This story being true or not, please internalize this; The state will not let us have mobile encrypted comms. period. (BIS was the last victim.)

Phones are all remote ownd.

We need simpler, p2p devices for sensitive conversations.

https://video.twimg.com/ext_tw_video/1696273294754775041/pu/vid/464x848/XLakT78CZ-og5f5m.mp4

Reply to this note

Please Login to reply.

Discussion

Is simpleX enough?

We also need to "Make Privacy Valued Again." 🤝

Wen ColdPhone mk4

😂🙏 yes

The ColdComms Mk5. For when you need your conversations on ice. Now available in shades of translucent icebergs

"Broke into" doesn't sound right. Does iOS backup your signal to icloud? This is my first thought when watching this. They pulled the text from an iOS icloud backup

New Pegasus is zero day, zero click. They just need your phone number for full access.

My understanding with the Egypt iPhone exploit case recently is the mobile carrier likely had a role (Vodafone Egypt). Quite possible US Intel agencies could do the same under FISA and CALEA policies with phones connected to US carrier wireless networks, especially in FISA case if communication is with a foreign surveillance target.

Could it have been a weak Signal PIN?

I bet he was using (now deprecated) SMS feature and they snooped on the other users texts (outside of signal). Would be pretty surprised if they somehow got into a signal-to-signal chat without physical access to one of their phones

Do it

If this is true, it’s scary

Maybe I’m naive, but I thought signal was “best in class.”

We are accessing “freedom tech” with these awful surveillance devices referred to as “cell phones.”

A $5 wrench attack or legal threat to the person on the other end is all it takes to get your signal texts. No fancy hacking required.

Signal isn't broke. Much more likely his phone was hacked or the otjer person on the line was weak. But yes, if the devil is on on your tail then there is practically no way to shake them.

Fortunately they don't give a shit about 99% of us as not everyone is planning on having a coffee with Putin next week so every needs to relax a little.

Until they come for you.. Then you get pissed? Someone ought to go to jail for this.

nostr:note17gpw2pmugy0ymvgngs3ays3yh0xlu0wpnfg4vg8h0wa79a27knus5snynt Imagine if messaging apps supported Bitcoin message signing (very low lift), they could start offering tap sign with TAPSIGNER tomorrow for your more sensitive comms.

This still leaves us with the phone UI being comprised when it shows you the message. But, at lease you could remove the in-transit issues.

This really looks like an attack on his whole phone (Pegasus-like attack) or an Apple backdoor (assuming he uses iphone) they are known to cooperate with three-letters ag**cies) not a signal issue per se.

This.

I think at best, intel agencies get metadata off of the SGX enclosures on the contacts connecting algos. From there, with a #, they can target for full remote exploitation (via 0 clicks). Then simply collect while unencrypted.

I doubt Signal encryption is compromised.

For more secure comms, there's a new option around: https://www.numbersstation.app/

Colin's blog posts are right on spot.

Yes. Good blog.

I mean Signal is the world’s most obvious intelligence honeypot

Yeah, like Tor, Bitcoin and Nostr ;)

Those don’t require trust. You trust that Signal doesn’t have a back door to your chats but you have no way of verifying that.

Signal is periodically reviewed and audited by cryptography experts.

Servers?🤣

and who's paying them? Wouldn't be the first time that what's on paper, doesn't match reality. Not to mention that these reviews are worthless, if you get a fradulent binary - which is real easy, if it's a state actor.

Signal Desktop and laptop/pc compromised via browser zero day.

Is graphene OS safe ? But then how do I know the pixel is safe?

You can verify Graphene yourself

From what is stated it’s possible the other party was compromised. Hence the leaked info, this is not evidence that his signal account was compromised.

🔱

You make a device and I’ll buy it but in the meantime I’m going to brush up on telekinesis 💫

Probably used an Apple Shitcoin with iCloud Backup.

Like a Pager?

What about Graphene OS with secret Nostr PM's or lightning notes?

They also lie. Its easier to say they have tucker's phone hacked than to say they have access to putin's side of the conversation.

The case for graphene OS.

Most likely the person on the other end is a fed or was pressured by feds. With Signal you are trusting the person you are speaking with. On top of that unless you validate their key you are trusting that you are talking with the person you think you are talking with. There are a bunch of other possibilities but these two seem the most credible to me. Also VERY possible Tucker is full of it.

nostr:note17gpw2pmugy0ymvgngs3ays3yh0xlu0wpnfg4vg8h0wa79a27knus5snynt The truth is that IOS devices are vulnerable to DNS surveillance no matter what you do. While Signal has some security guarantees, you still have your phone number tied to it. I hope Keet becomes successful.

Even putting aside the fact that Tucker Carlson is a lying liar who lies constantly, (why anyone would believe anything he says at this point defies logic), that's been debunked numerous times. It's far more likely, the person he talked to was sharing their conversation, or one of them had spyware on their device.

Nope, not touching that shady looking url.

CryptoAG, shady...🤣

🤣

We know Pegasus is out there. It is plausible to assume there are more sophisticated and less known tools out there. And soon IoT will be omnipresent. We also need to rethink privacy and to be more thoughtful when it comes to sensitive conversations

Unless there is proof, we should not assume Signal was broken into.

My assumption, or speculation, is this was more of a social engineering attack, rather than a technical attack on the software. The words he is using, and the way the video is cut do not reveal anything.

Snippets like this are clickbait, and should not be taken seriously. If the long form video is available, it should be posted rather than this clip. People should bring this to the attention of Signal.

#privacy #cybersecurity nostr:npub19g2hnf59ky4q32nc0kmuvd5jlfer526z37yp6dxx09tums8tcdasgyugw8

#signal