• Undearius@lemmy.ca
    link
    fedilink
    English
    arrow-up
    155
    ·
    7 days ago

    The comments of that tweet are nothing but “Signal is full of huge design flaws”

    Right, because “add user to group” is a design flaw.

    • ceenote@lemmy.world
      link
      fedilink
      English
      arrow-up
      97
      ·
      7 days ago

      If it’s full of design flaws, they probably shouldn’t be using it for military planning. It’s sad to see the cult members grasping at straws to make this the fault of anyone but those incompetent buffoons.

      • takeda@lemm.ee
        link
        fedilink
        English
        arrow-up
        48
        ·
        7 days ago

        They are trying to divert that the problem was journalist in the chat. In reality journalist present is the only good thing about the whole thing, he acted responsible and made us aware of this. I wouldn’t be surprised if Waltz did it on purpose to expose how they are threatening country’s security.

        The actual problem is that it looks like they use signal on personal insecure phones for all their communication. Signal is meant for consumer use not for classified information, but even if it was secure or doesn’t matter if the phone can be compromised and smartphones are constantly being broken into and the country doesn’t even need to be Russia and China to be capable of doing it. It is so bad that there are products that governments can buy to tap into their citizen’s phones.

        • ceenote@lemmy.world
          link
          fedilink
          English
          arrow-up
          29
          ·
          7 days ago

          You can also explicitly see in the screenshot that Waltz set the group to automatically delete messages after 4 weeks, in blatant violation of government record keeping laws. It’s probably why they’re using Signal in the first place.

          • Wildfire0Straggler3@lemm.ee
            link
            fedilink
            English
            arrow-up
            19
            ·
            7 days ago

            Exactly they violated the Federal Records Act for every message that was automatically deleted. Federal Judge Jeb Boasberg is currently presiding over the lawsuit.

  • magnetosphere@fedia.io
    link
    fedilink
    arrow-up
    64
    arrow-down
    1
    ·
    7 days ago

    I’ve never used Signal, so can’t speak to it’s quality, but the founder’s attitude is pretty funny

    • Mothra@mander.xyz
      link
      fedilink
      English
      arrow-up
      14
      ·
      7 days ago

      Been a solid messaging app for the past couple years I’ve been using it. Unlike Whatsapp, it’s much easier to control its notifications and media shared

      • BakedCatboy@lemmy.ml
        link
        fedilink
        English
        arrow-up
        7
        ·
        edit-2
        7 days ago

        As an old user of textsecure they’ve been solid for a surprising amount of time. Back in the day (ca like 2013?) me and all my friends would use CyanogenMod which at the time had textsecure built in to the ROM. It used an early version of the Signal encryption protocol layered onto plain SMS messages, and the ROM support meant I didn’t even need to install a special app - it would intercept all incoming and outgoing SMSes at the OS level and transparently encrypt and decrypt each one based on who it was coming from or going to. Since messages were direct, the textsecure servers afaik were only used to host public keys.

        Also since it was layered onto SMS, we had a handful of fun occurrences of re-flashing ROMs and forgetting to re-register and then we’d get gibberish texts from our friends whose phones still had our old key.

    • Sixty@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      6 days ago

      Very good these days! They’ve also been tested, all the gov gets are unix account creation date timestamps.

      Was pretty buggy back in 2016 especially with embeds and video codec support between android and apple devices.

      edit: There’s also Molly-FOSS a signal fork on https://molly.im/ with more optional security features but the FOSS branch doesn’t use google proprietary blobs/services. Great for GrapheneOS users especially.

  • Pregnenolone@lemmy.world
    link
    fedilink
    English
    arrow-up
    32
    arrow-down
    2
    ·
    6 days ago

    What does Karina add to this meme?

    Brought to you by the Department of Meme Efficiency (DOME)

  • Snowclone@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    6 days ago

    Man I bet having a buch of handles and email accounts and user names that are just a letter off from heads of departments and cabinet staff would get you a lot of unsolicited classified US documents and plans.

  • John Richard@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    9
    ·
    6 days ago

    Sure, there are plenty of great reasons to use Signal… like if you want your private messages you’ve sent linked back to you via a phone number. No tool intended for maximum security is going to require you to provide a phone number, which is incredibly difficult to acquire in the US without some form of KYC metadata. But sure if you’ve never read Moxie’s blog to see he is obviously invested in Israel’s agenda, then go ahead.

    • uuldika@lemmy.ml
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      6 days ago

      What on Earth does Signal requiring phone numbers have to do with Israel?

        • StupidBrotherInLaw@lemmy.world
          link
          fedilink
          English
          arrow-up
          9
          ·
          edit-2
          6 days ago

          You sound like a lunatic.

          “Ohhhh you’ll see! I can’t tell you what, how, when, or why, but oh will you alllllll see something, someday, somehow!”

          • John Richard@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            3
            ·
            edit-2
            6 days ago

            Right, cause clearly their push to use your biometric phone lock for encryption is so secure. If you at least want some security you won’t use the official app but one like Molly that has actual passphrase encryption, automatic locking, memory clearing & Orbot support.

            • phar@lemmy.ml
              link
              fedilink
              English
              arrow-up
              3
              ·
              6 days ago

              My signal has never asked for anything biometric. Where is this supposed to be happening?

        • uuldika@lemmy.ml
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          2
          ·
          6 days ago

          I’ve literally read the code for Signal’s double-ratchet protocol. It’s extremely high quality cryptography, written in Rust, open source, with several independent audits.

          The server code isn’t open, but we know they (used to?) use Intel SGX enclaves so the contact metadata is sealed from even the Signal Foundation. Admittedly SGX fell prey to a number of speculative execution attacks, but Signal had no way of foreseeing that.

          Also, Moxie hasn’t been involved since 2022.

    • boonhet@lemm.ee
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 days ago

      Huh? It’s not that badly written and it references a recent event. Why do you think it’s AI?

      • Etterra@discuss.online
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 days ago

        No it’s her voice and the way she reads the teleprompter like a literal robot with imitation emotions. She sounds like text-to-speech. Sorry I was unclear about which kind of AI lol