Elektrine lite

← Feed

@forster@mathstodon.xyz

Post #1910475

2026-04-28 06:59 UTC

There's quite a discussion around #Signal and the recent phishing attacks in Germany. Let me highlight two of Signal's design choices that challenge a bit the gospel that victims of such attacks are just "too stupid". 1. Signal does send system information from time to time, for example to inform about new features. This looks like a standard message in a separate communication channel (i.e., a text message sent by "Signal"). I find it quite plausible that people will not always be able to distinguish such system messages from messages sent by other users having the Signal logo as their profile picture. 2. Although it is now often claimed that Signal would never ask for my PIN that's not true literally. It asks for my PIN from time to time to make sure I don't forget it. This request for entering the PIN appears as a pop up. But would a user being trained to have the app interact with them via text messages notice the difference between the pop up and a system message? (Apart from that: There obviously were some not-so-smart moves by the involved people and institutions as well. I merely wanted to point out an aspect of the issue that I haven't seen discussed from the tech side so far.)

Replies (0)

No replies.