et al
et al
Lock

@glueckstein@digitalcourage.social

Vor allem neugierig. Nähen, Handwerk, Sport (machen nicht zugucken), Politik - echt jetzt? Und all den anderen Kram.
Boosten bedeutet nicht unbedingt Zustimmung!

Tischler i.R.
|bildete Menschen aus, die aus Gründen nicht in Betrieben unterkommen.Update: Mit dem Arbeiten ist jetzt Schluss. Dafür hab ich jetzt zwei Nähmaschinen.
Studium
|Diplomfitnessökonom
Radfahrer
|mit Womo für den Urlaub
December 15, 2022

Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.

Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.

But two things stood out:

1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.

2. Certificate revocation endpoints hit g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.

Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.

Soon the full analysis

#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics

Elk Logo

Elk is in Preview!

Thanks for your interest in trying out Elk, our work-in-progress Mastodon web client!

Expect some bugs and missing features here and there. we are working hard on the development and improving it over time.

Elk is Open Source. If you'd like to help with testing, giving feedback, or contributing, reach out to us on GitHub and get involved.

To boost development, you can sponsor the Team through GitHub Sponsors. We hope you enjoy Elk!

Daniel RoePatakAnthony Fu三咲智子 Kevin Deng

The Elk Team