this post was submitted on 12 Sep 2026
408 points (96.2% liked)

Technology

88301 readers
3002 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

top 50 comments
sorted by: hot top controversial new old
[–] peopleproblems@lemmy.world 173 points 2 weeks ago (16 children)

Interesting they highlight Signal again as though this is a vulnerability.

If someone else has access to a linked device... that's you fucking up access controls.

load more comments (16 replies)
[–] homesweethomeMrL@lemmy.world 103 points 2 weeks ago (1 children)

Signal failed to prevent soneone from accessing my unlocked phone and starting Signal! Everything was right there!

[–] Zarobi@aussie.zone 12 points 2 weeks ago (14 children)

On iOS you can set an app to require additional credentials to open, to prevent this situation. I'd imagine Android had something similar. I did it for all my important apps, just in case. Don't want someone able to access my bank account ~~or nudes~~.

[–] Igris@feddit.org 23 points 2 weeks ago

You can lock Signal. It's in it's privacy settings.

[–] Azzu@leminal.space 15 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

If someone can get unlocked access to your phone, your security practices are already insufficient. If you really want to prevent something like this, you need to make this first step impossible, not add a bandaid on top of it.

[–] Zarobi@aussie.zone 6 points 2 weeks ago

Real life isn't that clean. Security is about layers and making things as difficult as possible; there is never a single step which will fully protect you from everything

load more comments (12 replies)
[–] SnotFlickerman@lemmy.blahaj.zone 84 points 2 weeks ago (2 children)

Open source FIDO2 keys, KeePassXC, and Aegis.

SMS 2fa has always been a bad deal

[–] Brewchin@lemmy.world 53 points 2 weeks ago (1 children)

I'll never understand why people accept SMS 2FA as any kind of security. Might as well put it as an ad in a newspaper. 🤦🏻‍♂️

[–] Crumpled6273@lemmy.ca 54 points 2 weeks ago* (last edited 2 weeks ago) (8 children)

Because many services only have SMS as 2FA option. Especially government services.

Also it is impossible to use google without enabling the SMS 2FA option. No matter what, with only 2FA authenticator app or email, they will lock down the account by saying "unable to verify".

[–] cmnybo@discuss.tchncs.de 8 points 2 weeks ago (1 children)

I never set a phone number on two of my google accounts and they still work fine. Those accounts are old. Google didn't ask for a phone number to sign up back then.

I recall seeing something about them planning to get rid of SMS 2FA last year. It looks like it's still an option though.

[–] Zarobi@aussie.zone 10 points 2 weeks ago (1 children)

Watch out, if those accounts are ever "locked", you will get permanently locked out of the accounts. Happened to me because a data breach revealed my email address and some idiot tried brute forcing my password. Didn't work but it broke the account. Secondary recovery email address and correct password wasn't good enough. Support basically told me to give up and make a new account (???).

load more comments (1 replies)
load more comments (7 replies)
[–] urushitan@kakera.kintsugi.moe 13 points 2 weeks ago* (last edited 2 weeks ago) (4 children)

Signal doesn’t offer anything except sms 2fa and requires a phone number. It’s a terrible choice considering LEO can do what they did here and just get legal access to MITM your sms messages, spoof the 2fa, and take over your account, impersonating you. The other ones aren’t encrypted. So none of these they broke into are great choices for truly secure messaging.

[–] Zak@lemmy.world 8 points 2 weeks ago

They can only impersonate you that way if your contacts dismiss the warning about your safety number changing. If you're being directly targeted by the government of a wealthy country, using a specific app isn't enough to prevent surveillance; you'll need some actual opsec.

load more comments (3 replies)
[–] anon_8675309@lemmy.world 77 points 2 weeks ago

The headline makes people think signal is somehow broken.

It’s not. Just be careful and monitor your account. And don’t let anyone gain physical control of your device.

[–] Zak@lemmy.world 72 points 2 weeks ago (1 children)

What's described in the article is the same method Russia was using to compromise Ukrainian Signal accounts. It's just phishing.

[–] SergeantSushi@lemmy.world 11 points 2 weeks ago (1 children)

I think you're the only person here so far who read the linked article.

I also found the netzpolitik article that was referenced but not linked to in the original article.

This describes police adding a linked device to a person's WhatsApp account while gathering evidence (translated with Google Translate).

On January 12, 2020, Mr. and Mrs. P. were questioned. During the questioning, they voluntarily handed over the mobile phones they were carrying to the interviewing officers for a brief period so that messages from their daughter contained on the devices could be viewed and, among other things, photographed.

While the photographs were being taken, the computer-based application WhatsApp Web was covertly activated via a website made available online by the Federal Criminal Police Office (BKA), allowing the messages to be read on a BKA computer (sic!). This did not involve any intrusion via a Trojan horse or similar software.

The only link to Signal here is the nation state campaign which used social engineering via a phishing message from 'Signal Support'.

This nation state campaign was originally reported by a researcher at Citizen Lab.

[–] Zak@lemmy.world 7 points 2 weeks ago

I did notice some comments that may be from people who did not read and understand the article. These attacks are not sophisticated or hard to defend against, which is probably why the German police want to limit public awareness.

I find their view shortsighted/narrow; the attacks they're using (including SIM swapping) are also widely used by criminals for fraud and identity theft. Police agencies should not discourage the public from being more cybersecurity-aware.

[–] Agent641@lemmy.world 50 points 2 weeks ago (1 children)

The burglar broke in by knocking on the door and waiting for someone to come to the door and open it and then asking if they could come in and were let in and asked if they could just take stuff and the person said sure go nuts.

[–] deltapi@lemmy.world 15 points 2 weeks ago

Almost. More like they asked to use the bathroom then unlatched the bathroom window, left, and returned later through that window when the homeowner wasn't paying attention

[–] deltapi@lemmy.world 40 points 2 weeks ago (2 children)

To me, this proves that the police can still get the information they need without us handing over our encryption keys and requiring 'service providers' to MITM for them.

[–] cley_faye@lemmy.world 17 points 2 weeks ago (3 children)

Except they had to get the keys, at least for Signal, as described in the article. Only you can allow a new device. If you get a notification for a new device and you go "sure, let me flash that code for you", you're giving the key. And a moron.

Can't say about the other services.

load more comments (3 replies)
[–] WhyJiffie@sh.itjust.works 7 points 2 weeks ago (1 children)

for signal, that is still required. if you look, they used linked devices to get the messages

[–] deltapi@lemmy.world 7 points 2 weeks ago (1 children)

That's not MITM done by the signal foundation.

[–] WhyJiffie@sh.itjust.works 5 points 2 weeks ago

I meant us handing over our encryption keys. ofc MITM does not work here

[–] evilcultist@sh.itjust.works 32 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

Seems like signal could send a notification 24 hours after any new device is added to remind the user that it was done. Make it so it has to be dismissed on each device so dismissing it on one doesn’t make it vanish on the rest.

[–] thr0w4w4y2@sh.itjust.works 9 points 2 weeks ago

doesn’t help if you’re in custody and your device is in a lab

[–] bedwyr@piefed.ca 23 points 2 weeks ago (1 children)

A problem many aren't aware of, in an area that shares telecommunications info, two people within that area can be identified by the state sending encrypted messages by seeing when one person sends and another instantly receives a message. It could be easy enough to obscure that I would think by working differing lag times in.

I think it was in the intercept a few years back. I think this is it.

https://theintercept.com/2024/05/22/whatsapp-security-vulnerability-meta-israel-palestine/

[–] nodiratime@lemmy.world 5 points 2 weeks ago

Remailer (Mixmaster) were meant to address that problem back when E-Mails were more popular.

[–] time2lose@lemmy.world 20 points 2 weeks ago (10 children)

Telegram and whatsapp never had encryption. Also - they just give your messages on law enforcement request, always have.

Signal - how does it work with signal again?

[–] FriendOfDeSoto@startrek.website 21 points 2 weeks ago (1 children)

They are a bit vague on this but I suspect all of these attack vectors start with LEOs having physical access to the unlocked phone. They then set up a trusted desktop without the phone owners knowing.

Which is clever, to be fair. Whether or not that's legal is already a court case. The law is so frightfully grey.

[–] peopleproblems@lemmy.world 15 points 2 weeks ago (5 children)

Its also a failure of the user's access control and operating security.

Once a third party has access to the secure environment, that environment is and will always be compromised.

load more comments (5 replies)
load more comments (9 replies)
[–] odama626@lemmy.world 20 points 2 weeks ago

Signal in this was clickbait they literally just say oh well if someone can link in their device they can see 45 days of message history

[–] SleeplessCityLights@programming.dev 14 points 2 weeks ago (1 children)

Is everyone here really whining about social engineering? It's basic comp sec, weakest link are the people.

load more comments (1 replies)
[–] PattyMcB@lemmy.world 8 points 2 weeks ago

The article also mentions using linked device access. Clever. Fuck the police, though.

[–] UltraGiGaGigantic@lemmy.ml 5 points 2 weeks ago

Heck the state

load more comments
view more: next ›