lemmy.mair.io
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
jeffw@lemmy.world to Technology@lemmy.worldEnglish · 4 months ago

How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

www.wired.com

external-link
message-square
33
fedilink
304
external-link

How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

www.wired.com

jeffw@lemmy.world to Technology@lemmy.worldEnglish · 4 months ago
message-square
33
fedilink
  • disguy_ovahea@lemmy.world
    link
    fedilink
    English
    arrow-up
    36
    ·
    4 months ago

    Signal uses end-to-end encryption (E2EE). The only copies of messages are on the sender’s and recipient’s devices.

    https://support.signal.org/hc/en-us/articles/360007320391-Is-it-private-Can-I-trust-it#%3A~%3Atext=Signal+conversations+are+always+end%2C%2C+every+call%2C+every+time.

    • Ulrich@feddit.org
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      58
      ·
      4 months ago

      Copies of messages are also known as archives.

      • tehsYs@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        41
        arrow-down
        1
        ·
        4 months ago

        Signal does not archive messages on server side

        • Ulrich@feddit.org
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          51
          ·
          edit-2
          4 months ago

          They weren’t talking about the server:

          This app…works in almost exactly the same way as Signal, except that it also archives copies of all the messages passing through it, shattering all of its security guarantees.

          • ShittyBeatlesFCPres@lemmy.world
            link
            fedilink
            English
            arrow-up
            40
            ·
            4 months ago

            Later in the article, it talks specifically about the server-side archives being stored in plain text. That’s why the hacker was able to access messages. This isn’t about the local copies on phones.

            • Ulrich@feddit.org
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              55
              ·
              4 months ago

              Yeah I didn’t read past the misinformation

              • AbidanYre@lemmy.world
                link
                fedilink
                English
                arrow-up
                32
                ·
                edit-2
                4 months ago

                Kinda seems like you’re the misinformation.

                • Ulrich@feddit.org
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  26
                  ·
                  edit-2
                  4 months ago

                  You’re confused, I am not the author of this article. I did not write the statement above, just copied and pasted it here.

                  • AbidanYre@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    18
                    arrow-down
                    1
                    ·
                    4 months ago

                    I’m not confused, you’re intentionally misreading what’s happening for some reason.

                    “Passing through it” pretty clearly refers to the server as that’s what was hacked into and had plain text archives.

                    You’re hyper fixating on the fact that the article says “the app” when referring to both the phone and server pieces to try and argue… something.

              • doodledup@lemmy.world
                link
                fedilink
                English
                arrow-up
                14
                ·
                4 months ago

                Maybe you should start reading up on stuff you don’t know about before adding nonsense to internet threads.

                • Ulrich@feddit.org
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  24
                  ·
                  edit-2
                  4 months ago

                  Don’t know what you mean. I didn’t add any “nonsense”. Just a direct quote from the article in question.

                  • doodledup@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    3
                    ·
                    4 months ago

                    Totally /s Can’t even read your own comments.

          • disguy_ovahea@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            4 months ago

            The only backup option I see for Signal is through Android, but it’s optional. There is no backup support for iOS or desktop.

            https://support.signal.org/hc/en-us/articles/360007059752-Backup-and-Restore-Messages

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1.02K users / day
  • 4.18K users / week
  • 9.79K users / month
  • 25K users / 6 months
  • 1 local subscriber
  • 75.1K subscribers
  • 4.72K Posts
  • 68.5K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • BE: 0.19.9
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org