Signal: Firm claims to have cracked chat app's encryption
web.archive.org
web.archive.org
This is pure marketing BS. "Decrypting Signal messages and attachments was not an easy task. It required extensive research on many different fronts to create new capabilities from scratch." is marketing speak for "we read some open source code and reimplemented it, and we want it to sound hard and difficult so you will pay us more money."
Cellebrite's stuff is based on 0-day vulnerabilities in phone OSes and hardware in order to extract the data. Once you have the data, the rest of it is parsing and formatting fluff to package up the data in an easily digestible form for law enforcement to use. This is about the latter. There is no vulnerability in Signal being cracked here. It's just doing the same thing Signal does to show you your own messages.
A more worrying attack would be something able to decrypt the traffic on the wire, or a man-in-the-middle.
> The whole article read like amateur hour, which is I assume why they removed it.
- Moxie
... yes?
Surprisingly to no one: if you have fully access to the Phone (including access to the user's keystore) you can use the Signal app (and thus read messages). Thanks for making "our world a safer place".
Also in order to get to the Signal data storage you would first have to defeat the encryption of the device itself (ie. the encryption used by Android / IOS). I would assume that anyone who uses signal and really has something to hide has disabled fingerprint or face id and uses either a passphrase or pincode. It's going to be hard to ever access the signal storage that way.
Nice PR spin and non-story - yes, with access to the Android keystore secret, the database can be decrypted.
Doesn't work if the device has a functional root of trust, or Signal's password feature is used.
> Once the decrypted key is obtained
there are a few steps missing between these 2 paragraphs!
I'm not familiar with Android, but is this an easy step, or a "draw the rest of the fucking owl" step?
I get that this is a silly threat model, but the sooner we rely on non-mass storage for secrets, the better.
Android is much more fragmented ecosystem but most flagship manufacturers offer something similar.