Elektrine lite

← Feed

@vieuxrenard@chaos.social

Post #2076928

2026-05-04 08:31 UTC

Hello @signalapp - given the massive wave of phishing attacks against Signal, how are profiles called “Signal” or profile pictures bearing your logo still possible? Yes, your tech is solid, but you’re making it way too easy for attackers to succeed. #signal #hacking #phishing

Replies (5)

  • @n2o@23.social 2026-05-04 08:41

    @vieuxrenard @signalapp Not sure how they would rule that out without checking content. Which they won't. Ever. I hope.

    Open ##2141358

  • @andrec@mastodon.social 2026-05-04 09:01

    @vieuxrenard @signalapp This is because a) a profiles name and image is stored and send encrypted and cannot be accessed. b) you'll never catch every last fishy name/image and if a user thinks it's impossible for users to name themselves like that, the user will be more likely to trust "Signal Sυpport" and won't notice that this is not an "u" but "υ" (Greek upsilon). TLDR: Prohibition of some problematic profile names won't make it harder for attackers.

    Open ##2141365

  • @flxtr@social.tchncs.de 2026-05-04 11:46

    @vieuxrenard Others pointed out, that public filter code/list would be the only way and that'd be easy to bypass. In my opinion, Signal’s biggest mistake is that, through their fake marketing contact, they’ve already gotten users used to the idea that Signal would message them through an official channel in the app. So now they always have to write: “We would never message our users to ask for login credentials,” instead of simply being able to say that they would never message users at all. This reminds me a bit of banks that kept telling you what they would never do via email, until they actually did it. (Sending links, links pointing to online banking logins, links pointing to other domains (tracking links), etc.) @signalapp

    Open ##2141366

  • @satmd@brettvormkopf.de 2026-05-04 11:57

    @vieuxrenard You are asking good questions and at the same time I'm not sure if they are on point or how much they overlap with the solution. When identical logos/nicks are blocked, then there's unicode lookalikes and cropped/artefacted logos that suffice to trick users. Further, people likely fall for much more obvious fakes. Even when you tell them beforehand. Then there's the psychological aspect that the more security one adds on the surface, the more people will solely rely on others keeping them safe, driving them to be less cauteous. Recently some people claim tech to be too complicated and techies too elitist and exclusive-minded. But when people ignore omnipresent warnings, maybe we should keep them away for their own safety? I don't know. So serious question: where exactly is the bar? What's reasonable counter-measures to such fakes? Do you have ideas in mind? @signalapp

    Open ##2141367

  • @flxtr@social.tchncs.de 2026-05-04 21:49

    @vieuxrenard Hey, WhatsApp Support here. We contact you via Signal, because your WA account seems compromised. PIN plz. 🥹🙏 Thx @signalapp

    Open ##2141368