Messenger Privacy T...
 
Notifications
Clear all

Messenger Privacy Test

4 Posts
3 Users
0 Reactions
775 Views
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

The Swiss digital community (Digitale Gesellschaft) just published an overview of messengers tested about privacy and security, only Google Translate version in English available otherwise German

https://translate.google.com/translate?sl=de&tl=en&js=y&prev=_t&hl=en&ie=UTF-8&u=https%3A%2F%2Fwww.digitale-gesellschaft.ch%2Fmessenger%2Fbewertung.html&edit-text=


   
Quote
(@droopy)
Estimable Member
Joined: 11 years ago
Posts: 136
 

Almost all are interceptable nowadays.
I will publish soon many exploits or how a goverment intercept any of them.

Example, signal, worst "secure" software used by snowden

1) Signal capture your real phone number for login.
With that information i could localte you SS7 tracking or even do a remote injection (google pegasus nso) attack vector
2) Signal has a weak implementation of zrtp. They do not add key continuity.
So, each call is a new fresh key exchange without any cache. I could re-route the new call, and from server force a rtp relay to separate the streams and do a man-in-the-middle
3) Signal server is not opensource and no federation, so, we could not understand how server works and which info is sent
4) etc, etc.

Each software has weakness, so really ALL list publish is insecure. Zero security products.

If you want something secure, code your own, use opensource products, and have total control of the infraestructure, and try not using mobile devices as they have zero days exploits.

Droopy
Government Reverse Engineer


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Droopy
Goverment Reverse Engineer

Before you spend money on printing your business cards, you might want to revise your spelling.

jaclaz


   
ReplyQuote
RolfGutmann
(@rolfgutmann)
Noble Member
Joined: 10 years ago
Posts: 1185
Topic starter  

@droopy - I know that this overview just is a trigger to think about messenger security and privacy. You are completely right in your review. See sometimes its helpful to get a general overview of the market and have a low brew comparison.

Your contribution is very much appreciated.


   
ReplyQuote
Share: