This is a Phishing attack, just so we're clear, they haven't broken the encryption. They gain access by tricking you into clicking malicious links or scanning fake QR codes. As long as you stay vigilant you should be fine, make sure to warn other people in your life though who might not be as keen on this though, they can easily be compromised, and if they share conversations with you it can indirectly affect you if they are.
Privacy
Protect your privacy in the digital world
Welcome! This is a community for all those who are interested in protecting their privacy.
Rules
PS: Don't be a smartass and try to game the system, we'll know if you're breaking the rules when we see it!
- Be nice, civil and no bigotry/prejudice.
- No tankies/alt-right fascists. The former can be tolerated but the latter are banned.
- Stay on topic.
- Don't promote proprietary software.
- No crypto, blockchain, etc.
- No Xitter links. (only allowed when can't fact check any other way, use xcancel)
- If in doubt, read rule 1
Related communities:
- !opensource@programming.dev
- !selfhosting@slrpnk.net / !selfhosted@lemmy.world
- !piracy@lemmy.dbzer0.com
To be clear: these are phishing techniques. They aren’t breaking the encryption, they’re getting the user to let them in.
That’s good to know! I was worried they were breaking the encryption.
Yes; they are not breaking it, but they have developed malicious QR codes, which the user expects to be the link device QR, but is actually giving them access to their messages.
Russia-backed hackers are attempting to compromise Signal’s “linked devices” capability, which allows Signal users to link their messaging account to multiple devices, including phones and laptops, using a quick response (QR) code.
Google threat analysts report that Russia-linked threat actors have developed malicious QR codes that, when scanned, will give the threat actor real-time access to the victim’s messages without having to compromise the victim’s phone or computer.
Who is scanning random qr codes into signal?
I scam every one I see
Before I even read: it's phishing, and it's nothing new. There's no evidence supporting anyone has broken this level of E2EE.
After reading: oh look. Surprise. This is my surprised face.
This just screams of "we want backdoors to be forced into encrypted things so we have even more control"
Security is only as good as it's weakest link, which is almost always the end user. These attacks do not compromise Signal the protocol (e.g seeing in-flight data), they are focusing on hijacking account information to gain access.
Clearly the solution is giving back doors only to the government.