Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

you are viewing a single comment's thread
view the rest of the comments
[–] 10 points 1 day ago (5 children)

Curious to see how Signal will mitigate against this

  • source
  • hideshow 5 child comments
  • [–] 3 points 16 hours ago

    they did not disclose how have they done it for signal, and than mentioning linked devices. it could be that they got access to a linked computer of the user, and copied messages that way. there is not much signal could do against this. afaik the app already uses the system keystore to store api keys, and to partially encrypt its data, but the system keystore is often not so strong because its automatically unlocked

  • source
  • parent
  • [–] 16 points 1 day ago (2 children)

    Signal doesn't sync previous history so only new messages since linking are affected. I guess sending notifications to previous devices about link status would be helpful.

    Last I checked linked devices could only be computers, and linking didn't involve phone numbers at all, so sim cloning and sms interception shouldn't work, only qr linking, but I'm not sure that still is the case

  • source
  • parent
  • hideshow 2 child comments