What is the Signal app and is it secure?

Patria
AutorPatria
20:34
Podijeli:
What is the Signal app and is it secure?

(Patria) - Signal, an end-to-end encrypted messaging app long considered one of the most secure in the world, has recently faced attacks from hackers accused of ties to Russia.

Senior German officials on Saturday blamed Moscow-backed groups for phishing attacks targeting high-ranking politicians on the messaging app, raising questions about how secure Signal actually is, AFP reported.

Similar phishing cases have been reported by Dutch and American users, and in February Google warned of cyber attacks by groups linked to Russia.

But what makes Signal different from other messaging apps, and how could one of the world's most secure messaging apps be so widely targeted?

How does it work?

Signal's end-to-end encryption means that every sent message travels in encoded form and can only be decrypted by the end user.

No one in between—neither the company providing the service, nor the internet provider, nor hackers intercepting the message—can read the content because they lack the keys to unlock it.

Signal is not the only messaging service that does this, but unlike WhatsApp and Apple's iMessage, the app is controlled by an independent non-profit organization—not some big tech giant motivated by revenue. This has earned it greater trust from those concerned about privacy.

Signal also goes further than WhatsApp in terms of data privacy, making metadata such as the time of message delivery and its recipient invisible even to the company itself.

WhatsApp shares information with its parent company Meta and third parties, including phone numbers, mobile device information, and IP addresses.

For these reasons, Signal has long been a favorite for messaging among users who are particularly concerned about communication secrecy, such as people working in security professions, journalists, and their sources.

Who owns Signal?

Founded in 2012, Signal is owned by the Signal Foundation, based in Mountain View, California.

Its history is linked to WhatsApp: the site was founded by cryptographer and entrepreneur Moxie Marlinspike, with an initial fifty million dollars from WhatsApp co-founder Brian Acton.

Both Signal and WhatsApp, which Mark Zuckerberg bought in 2014, are based on the same protocol built by Marlinspike.

"We are not tied to any big tech company, nor can any of them ever take us over," reads Signal's website.

Development is mostly funded by grants and donations.

Very open compared to other Silicon Valley leaders, Signal's president is Meredith Whittaker, who worked for Google for years and is a fierce critic of business models built on extracting personal data.

Has Signal been hacked?

Signal's encryption itself has not been broken. Cyber attackers accused of Russian ties did not directly target the encryption system.

Instead, recent attacks relied on phishing—tricking users into handing over access to their accounts.

The attacks work by sending messages that supposedly come from Signal support, such as fake security alerts or invitations to join group chats.

Once users click on these links or enter sensitive account information, attackers can then gain access to messages and chat groups. This means hackers gain access to data shared on Signal and can impersonate the person whose account has been compromised.

Signal did not immediately respond to AFP's requests for comment on the recent attacks.

Komentari (0)

Prijavite se za komentiranje

Prijava

Jos nema komentara. Budite prvi!

Minuta

Sve →

Iz drugih kategorija