cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

  • conorabA
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 hour ago

    I might be mistaken but I don’t think Signal uses SMS alone to gain access to a chat so the attack vector for the Signal part based on what the article is saying is that the police are just getting access to a device that’s already authorised (and has the keys) then just adding in another device which they control. This sounds like Signal functioning as expected. The article does refer to police not wanting to give away too many details to maybe there’s something that hasn’t been disclosed, but the cited methods (assuming SMS is off the table for Signal) sound like normal behaviour.