Signal says there is no evidence rumored zero-day bug is real
bleepingcomputer.com
bleepingcomputer.com
So.... what did this person do to verify the information before sharing it? Since they 'spend their life' fighting disinformation, surely they didn't just retweet it blindly? Right?
Generating a "link preview" involves invoking some sort of browser engine to some degree, so "has a zero-day vulnerability" is virtually guaranteed to be true, whether or not you have a report of a concrete exploit.
If that were true, it wouldn't only be a Signal vulnerability, but also one of Android/iOS.
I am glad to be reassured that fetching data from arbitrary servers inside of a secure chat continues to be worth the benefit of being able to see a little thumbnail of a page.
But that would mean any app with link preview (eg. slack, whatsapp, discord) would also be affected...
Today's headline: We Have No Evidence $Product Is Vuln
Tomorrow's headline: Hacker Releases Data Dump From $Product
Many years ago, a 'researcher' made claims to the media that our product had a zero-day that looked like a deliberate backdoor. They refused to tell us anything about the bug.
In our case, the media reported the researcher's claims uncritically alongside our denials. We decided the best strategy was to say as little as possible, as saying or doing more wouldn't improve the quality of the reporting and would only risk drawing more attention to the false claims.
I think we had a good track record of handling vulnerabilities well, and we definitely had some nasty ones. But this was not one of them.
Well yes, of course they said that, they're not going to disclose their million-dollar zero-days to you are they.