this post was submitted on 12 Mar 2025
304 points (100.0% liked)

Technology

69947 readers
3468 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 21 points 2 months ago* (last edited 2 months ago) (1 children)

The article explains everything. The gist is Russians are targeting Ukrainians with phishing attacks via Signal. There also is the suggestion they're exploiting the linked devices functionality, though I'm not sure how.

[–] [email protected] 2 points 2 months ago (4 children)

Appreciate this, I don't click links lol

Apparently if they can get you to scan some bogus qr code they can get you add their device to your account.

Why signal not cooperating tho? Following us government?

[–] [email protected] 18 points 2 months ago (1 children)

...I don't click links...

I strongly suggest doing so if you want to understand what the article is about

[–] [email protected] 2 points 2 months ago

Comment section is all I need

[–] [email protected] 13 points 2 months ago* (last edited 2 months ago) (1 children)

Because they can't without backdooring the software? Just like they also refuse to co-operate with Swedish government and threatened to leave the market should Sweden try to force them.

You know Russian spies can also use TOR onion routing and so on.

As for phishing there is nothing Signal can do about someone scanning a signal contact sharing QR and adding it to their contracts list beyond informative "hey are you really sure, really really sure you want to add this contact". If user trusts someone they shouldn't, no amount of app policy protections help. Or maybe they manage to shish them to scan and approve "share account to another device". Again nothing Signal can do about that.

[–] [email protected] 2 points 2 months ago

As long as there's a clear confirmation dialog.

[–] [email protected] 8 points 2 months ago* (last edited 2 months ago)

Not sure. Might be political tension. Might be that phishing attacks are typically user error, and Signal feels like at a certain point it's not their responsibility. Hard to say beyond conjecture, and I didn't see a clear reason given in the article.

[–] [email protected] 1 points 2 months ago

That's not how anything works