But if the attacker has a 0day, which likely all the big players do, they don't need your physical device. Which means signal will do squat to protect your data in that case.
But if the attacker has a 0day, which likely all the big players do, they don't need your physical device. Which means signal will do squat to protect your data in that case.
The question is are you a valuable enough asset that they are gunna burn their $50M 0day just to get your device.
I think Signal is pretty safe from such things. Better than for example Whatsapp. Which seems to be where a majority of these nation-states using their 0days and exploits on.
USA/Russia/Israel for sure have these programs.
> The question is are you a valuable enough asset that they are gunna burn their $50M 0day just to get your device.
You are at least an order of magnitude overshooting the price. Also what is the percentage of Android phones not on the latest security patches and pretty much wide open for known 0days? For sure 90%+.
This tech is available for anyone with enough money, there are plenty of bad guy rich people. An actual investigative journalist can easily make an enemy of a rich person.
> I think Signal is pretty safe from such things.
You base this information on what? If someone is executing code as root on your phone they can absolutely use the method describe in the Cellebrite article.
Be upfront about it. The vast majority of their users, even those who should know better do not realize this.
0days are not that expensive. Within reach of practically any bad guy really.
They are highly proud of Snowden recommending them. But anyone operating on the level he did is a moron to trust Signal. So what the fuck?
There are no apps that resist the phone being rooted. Everyone is vulnerable to 0days by definition.
I don't know why everybody is repeating this as if I somehow don't understand that. My point is Signal is promoted as some sort of panacea by security professionals even though all that security can be bypassed, likely routinely by actual bad guys.
Has he ever said that Signal is the end-all, perfect solution that will prevent all kinds of threats and provide perfect privacy? I am sure there is a lot of sloppy messaging out there, but an endorsement along the lines of "I trust Signal's encryption and that it's not backdoored" is not unreasonable
so you're user YES, which is NO-root, but YES
rm -rf /
Great Sucess.
NO or NON root system, it seems like a marketable gimmick.
Must be up your people's ass.
Just checked, Signal has this; does this actually serve to unencrypt the encryption key or is that still accessible as root?
Above using the platforms secure storage for secrets, there is nothing more an app should do.
It's a pervasive problem of lack of technology and security education in the West.
Not a priority for US etc to show people how to secure themselves.
A communication has many links in a chain.
Some links in most chains will have some weakness or other. So what?
That does not mean that there is no value in the strong links.
You might as well say "But if the attacker has a sniper, which likely all the big players do, they don't need to read you communications to get you, they can just shoot you from across the street. Which means Signal will do squat to protect your life in that case."