• sqgl@beehaw.org
    link
    fedilink
    arrow-up
    5
    ·
    5 days ago

    Regarding the trick of an adversary gaining access by emailing or SMS’ing a QR code for adding another device…

    Why does the new device not demand the PIN before being added?

    • Jason2357@lemmy.ca
      link
      fedilink
      arrow-up
      5
      ·
      4 days ago

      It does, I tried it. Though, that may have been an addition since the attacks started.

      Though, in that specific case - Russian agents conducting espionage via targeted individuals - it’s very likely they surveil their targets long enough to catch their device PIN before they nab the phone and return it. In the end, there is very little recourse to defend against this type of Evil Maid attack. Signal is really better at protecting against mass surveillance, but for individuals directly targeted by state espionage? You would need serious opsec, using air-gapped computers kept in safes or guarded by humans 24x7 and other crazy stuff. They have rules about what can be physically done with devices containing top secret information for a good reason.

      • sqgl@beehaw.org
        link
        fedilink
        arrow-up
        1
        ·
        4 days ago

        If they could surveil the device to see the PIN being entered then no app would protect them.

        My Signal only asks for a PIN about once per month so that would be a lot of screen surveillance hours to sit through in order to catch that moment.

        More likely is that it was fixed since the breach but I cannot find release notes (hard to search on my phone).