254
you are viewing a single comment's thread
view the rest of the comments
[-] 9tr6gyp3@lemmy.world 12 points 1 month ago

Whats the vulnerability with Signal and phone numbers?

[-] wildbus8979@sh.itjust.works 6 points 1 month ago

It's better now, but for years and years all they used for contact discovery was simple hashing.. problem is the dataset is very small, and it was easy to generate a rainbow table of all the phone number hashes in a matter of hours. Then anyone with access to the hosts (either hackers, or the US state via AWS collaboration) had access to the entire social graph.

[-] 9tr6gyp3@lemmy.world 1 points 1 month ago

Yeah the way I remember it, they put a lot of effort into masking that social graph. That was a while back too, not recent.

[-] wildbus8979@sh.itjust.works 3 points 1 month ago

What I'm saying though is that for the longest time they didn't, and when they changed the technique they hardly acknowledge that it was a problem in the past and that essentially every users social graph had been compromised for years.

[-] KLISHDFSDF@lemmy.ml 16 points 1 month ago

Signal, originally known as TextSecure, worked entirely over text messages when it first came out. It was borne from a different era and and securing communication data was the only immediate goal because at the time everything was basically viewable by anyone with enough admin rights on basically every platform. Signal helped popularize end-to-end encryption (E2EE) and dragged everyone else with them. Very few services at the time even advertised E2EE, private metadata or social graph privacy.

As they've improved the platform they continue to make incremental changes to enhance security. This is not a flaw, this is how progress is made.

[-] bastion@feddit.nl 2 points 1 month ago
[-] 9tr6gyp3@lemmy.world 2 points 1 month ago

Did it get leaked or something?

this post was submitted on 12 Jul 2024
254 points (93.2% liked)

Technology

57226 readers
3876 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS