cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

you are viewing a single comment's thread
view the rest of the comments
[–] 21 points 2 days ago (3 children)

They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.

Which is clever, to be fair. Whether or not that's legal is already a court case. The law is so frightfully grey.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 14 points 2 days ago (2 children)

    Its also a failure of the user's access control and operating security.

    Once a third party has access to the secure environment, that environment is and will always be compromised.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 days ago (1 child)

    Is the user made aware of this by the operator (signal, telegram, et al)?

    If not, it's a big haul to get to competency. The operator should be educating users on how to limit compromise.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 2 days ago
    1. It NEVER advertises itself as such.

    2. IIRC Signal DOES warn you about this, first when you make an account, and then when you try to save media files, and when you try to start a group chat. The others aren't remotely secure anyway and I have no interest in attempting to defend them.

  • source
  • parent