Is Signal instant messaging “compromised,” as Elon Musk claims?


Corentin Béchade

May 13, 2024 at 9:16 a.m.

7

The Signal application comes under fire © DANIEL CONSTANTE / Shutterstock

The Signal application comes under fire © DANIEL CONSTANTE / Shutterstock

Mini controversy in the encryption world. Elon Musk claimed that the messaging app Signalknown for its privacy protection tools, had “loopholes” that made it dangerous.

Is Signal less secure than the application claims? In any case, this is what Elon Musk seems to think, who published a message on his social networkknown flaws» and never corrected. Enough to cast doubt on the integrity of the well-known application, especially since the billionaire’s message followed the publication of an article half-heartedly accusing the Signal foundation (which publishes the software) of collaborating with the services of the American state.

A few days later, it was Pavel Durov, the CEO of the competing application Telegram, who allowed himself to question the security of Signal. In a message published on his application, the manager explains that the technical choices made by the structure behind Signal do not ensure the real confidentiality of messages exchanged on the platform. But then, what is it really?

Elon Musk contradicted by the community

Signal, in addition to being an instant messaging application, is also an encryption protocol in its own right. Open source, it is used in many other software, including WhatsApp and Skype. Due to its open nature, the algorithm has been audited by a number of encryption specialists who, according to an audit carried out in January 2024, did not find the famous “flaws» mentioned by Elon Musk. Signal’s security has long been praised by big names in digital technology like Edward Snowden… and Elon Musk in 2021. The European Commission has also adopted Signal to protect its communications since 2020.

These facts were also recalled by Meredith Whittaker, CEO of Signal who, in a long message in response to Muskexplains that “uA large community of cybersecurity researchers carefully reviews each update and combs through each of our files» to ensure that no piece of malicious code has slipped in. This context was also recalled in Elon Musk’s message via the famous “Community Notes”.

“Reproducible compilations”, shaky evidence

The doubts expressed by the CEO of Telegram are of another nature and more precise: he tackles the question of “reproducible compilations” of Signal. An important security principle, this concept poses the idea that by compiling the code of an open source application oneself one should obtain exactly the same cryptographic signature as that published by the publisher itself. A way to ensure that no piece of code has been injected when putting the application online.

Signal can now resist quantum attacks, but what is it?
To discover
Signal can now resist quantum attacks, but what is it?

Sep 28, 2023 at 11:00

News

Pavel Durov therefore explains that, unlike Telegram, Signal does not allow you to make reproducible compilations on its iOS app. Proof that Signal has something to hide. The reality, however, is more complicated than that. Due to the way Apple publishes its apps to its AppStore (each going through an encryption process), it is impossible to compare the signatures of a downloaded app and a locally compiled app. On Android, Signal passes the test of reproducible compilations without problem, however.

This is not the first time that Signal has come under fire for alleged design or security flaws in its service. Last December, it was the French government itself which cast doubt on this subject by promoting its Olvid application. But so far, no evidence of any security defect in Signal has ever been provided.

Signal

Download

Signal

  • Feature-rich
  • Open source
  • Secure

Signal is a unique instant messaging application, offering end-to-end encryption to protect messages exchanged on its platform. Preferred by users concerned about preserving their privacy and avoiding the exploitation of their data, it is completely free and without advertising. Available on Android, iOS, as well as PC (Windows, Mac and Linux), Signal can be used in a complementary way on different devices for secure and privacy-respecting communication.

Signal is a unique instant messaging application, offering end-to-end encryption to protect messages exchanged on its platform. Preferred by users concerned about preserving their privacy and avoiding the exploitation of their data, it is completely free and without advertising. Available on Android, iOS, as well as PC (Windows, Mac and Linux), Signal can be used in a complementary way on different devices for secure and privacy-respecting communication.

Corentin Béchade

Corentin Béchade

A journalist for almost 10 years, I have been in the tech and digital sector since my very first jobs. Tinkerer (a lot), librarian (a little), I developed a specialization in...

Read other articles

A journalist for almost 10 years, I have been in the tech and digital sector since my very first jobs. Tinkerer (a lot), librarian (a little), I have developed a specialization in the themes of ecology and digital technology as well as the protection of privacy. On weekends I torture Raspberry Pis with lots of 'sudo' commands to relax.

Read other articles



Source link -99