GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

GNU Too (gnu2@gnusocial.jp)'s status on Monday, 05-Jan-2026 08:25:52 JST

  1. Embed this notice
    scriptjunkie (sj@social.scriptjunkie.us)'s status on Saturday, 03-Jan-2026 13:02:00 JST scriptjunkie scriptjunkie

    FBI is spying on private Signal group chats. The Guardian article from a few weeks ago going around is a terrible article full of hysterics with no concrete details or any sane idea of security, so don't give them the click and I'll try to do so myself.

    Someone in the group chat has a hacked phone or laptop with signal desktop, or once scanned a bad QR code and all their chats will forevermore be owned or maybe they're just giving logs to the FBI or someone in their apartment is. It doesn't really matter.

    What can the FBI do with this? Any message the user sends triggers notifications to all chat members via APN/FCN (see: https://github.com/signalapp/Signal-Server/blob/9c4047a90bee044255fdcf7c5c2e59f89f1ff5e8/service/src/main/java/org/whispersystems/textsecuregcm/push/PushNotificationScheduler.java#L305-L314 for example). The FBI could send a National Security Letter to Signal to demand the Apple/Google ID's of everyone on the convo, then do the same to Apple/Google to get the phone number, name, location, etc. of all the users. The NSL would prohibit notifying the users.

    Will members be put on watchlists, no-fly-listed, hit by terror (antifa) charges? I don't know! They could. This was theorized before (e.g. https://www.scriptjunkie.us/2020/01/dispelling-decentralization-doubts/) but now that it's confirmed, it's worth checking out decentralized, non-phone-based, actually secure alternatives.

    In conversation about 3 months ago from social.scriptjunkie.us permalink Repeated by gnu2

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.scriptjunkie.us
      Dispelling Decentralization Doubts
      from scriptjunkie

    2. https://social.scriptjunkie.us/system/media_attachments/files/115/829/117/063/750/891/original/784295c78e21cd2c.png

    3. https://social.scriptjunkie.us/system/media_attachments/files/115/829/167/200/004/656/original/fd116018ca2f0d6c.png
    4. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Signal-Server/service/src/main/java/org/whispersystems/textsecuregcm/push/PushNotificationScheduler.java at 9c4047a90bee044255fdcf7c5c2e59f89f1ff5e8 · signalapp/Signal-Server
      Server supporting the Signal Private Messenger applications on Android, Desktop, and iOS - signalapp/Signal-Server

Feeds

  • Activity Streams
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.