cross-posted from : https://lemmy.zip/post/71321898
Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance


you know what would solve this? simplex.
“Just get everyone in your life to move to ______ and that will solve all your problems”
A suggestion as old as time
it’s one of the most secure message apps available.
messages are signed, encrypted and passed through servers, never left on the server. unless you were the intended recipient you will not decrypt it.
it’s the truecrypt of instant messaging.
Signal does all that already
signal has a closed source server that can’t be audited.
https://github.com/signalapp/Signal-Server
That changed
what does it need a database for?
simplex is literally a message broker. no data remains on the server.
Signal doesn’t keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don’t have your metadata.
then why does it have a database?
Because sometimes, people are not online 24/7 and messages still need to reach them when possible.
Oh really? Simplex would block someone from accessing your phone and thus Simplex’ data?
give me a list of messaging apps that stop attacks that leverage physical access.
use a better os that has encryption and kill codes if that’s your concern.
um…
why are you so against people using a more secure way to communicate?
the only time they mention signal is when they explain they used linked devices to obtain signal messages. not SMS! if you lose your phone or whatever, and log in on a new device, your messages won’t magically reappear, they are lost, and all your contacts get a warning that your safety numbers have changed.
simplex messages stay on your phone. you can’t switch phones and have them follow you because there’s no way to sign in because there’s no account for you to sign in with.
simplex doesn’t require a phone number or email. the trust is made between users, keeping users safer because it requires physical access between users. sure you can share your code over SMS or otherwise, but that’s a user issue that breaks usage policy, not a problem with the software.
I think that’s what I said with signal too. the exception is you can have your messages follow you, if you still have the old phone, because the app supports transferring the data.
if it can transfer the data, there’s more opportunity to successfully steal it.
convenience will always negate security.
Intercepting a verification code with signal does not allow reading messages.