? simplex. um... permalink fedilink source parent hideshow 8 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (7 children) either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance why are you so against people using a more secure way to communicate? permalink fedilink source parent hideshow 7 child comments replies: [–] WhyJiffie@sh.itjust.works 2 points 4 weeks ago (5 children) the only time they mention signal is when they explain they used linked devices to obtain signal messages. not SMS! if you lose your phone or whatever, and log in on a new device, your messages won't magically reappear, they are lost, and all your contacts get a warning that your safety numbers have changed. permalink fedilink source parent hideshow 5 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (4 children) simplex messages stay on your phone. you can't switch phones and have them follow you because there's no way to sign in because there's no account for you to sign in with. simplex doesn't require a phone number or email. the trust is made between users, keeping users safer because it requires physical access between users. sure you can share your code over SMS or otherwise, but that's a user issue that breaks usage policy, not a problem with the software. permalink fedilink source parent hideshow 4 child comments replies: [–] WhyJiffie@sh.itjust.works 1 point 4 weeks ago (3 children) simplex messages stay on your phone I think that's what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data. permalink fedilink source parent hideshow 3 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (2 children) if it can transfer the data, there's more opportunity to successfully steal it. convenience will always negate security. permalink fedilink source parent hideshow 2 child comments replies: [–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Intercepting a verification code with signal does not allow reading messages. permalink fedilink source parent
[–] yestalgia@lemmy.world 12 points 4 weeks ago (11 children) "Just get everyone in your life to move to ______ and that will solve all your problems" A suggestion as old as time permalink fedilink source parent hideshow 11 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago (10 children) it's one of the most secure message apps available. messages are signed, encrypted and passed through servers, never left on the server. unless you were the intended recipient you will not decrypt it. it's the truecrypt of instant messaging. permalink fedilink source parent hideshow 10 child comments replies: [–] Natanael@infosec.pub 2 points 4 weeks ago (9 children) Signal does all that already permalink fedilink source parent hideshow 9 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (8 children) signal has a closed source server that can't be audited. permalink fedilink source parent hideshow 8 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (7 children) https://github.com/signalapp/Signal-Server That changed permalink fedilink source parent hideshow 7 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago (6 children) what does it need a database for? simplex is literally a message broker. no data remains on the server. permalink fedilink source parent hideshow 6 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (4 children) Signal doesn't keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don't have your metadata. permalink fedilink source parent hideshow 4 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (3 children) then why does it have a database? permalink fedilink source parent hideshow 3 child comments replies: [–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Because sometimes, people are not online 24/7 and messages still need to reach them when possible. permalink fedilink source parent
[–] GreenKnight23@lemmy.world -1 points 4 weeks ago (10 children) it's one of the most secure message apps available. messages are signed, encrypted and passed through servers, never left on the server. unless you were the intended recipient you will not decrypt it. it's the truecrypt of instant messaging. permalink fedilink source parent hideshow 10 child comments replies: [–] Natanael@infosec.pub 2 points 4 weeks ago (9 children) Signal does all that already permalink fedilink source parent hideshow 9 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (8 children) signal has a closed source server that can't be audited. permalink fedilink source parent hideshow 8 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (7 children) https://github.com/signalapp/Signal-Server That changed permalink fedilink source parent hideshow 7 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago (6 children) what does it need a database for? simplex is literally a message broker. no data remains on the server. permalink fedilink source parent hideshow 6 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (4 children) Signal doesn't keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don't have your metadata. permalink fedilink source parent hideshow 4 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (3 children) then why does it have a database? permalink fedilink source parent hideshow 3 child comments replies: [–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Because sometimes, people are not online 24/7 and messages still need to reach them when possible. permalink fedilink source parent
[–] Natanael@infosec.pub 2 points 4 weeks ago (9 children) Signal does all that already permalink fedilink source parent hideshow 9 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (8 children) signal has a closed source server that can't be audited. permalink fedilink source parent hideshow 8 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (7 children) https://github.com/signalapp/Signal-Server That changed permalink fedilink source parent hideshow 7 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago (6 children) what does it need a database for? simplex is literally a message broker. no data remains on the server. permalink fedilink source parent hideshow 6 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (4 children) Signal doesn't keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don't have your metadata. permalink fedilink source parent hideshow 4 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (3 children) then why does it have a database? permalink fedilink source parent hideshow 3 child comments replies: [–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Because sometimes, people are not online 24/7 and messages still need to reach them when possible. permalink fedilink source parent
[–] GreenKnight23@lemmy.world 0 points 4 weeks ago (8 children) signal has a closed source server that can't be audited. permalink fedilink source parent hideshow 8 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (7 children) https://github.com/signalapp/Signal-Server That changed permalink fedilink source parent hideshow 7 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago (6 children) what does it need a database for? simplex is literally a message broker. no data remains on the server. permalink fedilink source parent hideshow 6 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (4 children) Signal doesn't keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don't have your metadata. permalink fedilink source parent hideshow 4 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (3 children) then why does it have a database? permalink fedilink source parent hideshow 3 child comments replies: [–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Because sometimes, people are not online 24/7 and messages still need to reach them when possible. permalink fedilink source parent
[–] Natanael@infosec.pub 1 point 4 weeks ago (7 children) https://github.com/signalapp/Signal-Server That changed permalink fedilink source parent hideshow 7 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago (6 children) what does it need a database for? simplex is literally a message broker. no data remains on the server. permalink fedilink source parent hideshow 6 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (4 children) Signal doesn't keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don't have your metadata. permalink fedilink source parent hideshow 4 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (3 children) then why does it have a database? permalink fedilink source parent hideshow 3 child comments replies: [–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Because sometimes, people are not online 24/7 and messages still need to reach them when possible. permalink fedilink source parent
[–] GreenKnight23@lemmy.world -1 points 4 weeks ago (6 children) what does it need a database for? simplex is literally a message broker. no data remains on the server. permalink fedilink source parent hideshow 6 child comments replies: [–] Natanael@infosec.pub 1 point 4 weeks ago (4 children) Signal doesn't keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don't have your metadata. permalink fedilink source parent hideshow 4 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (3 children) then why does it have a database? permalink fedilink source parent hideshow 3 child comments replies: [–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Because sometimes, people are not online 24/7 and messages still need to reach them when possible. permalink fedilink source parent
[–] Natanael@infosec.pub 1 point 4 weeks ago (4 children) Signal doesn't keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don't have your metadata. permalink fedilink source parent hideshow 4 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (3 children) then why does it have a database? permalink fedilink source parent hideshow 3 child comments replies: [–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent
[–] GreenKnight23@lemmy.world 0 points 4 weeks ago (3 children) then why does it have a database? permalink fedilink source parent hideshow 3 child comments replies: [–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent
[–] Natanael@infosec.pub 0 points 4 weeks ago (2 children) Here's what he documentation says; Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days. ... Or wait... Oops, that was from Simplex, who has a database, that didn't come from Signal's documentation https://github.com/simplex-chat/simplexmq/blob/master/protocol/overview-tjr.md permalink fedilink source parent hideshow 2 child comments replies: [–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent
[–] GreenKnight23@lemmy.world 2 points 4 weeks ago (1 child) cherry picking. By default, routers do not retain access logs, and permanently delete messages and queues when requested. Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.[0] There is still a risk that a router maliciously records all queues and messages (even though encrypted) sent via the same transport connection to gain a partial knowledge of the user's communications graph and other meta-data. what this means is don't blindly trust a random public router. if you host your own router, you can set the threshold to hours or seconds. you can also ensure that your router isn't maliciously storing records. simplex uses an in-memory queue to store messages for delivery. if the server was extracted for legal measures, this means the messages are erased and difficult if not impossible to collect. for signal, they are written to disk. this means there is evidence of communications between users. even if you host your own signal server, it will be there. permalink fedilink source parent hideshow 1 child comment replies: [–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent
[–] Natanael@infosec.pub -1 points 4 weeks ago* (last edited 3 weeks ago) Liar You're claiming Signal does these things when it doesn't, and claim Simplex doesn't do what's in the documentation By the way, the Simplex CEO supports nazis permalink fedilink source parent
[–] cley_faye@lemmy.world 0 points 4 weeks ago Because sometimes, people are not online 24/7 and messages still need to reach them when possible. permalink fedilink source parent
[–] fonix232@fedia.io 7 points 4 weeks ago (10 children) Oh really? Simplex would block someone from accessing your phone and thus Simplex' data? permalink fedilink source parent hideshow 10 child comments replies: [–] GreenKnight23@lemmy.world -1 points 4 weeks ago* (9 children) give me a list of messaging apps that stop attacks that leverage physical access. use a better os that has encryption and kill codes if that's your concern. permalink fedilink source parent hideshow 9 child comments replies: [–] vald@mbin.linuxnation.social 5 points 4 weeks ago (8 children) give me a list of messaging apps that stop attacks that leverage physical access. you know what would solve this? simplex. um... permalink fedilink source parent hideshow 8 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (7 children) either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance why are you so against people using a more secure way to communicate? permalink fedilink source parent hideshow 7 child comments replies: [–] WhyJiffie@sh.itjust.works 2 points 4 weeks ago (5 children) the only time they mention signal is when they explain they used linked devices to obtain signal messages. not SMS! if you lose your phone or whatever, and log in on a new device, your messages won't magically reappear, they are lost, and all your contacts get a warning that your safety numbers have changed. permalink fedilink source parent hideshow 5 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (4 children) simplex messages stay on your phone. you can't switch phones and have them follow you because there's no way to sign in because there's no account for you to sign in with. simplex doesn't require a phone number or email. the trust is made between users, keeping users safer because it requires physical access between users. sure you can share your code over SMS or otherwise, but that's a user issue that breaks usage policy, not a problem with the software. permalink fedilink source parent hideshow 4 child comments replies: [–] WhyJiffie@sh.itjust.works 1 point 4 weeks ago (3 children) simplex messages stay on your phone I think that's what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data. permalink fedilink source parent hideshow 3 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (2 children) if it can transfer the data, there's more opportunity to successfully steal it. convenience will always negate security. permalink fedilink source parent hideshow 2 child comments replies: [–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Intercepting a verification code with signal does not allow reading messages. permalink fedilink source parent
[–] GreenKnight23@lemmy.world -1 points 4 weeks ago* (9 children) give me a list of messaging apps that stop attacks that leverage physical access. use a better os that has encryption and kill codes if that's your concern. permalink fedilink source parent hideshow 9 child comments replies: [–] vald@mbin.linuxnation.social 5 points 4 weeks ago (8 children) give me a list of messaging apps that stop attacks that leverage physical access. you know what would solve this? simplex. um... permalink fedilink source parent hideshow 8 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (7 children) either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance why are you so against people using a more secure way to communicate? permalink fedilink source parent hideshow 7 child comments replies: [–] WhyJiffie@sh.itjust.works 2 points 4 weeks ago (5 children) the only time they mention signal is when they explain they used linked devices to obtain signal messages. not SMS! if you lose your phone or whatever, and log in on a new device, your messages won't magically reappear, they are lost, and all your contacts get a warning that your safety numbers have changed. permalink fedilink source parent hideshow 5 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (4 children) simplex messages stay on your phone. you can't switch phones and have them follow you because there's no way to sign in because there's no account for you to sign in with. simplex doesn't require a phone number or email. the trust is made between users, keeping users safer because it requires physical access between users. sure you can share your code over SMS or otherwise, but that's a user issue that breaks usage policy, not a problem with the software. permalink fedilink source parent hideshow 4 child comments replies: [–] WhyJiffie@sh.itjust.works 1 point 4 weeks ago (3 children) simplex messages stay on your phone I think that's what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data. permalink fedilink source parent hideshow 3 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (2 children) if it can transfer the data, there's more opportunity to successfully steal it. convenience will always negate security. permalink fedilink source parent hideshow 2 child comments replies: [–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Intercepting a verification code with signal does not allow reading messages. permalink fedilink source parent
[–] vald@mbin.linuxnation.social 5 points 4 weeks ago (8 children) give me a list of messaging apps that stop attacks that leverage physical access. you know what would solve this? simplex. um... permalink fedilink source parent hideshow 8 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (7 children) either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance why are you so against people using a more secure way to communicate? permalink fedilink source parent hideshow 7 child comments replies: [–] WhyJiffie@sh.itjust.works 2 points 4 weeks ago (5 children) the only time they mention signal is when they explain they used linked devices to obtain signal messages. not SMS! if you lose your phone or whatever, and log in on a new device, your messages won't magically reappear, they are lost, and all your contacts get a warning that your safety numbers have changed. permalink fedilink source parent hideshow 5 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (4 children) simplex messages stay on your phone. you can't switch phones and have them follow you because there's no way to sign in because there's no account for you to sign in with. simplex doesn't require a phone number or email. the trust is made between users, keeping users safer because it requires physical access between users. sure you can share your code over SMS or otherwise, but that's a user issue that breaks usage policy, not a problem with the software. permalink fedilink source parent hideshow 4 child comments replies: [–] WhyJiffie@sh.itjust.works 1 point 4 weeks ago (3 children) simplex messages stay on your phone I think that's what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data. permalink fedilink source parent hideshow 3 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (2 children) if it can transfer the data, there's more opportunity to successfully steal it. convenience will always negate security. permalink fedilink source parent hideshow 2 child comments replies: [–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Intercepting a verification code with signal does not allow reading messages. permalink fedilink source parent
[–] GreenKnight23@lemmy.world 1 point 4 weeks ago (7 children) either through physical access to someone’s phone OR by intercepting verification codes via a state-sanctioned phishing attack OR intercepting SMS messages via telephone surveillance why are you so against people using a more secure way to communicate? permalink fedilink source parent hideshow 7 child comments replies: [–] WhyJiffie@sh.itjust.works 2 points 4 weeks ago (5 children) the only time they mention signal is when they explain they used linked devices to obtain signal messages. not SMS! if you lose your phone or whatever, and log in on a new device, your messages won't magically reappear, they are lost, and all your contacts get a warning that your safety numbers have changed. permalink fedilink source parent hideshow 5 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (4 children) simplex messages stay on your phone. you can't switch phones and have them follow you because there's no way to sign in because there's no account for you to sign in with. simplex doesn't require a phone number or email. the trust is made between users, keeping users safer because it requires physical access between users. sure you can share your code over SMS or otherwise, but that's a user issue that breaks usage policy, not a problem with the software. permalink fedilink source parent hideshow 4 child comments replies: [–] WhyJiffie@sh.itjust.works 1 point 4 weeks ago (3 children) simplex messages stay on your phone I think that's what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data. permalink fedilink source parent hideshow 3 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (2 children) if it can transfer the data, there's more opportunity to successfully steal it. convenience will always negate security. permalink fedilink source parent hideshow 2 child comments replies: [–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent [–] cley_faye@lemmy.world 0 points 4 weeks ago Intercepting a verification code with signal does not allow reading messages. permalink fedilink source parent
[–] WhyJiffie@sh.itjust.works 2 points 4 weeks ago (5 children) the only time they mention signal is when they explain they used linked devices to obtain signal messages. not SMS! if you lose your phone or whatever, and log in on a new device, your messages won't magically reappear, they are lost, and all your contacts get a warning that your safety numbers have changed. permalink fedilink source parent hideshow 5 child comments replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago (4 children) simplex messages stay on your phone. you can't switch phones and have them follow you because there's no way to sign in because there's no account for you to sign in with. simplex doesn't require a phone number or email. the trust is made between users, keeping users safer because it requires physical access between users. sure you can share your code over SMS or otherwise, but that's a user issue that breaks usage policy, not a problem with the software. permalink fedilink source parent hideshow 4 child comments replies: [–] WhyJiffie@sh.itjust.works 1 point 4 weeks ago (3 children) simplex messages stay on your phone I think that's what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data. permalink fedilink source parent hideshow 3 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (2 children) if it can transfer the data, there's more opportunity to successfully steal it. convenience will always negate security. permalink fedilink source parent hideshow 2 child comments replies: [–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent
[–] GreenKnight23@lemmy.world 0 points 4 weeks ago (4 children) simplex messages stay on your phone. you can't switch phones and have them follow you because there's no way to sign in because there's no account for you to sign in with. simplex doesn't require a phone number or email. the trust is made between users, keeping users safer because it requires physical access between users. sure you can share your code over SMS or otherwise, but that's a user issue that breaks usage policy, not a problem with the software. permalink fedilink source parent hideshow 4 child comments replies: [–] WhyJiffie@sh.itjust.works 1 point 4 weeks ago (3 children) simplex messages stay on your phone I think that's what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data. permalink fedilink source parent hideshow 3 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (2 children) if it can transfer the data, there's more opportunity to successfully steal it. convenience will always negate security. permalink fedilink source parent hideshow 2 child comments replies: [–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent
[–] WhyJiffie@sh.itjust.works 1 point 4 weeks ago (3 children) simplex messages stay on your phone I think that's what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data. permalink fedilink source parent hideshow 3 child comments replies: [–] GreenKnight23@lemmy.world 1 point 4 weeks ago (2 children) if it can transfer the data, there's more opportunity to successfully steal it. convenience will always negate security. permalink fedilink source parent hideshow 2 child comments replies: [–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent
[–] GreenKnight23@lemmy.world 1 point 4 weeks ago (2 children) if it can transfer the data, there's more opportunity to successfully steal it. convenience will always negate security. permalink fedilink source parent hideshow 2 child comments replies: [–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent
[–] WhyJiffie@sh.itjust.works 0 points 4 weeks ago (1 child) I have bad news for you, simplex also has this "security flaw": https://simplex.chat/docs/guide/managing-data.html permalink fedilink source parent hideshow 1 child comment replies: [–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent
[–] GreenKnight23@lemmy.world 0 points 4 weeks ago cool. so then signal is just as good as simplex. permalink fedilink source parent
[–] cley_faye@lemmy.world 0 points 4 weeks ago Intercepting a verification code with signal does not allow reading messages. permalink fedilink source parent