<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>signal &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/signal/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Tue, 28 Oct 2025 19:17:21 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Signal’s Post-Quantum Cryptographic Implementation</title>
		<link>https://noise.getoto.net/2025/10/29/signals-post-quantum-cryptographic-implementation/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 29 Oct 2025 11:09:57 +0000</pubDate>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[quantum computing]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=71097</guid>

					<description><![CDATA[<p>Signal has <a href="https://signal.org/blog/spqr/">just rolled out</a> its quantum-safe cryptographic implementation.</p>
<p><i>Ars Technica</i> has a <a href="https://arstechnica.com/security/2025/10/why-signals-post-quantum-makeover-is-an-amazing-engineering-achievement/">really good article</a> with details:</p>
<blockquote><p>Ultimately, the architects settled on a creative solution. Rather than bolt KEM onto the existing double ratchet, they allowed it to remain more or less the same as it had been. Then they used the new quantum-safe ratchet to implement a parallel secure messaging system.</p>
<p>Now, when the protocol encrypts a message, it sources encryption keys from both the classic Double Ratchet and the new ratchet. It then mixes the two keys together (using a cryptographic key derivation function) to get a new encryption key that has all of the security of the classical Double Ratchet but now has quantum security, too...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Using Signal Groups for Activism</title>
		<link>https://noise.getoto.net/2025/07/10/using-signal-groups-for-activism/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 10 Jul 2025 11:08:53 +0000</pubDate>
				<category><![CDATA[activism]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70450</guid>

					<description><![CDATA[Good tutorial by Micah Lee. It includes some nonobvious use cases.
]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Signal Blocks Windows Recall</title>
		<link>https://noise.getoto.net/2025/05/23/signal-blocks-windows-recall/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 23 May 2025 11:02:59 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70288</guid>

					<description><![CDATA[This article gives a good rundown of the security risks of Windows Recall, and the repurposed copyright protection took that Signal used to block the AI feature from scraping Signal data.
]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>The Signal Chat Leak and the NSA</title>
		<link>https://noise.getoto.net/2025/03/31/the-signal-chat-leak-and-the-nsa/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 31 Mar 2025 11:04:55 +0000</pubDate>
				<category><![CDATA[defense]]></category>
		<category><![CDATA[Department of Defense]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70069</guid>

					<description><![CDATA[<p>US National Security Advisor Mike Waltz, who started the now-infamous group chat coordinating a US attack against the Yemen-based Houthis on March 15, is seemingly now suggesting that the secure messaging service Signal has security vulnerabilities.</p>
<p>"I didn’t see this loser in the group," Waltz <a href="https://abcnews.go.com/Politics/trump-admins-shifting-explanations-journalist-added-signal-chat/story?id=120179649">told</a> Fox News about <em>Atlantic</em> editor in chief Jeffrey Goldberg, whom Waltz <a href="https://www.theatlantic.com/politics/archive/2025/03/trump-administration-accidentally-texted-me-its-war-plans/682151/">invited</a> to the chat. "Whether he did it deliberately or it happened in some other technical mean, is something we’re trying to figure out."</p>
<p>Waltz’s implication that Goldberg may have hacked his way in was followed by a ...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Signal Will Leave the UK Rather Than Add a Backdoor</title>
		<link>https://noise.getoto.net/2023/09/26/signal-will-leave-the-uk-rather-than-add-a-backdoor/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 26 Sep 2023 11:15:02 +0000</pubDate>
				<category><![CDATA[backdoors]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67824</guid>

					<description><![CDATA[<p>Totally expected, but still <a href="https://techcrunch.com/2023/09/21/meredith-whittaker-reaffirms-that-signal-would-leave-u-k-if-forced-by-privacy-bill/">good to hear</a>:</p>
<blockquote><p>Onstage at TechCrunch Disrupt 2023, Meredith Whittaker, the president of the Signal Foundation, which maintains the nonprofit Signal messaging app, reaffirmed that Signal would leave the U.K. if the country’s recently passed Online Safety Bill forced Signal to build “backdoors” into its end-to-end encryption.</p>
<p>“We would leave the U.K. or any jurisdiction if it came down to the choice between backdooring our encryption and betraying the people who count on us for privacy, or leaving,” Whittaker said. “And that’s never not true.”...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Fake Signal and Telegram Apps in the Google Play Store</title>
		<link>https://noise.getoto.net/2023/09/14/fake-signal-and-telegram-apps-in-the-google-play-store/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 14 Sep 2023 11:05:51 +0000</pubDate>
				<category><![CDATA[cyberespionage]]></category>
		<category><![CDATA[espionage]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[Telegram]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67779</guid>

					<description><![CDATA[<p>Google <a href="https://arstechnica.com/security/2023/08/google-removes-fake-signal-and-telegram-apps-hosted-on-play/">removed</a> fake Signal and Telegram apps from its Play store.</p>
<blockquote><p>An app with the name Signal Plus Messenger was available on Play for nine months and had been downloaded from Play roughly 100 times before Google took it down last April after being tipped off by security firm ESET. It was also available in the Samsung app store and on signalplus[.]org, a dedicated website mimicking the official Signal.org. An app calling itself FlyGram, meanwhile, was created by the same threat actor and was available through the same three channels. Google removed it from Play in 2021. Both apps remain available in the Samsung store...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>UK Threatens End-to-End Encryption</title>
		<link>https://noise.getoto.net/2023/04/24/uk-threatens-end-to-end-encryption/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 24 Apr 2023 10:39:33 +0000</pubDate>
				<category><![CDATA[encryption]]></category>
		<category><![CDATA[laws]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[UK]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67261</guid>

					<description><![CDATA[<p>In an <a href="https://blog.whatsapp.com/an-open-letter">open letter</a>, seven secure messaging apps—including Signal and WhatsApp—point out that the UK’s <a href="https://www.gov.uk/guidance/a-guide-to-the-online-safety-bill">Online Safety Bill</a> could destroy end-to-end encryption:</p>
<blockquote><p>As currently drafted, the Bill could break end-to-end encryption,opening the door to routine, general and indiscriminate surveillance of personal messages of friends, family members, employees, executives, journalists, human rights activists and even politicians themselves, which would fundamentally undermine everyone’s ability to communicate securely.</p>
<p>The Bill provides no explicit protection for encryption, and if implemented as written, could empower OFCOM to try to force the proactive scanning of private messages on end-to-end encrypted communication services—nullifying the purpose of end-to-end encryption as a result and compromising the privacy of all users...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Interview with Signal’s New President</title>
		<link>https://noise.getoto.net/2022/10/20/interview-with-signals-new-president/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 20 Oct 2022 11:47:42 +0000</pubDate>
				<category><![CDATA[Facebook]]></category>
		<category><![CDATA[interviews]]></category>
		<category><![CDATA[metadata]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=65989</guid>

					<description><![CDATA[<p>Long and interesting <a href="https://www.theverge.com/23409716/signal-encryption-messaging-sms-meredith-whittaker-imessage-whatsapp-china">interview</a> with Signal’s new president, Meredith Whittaker:</p>
<blockquote><p>WhatsApp uses the Signal encryption protocol to provide encryption for its messages. That was absolutely a visionary choice that Brian and his team led back in the day ­- and big props to them for doing that. But you can’t just look at that and then stop at message protection. WhatsApp does not protect metadata the way that Signal does. Signal knows nothing about who you are. It doesn’t have your profile information and it has introduced group encryption protections. We don’t know who you are talking to or who is in the membership of a group. It has gone above and beyond to minimize the collection of metadata...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Signal Phone Numbers Exposed in Twilio Hack</title>
		<link>https://noise.getoto.net/2022/08/23/signal-phone-numbers-exposed-in-twilio-hack/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 23 Aug 2022 11:30:40 +0000</pubDate>
				<category><![CDATA[cell phones]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=65797</guid>

					<description><![CDATA[<p>Twilio was hacked earlier this month, and the phone numbers of 1,900 Signal users <a href="https://techcrunch.com/2022/08/15/signal-phone-number-exposed-twilio/">were</a> <a href="https://support.signal.org/hc/en-us/articles/4850133017242">exposed</a>:</p>
<blockquote><p>Here’s what our users need to know:</p>
<ul>
<li>All users can rest assured that their message history, contact lists, profile information, whom they’d blocked, and other personal data remain private and secure and were not affected.
</li><li>For about 1,900 users, an attacker could have attempted to re-register their number to another device or learned that their number was registered to Signal. This attack has since been shut down by Twilio. 1,900 users is a very small percentage of Signal’s total users, meaning that most were not affected...</li></ul></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Cellebrite Can Break Signal</title>
		<link>https://noise.getoto.net/2020/12/21/cellebrite-can-break-signal/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 21 Dec 2020 12:06:55 +0000</pubDate>
				<category><![CDATA[cryptanalysis]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[signal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=60609</guid>

					<description><![CDATA[<p>Cellebrite announced that it can break Signal. (Note that the company has <a href="https://www.cellebrite.com/en/blog/cellebrites-new-solution-for-decrypting-the-signal-app/">heavily edited</a> its blog post, but the <a href="https://web.archive.org/web/20201210150311/https://www.cellebrite.com/en/blog/cellebrites-new-solution-for-decrypting-the-signal-app/">original</a> &#8212; with lots of technical details &#8212; was saved by the Wayback Machine.)</p>
<p>News <a href="https://www.haaretz.com/israel-news/tech-news/.premium-israeli-spy-tech-firm-says-it-can-break-into-signal-app-previously-considered-safe-1.9368581">article</a>. Slashdot <a href="https://it.slashdot.org/story/20/12/14/2241230/israeli-spy-tech-firm-says-it-can-break-into-signal-app">post</a>.</p>
<p>The whole story is puzzling. Cellebrite&#8217;s details will make it easier for the Signal developers to patch the vulnerability. So either Cellebrite believes it is so good that it can break whatever Signal does, or the original blog post was a mistake.</p>
<p>EDITED TO ADD (12/22): Signal&#8217;s Moxie Marlinspike takes serious issue with Cellebrite&#8217;s announcement. I have urged him to write it up, and will link to it when he does...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 32/184 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-11 21:54:48 by W3 Total Cache
-->