Post #1174738
2026-03-09 16:16 UTC
Replies (6)
-
@signalapp@mastodon.world 2026-03-09 16:17
To protect people from such phishing, Signal actively warns users against sharing their SMS code and PIN. We also want to emphasize that Signal Support will *never* initiate contact via in-app messages, SMS, or social media to ask for your verification code or PIN. If anyone asks for any Signal related code, it is a scam. We make this clear when users receive their SMS code during initial signup.
-
@sonjdol@ohai.social 2026-03-09 16:34
@signalapp@mastodon.world this might be worth a push message to all users
-
@lennybacon@infosec.exchange 2026-03-09 19:30
@signalapp@mastodon.world LOL! The day Signal puts a bot in the app would be the day I stop using it…
-
@dresstokilt@mastodon.social 2026-03-09 21:39
@signalapp@mastodon.world probably doesn't help that your app suggests that I verify my PIN - which apparently I will ever need? - every time I'm in it.
-
@yuliyan@nahe.social 2026-04-24 11:16
@signalapp@mastodon.world Wouldn't it be pretty easy to just prohibit accounts being able to use "Signal", "support" and so on as a user name?
-
@lasagne@chaos.social 2026-04-27 07:21
@signalapp@mastodon.world How about a local filter that matches new conversations on the relevant words that then puts a warning over this new contact, that users have to intentionally click on two separate things to make it go away. These things should look out of the ordinary. Like TLS warnings but better explanation. "This new contacts mesages look like a phishing attack. If you are not intentionally adding a contract right now, your should block this." Or something.