this post was submitted on 26 Nov 2023
309 points (95.3% liked)

Privacy

40074 readers
899 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

When I press on some message to forward it, it shows me Random usernames of contacts I don't know. And it even shows some Mobile Numbers I don't know. For example, one number starts with +964 that's Iraq. I'm from Europe tho. These contacts and numbers are from all over the place.

Edit: This only happens on Signal Desktop. If I try to forward a message on Android it only shows my Contacts. And none of these unkown ones.

top 50 comments
sorted by: hot top controversial new old
[–] ripe_banana@lemmy.world 177 points 2 years ago* (last edited 2 years ago) (1 children)

For all of our safety, consider submitting a bugreport.

[–] ErKaf@feddit.de 52 points 2 years ago (1 children)

Thanks for the Link. I submitted a report.

[–] KLISHDFSDF@lemmy.ml 15 points 2 years ago (2 children)

link to report so we can track? thanks!

[–] rockSlayer@lemmy.world 13 points 2 years ago (1 children)

I don't think it's the same user, but here's a report on GitHub with same repro

[–] ErKaf@feddit.de 7 points 2 years ago* (last edited 2 years ago) (1 children)

This is a totally different thing, and I also don't get what the problem of this user is. He wants to share a picture and then just like on android the list of your recent chats opens where of course the pofilepic shows to know where you want to send it to, and he somehow doesn't want the profile pic to be there even tho this is totally normal behavior from android and iOS since... always? Or do I misunderstand his problem because I don't use iOS? Well the most important part, it doesn't sound like my problem at all.

[–] elias_griffin@lemmy.world 11 points 2 years ago (1 children)

What that user is describing is very serious. They are saying iOS can reach into Signal and extract data.

[–] folkrav@lemmy.ca 12 points 2 years ago* (last edited 2 years ago) (1 children)

The user is describing iOS' share sheet, which Signal seems to advertise as a feature. The OS isn't reaching in and grabbing data, Signal is providing data to the OS.

Also note that said user signaled this on the Signal-Android repo, which combined with their inability to find this info, when i don't even own an iOS device, makes me think they aren't the most observant user out there.

load more comments (1 replies)
[–] ErKaf@feddit.de 5 points 2 years ago

I just followed his link and submitted my report. Don't have any link.

[–] hersh@literature.cafe 47 points 2 years ago (3 children)

Has anyone else been able to reproduce this? I just tried and was not able to.

OP, is it possible these people were in group chats you were part of?

[–] aodhsishaj@lemmy.world 16 points 2 years ago (1 children)

I still don't see any bug report anyone can follow up on.... I cannot trust OP's experience until that's linked here.

[–] ErKaf@feddit.de 8 points 2 years ago

The bug report forum from Signal doesn't give you any link.

[–] ErKaf@feddit.de 11 points 2 years ago (2 children)

No, they are not. I'm in two groups. None of them are in the groups. I only use Signal for Real life friends from my Country. I never joined any random group. These people are from all over the world.

load more comments (2 replies)
[–] Pantherina@feddit.de 5 points 2 years ago

Group chats very likely. There are often sync issues from mobile, so these may just be old spam or group chat numbers.

[–] ErKaf@feddit.de 46 points 2 years ago

I just counted. Signal leaked 56 random people to me.

[–] Atemu@lemmy.ml 39 points 2 years ago

Could it be that these are spam numbers that tried to reach you at some point but were blocked before they could?

[–] jherazob@beehaw.org 25 points 2 years ago

They should have added usernames YEARS ago, but instead they go and remove SMS support in the client...

[–] elias_griffin@lemmy.world 23 points 2 years ago* (last edited 2 years ago) (1 children)

Huge if true! You could conceivably submit your phone to a Cybersecurity company and share in any reward.

Help us with:

  • Your OS Version
  • OS settings that are possibly related
  • How you obtained Signal
  • Signal version
  • Video proof
  • Steps to reproduce

Who knows how to compute a hash for an installed mobile phone app? We need to compare it with legit.

[–] ErKaf@feddit.de 12 points 2 years ago (13 children)

https://imgur.com/a/a6CQSpA

The video proof. It also shows the OS and Steps to reproduce. How I obtained Signal: Flathub Signal Version: 6.38.0 OS Settings: Nothing relevant.

load more comments (13 replies)
[–] Templa@beehaw.org 22 points 2 years ago (1 children)

Why did someone see that I joined Signal? People who already know your number and already have you in their contacts see that they can contact you on Signal. Nothing is sent to them by your Signal app or the Signal service. They just see a number they know is registered. If someone knows how to send you an insecure SMS, we want them to see that they can send you a Signal message instead.

Why did I see that my contact joined Signal? You are notified when someone that is stored in your contact list is a new Signal user. If you can send an insecure SMS to a contact, we want you to know you can send a Signal message instead.

I hate this.

[–] ReversalHatchery@beehaw.org 12 points 2 years ago (1 children)

So Signal does not protect against those that fill their contacts with every existing number?

But also, this does not explain why is it only happening in the desktop app for OP

[–] qwerty_bastard@feddit.uk 19 points 2 years ago (3 children)

Protect against what? People knowing you have Signal? Excuse me if it's obvious to everyone else, but I'm struggling to understand the issue here.

[–] aintnofilthybot@feddit.de 8 points 2 years ago (5 children)

It confirms that your number is valid and in use.

load more comments (5 replies)
load more comments (2 replies)
[–] Katzastrophe@feddit.de 14 points 2 years ago (1 children)

Wtf is happening in these comments

[–] ErKaf@feddit.de 7 points 2 years ago (2 children)
load more comments (2 replies)
[–] possiblylinux127@lemmy.zip 13 points 2 years ago (1 children)

I've been getting spam on signal. I wonder if this is how they got my number

load more comments (1 replies)
[–] BearOfaTime@lemm.ee 11 points 2 years ago

Noticed in one of your comments this is happening on Signal desktop. Is this a windows machine? Maybe update your post so people are aware it's no on Android

[–] pkill@programming.dev 9 points 2 years ago (2 children)
[–] Ohh@lemmy.ml 22 points 2 years ago (7 children)

My confidence in signal is greater than my confidence in a random fork. Privacy is hard... So I feel it's better to trust something less than ideal, than to trust a random dude promising to solve all problems...

That's just my threat model.

load more comments (7 replies)
[–] ErKaf@feddit.de 10 points 2 years ago

Its not a problem with the Android App.

[–] LWD@lemm.ee 8 points 2 years ago* (last edited 2 years ago) (1 children)
[–] ErKaf@feddit.de 31 points 2 years ago

56 different numbers from all over the world, and all of them are actually real and have signal? I doubt I accidentally do something like this haha :)

[–] Natanael@slrpnk.net 7 points 2 years ago
load more comments
view more: next ›