• sugar_in_your_tea@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        5 hours ago

        The main issue I know about is in how messages are stored (the top CVE in that list). If a phone is compromised, all chat history could be exfiltrated. That’s incredibly unlikely for a regular citizen, but it’s a lot more likely for an important position like the head of the Department of Defense or something.

        NOTE: the vendor disputes the relevance of this finding because the product is not intended to protect against adversaries with this degree of local access.

          • sugar_in_your_tea@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            5 hours ago

            Same. I’m just generally pretty cyber-security curious, and have read a bit on this topic.

            I think Signal and Matrix are absolutely fantastic. I use Signal as an SMS replacement and Matrix for group chats, and I whole-heartedly recommend both.

            BTW, thanks for providing the CVEs, I hope that answers a few peoples’ questions about it. One thing to note is that a high number of CVEs is indicative of a lot of academic interest, which is a good indicator that a project is interesting to the security community. So seeing a lot of CVEs is a good thing, assuming the more critical ones get close quickly (and Signal does a good job keeping up with updates).