Skip to main content

Signal bug lets attackers tamper with encrypted messages—patch now

  • September 16, 2016
  • 1 reply
  • 185 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Signal may be the most trusted messaging app, but it's not perfect.

Dan Goodin (US) - 15/9/2016
 
                      
 http://cdn.arstechnica.net/wp-content/uploads/sites/3/2016/09/signal-for-android-800x653.jpg
 
 
Signal, the mobile messaging app recommended by NSA leaker Edward Snowden and a large number of security professionals, just fixed a bug that allowed attackers to add random data to the attachments of encrypted messages sent by Android users.
The update is available on this Github submission, but isn't yet available in the Google Play market for Android apps.
 
The message authentication-bypass vulnerability was one of two weaknesses found by researchers Jean-Philippe Aumasson and Markus Vervier in an informal review of the Java code used by the Android version of Signal. The bug made it possible for attackers who compromised or impersonated a Signal server to modify a valid attachment by adding random data to it. A second bug possibly would have allowed attackers to remotely execute malicious code, but Vervier told Ars that a third bug limited exploits to a simple remote crash.
 
Full Article

1 reply

Baldrick
Gold VIP
  • Gold VIP
  • 16060 replies
  • September 16, 2016
Just goes to show that no supplier can rest on their laurels and that the fight against the miscreants is never ending. :(

Reply