#pastpuzzle 454
π₯π¨π₯π₯ (+1944)
π₯π₯π₯π¨ (+1917)
π©π©π©π© (0)
βͺοΈβͺοΈβͺοΈβͺοΈ
3/4 π₯
https://www.pastpuzzle.de
#pastpuzzle 454
π₯π¨π₯π₯ (+1944)
π₯π₯π₯π¨ (+1917)
π©π©π©π© (0)
βͺοΈβͺοΈβͺοΈβͺοΈ
3/4 π₯
https://www.pastpuzzle.de
#pastpuzzle 453
π©π₯π₯π₯ (-49)
π©π©π₯π© (+80)
π₯π¨π¨π₯ (+316)
π©π©π©π© (0)
4/4 π©
https://www.pastpuzzle.de
#pastpuzzle 260
π©π₯π₯π₯ (+273)
π©π©π₯π₯ (+41)
π¨π¨π¨π₯ (+417)
π©π©π©π© (0)
4/4 π©
https://www.pastpuzzle.de
Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.
Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR β MREnclave verification means even a compromised Signal server can't extract your PIN hash.
But two things stood out:
1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.
2. Certificate revocation endpoints hit http://g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs β without touching message content.
Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.
Soon the full analysis
#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics
#pastpuzzle 258
π©π₯π₯π© (-560)
π©π©π©π© (0)
βͺοΈβͺοΈβͺοΈβͺοΈ
βͺοΈβͺοΈβͺοΈβͺοΈ
2/4 π₯
https://www.pastpuzzle.de
#pastpuzzle 257
π₯π₯π₯π₯ (-432)
π₯π₯π₯π© (-20)
π©π©π©π© (0)
βͺοΈβͺοΈβͺοΈβͺοΈ
3/4 π₯
https://www.pastpuzzle.de
#pastpuzzle 450
π©π₯π₯π₯ (+236)
π©π©π₯π₯ (-18)
π₯π₯π¨π₯ (+354)
π©π©π©π© (0)
4/4 π©
https://www.pastpuzzle.de
#pastpuzzle 255
π©π©π©π₯ (+3)
π©π¨π₯π¨ (-508)
π©π©π©π© (0)
βͺοΈβͺοΈβͺοΈβͺοΈ
3/4 π₯
https://www.pastpuzzle.de
#pastpuzzle 449
π©π₯π¨π₯ (-58)
π©π₯π₯π© (-250)
π₯π₯π¨π₯ (+169)
π©π©π©π© (0)
4/4 π©
https://www.pastpuzzle.de