• ramjambamalam
    link
    fedilink
    English
    arrow-up
    19
    ·
    edit-2
    3 days ago

    I can think of easier ways of compromising the data besides brute forcing the keys, off the top of my head, and I’m just some schmuck. Relevant XKCD: https://xkcd.com/538/

    1. Compromise their endpoint with a malicious app on the app store.

    2. Gain physical access to the device and compromise it. Use your imagination – pickpocket, traffic stop or customs inspection by a compromised agent, seduce them with a honeypot, etc.

    3. Socially engineer them to mistakingly add you to their group chats.

    4. SIM swap

    Signal might be fine for journalists, criminals, cheating spouses, and general privacy when used properly with good OpSec but nation state adversaries have significantly greater resources than your average attacker, and thus require more significant security.