this post was submitted on 26 Mar 2025
386 points (99.5% liked)

News

36233 readers
2963 users here now

Welcome to the News community!

Rules:

1. Be civil


Attack the argument, not the person. No racism/sexism/bigotry. Good faith argumentation only. This includes accusing another user of being a bot or paid actor. Trolling is uncivil and is grounds for removal and/or a community ban. Do not respond to rule-breaking content; report it and move on.


2. All posts should contain a source (url) that is as reliable and unbiased as possible and must only contain one link.


Obvious biased sources will be removed at the mods’ discretion. Supporting links can be added in comments or posted separately but not to the post body. Sources may be checked for reliability using Wikipedia, MBFC, AdFontes, GroundNews, etc.


3. No bots, spam or self-promotion.


Only approved bots, which follow the guidelines for bots set by the instance, are allowed.


4. Post titles should be the same as the article used as source. Clickbait titles may be removed.


Posts which titles don’t match the source may be removed. If the site changed their headline, we may ask you to update the post title. Clickbait titles use hyperbolic language and do not accurately describe the article content. When necessary, post titles may be edited, clearly marked with [brackets], but may never be used to editorialize or comment on the content.


5. Only recent news is allowed.


Posts must be news from the most recent 30 days.


6. All posts must be news articles.


No opinion pieces, Listicles, editorials, videos, blogs, press releases, or celebrity gossip will be allowed. All posts will be judged on a case-by-case basis. Mods may use discretion to pre-approve videos or press releases from highly credible sources that provide unique, newsworthy content not available or possible in another format.


7. No duplicate posts.


If an article has already been posted, it will be removed. Different articles reporting on the same subject are permitted. If the post that matches your post is very old, we refer you to rule 5.


8. Misinformation is prohibited.


Misinformation / propaganda is strictly prohibited. Any comment or post containing or linking to misinformation will be removed. If you feel that your post has been removed in error, credible sources must be provided.


9. No link shorteners or news aggregators.


All posts must link to original article sources. You may include archival links in the post description. News aggregators such as Yahoo, Google, Hacker News, etc. should be avoided in favor of the original source link. Newswire services such as AP, Reuters, or AFP, are frequently republished and may be shared from other credible sources.


10. Don't copy entire article in your post body


For copyright reasons, you are not allowed to copy an entire article into your post body. This is an instance wide rule, that is strictly enforced in this community.

founded 2 years ago
MODERATORS
 

Summary

The Pentagon warned employees against using the encrypted messaging app Signal due to a potential vulnerability exploited by Russian hackers.

The warning came just before a security breach where top Trump administration officials, including the vice president and defense secretary, accidentally added a journalist to a Signal group chat discussing military strikes in Yemen.

The leak sparked outrage and criticism, though Trump downplayed it as a "glitch."

Signal stated it was unaware of any unaddressed vulnerabilities.

you are viewing a single comment's thread
view the rest of the comments
[–] BossDj@lemm.ee 23 points 11 months ago (3 children)

So the vulnerability is that people at the pentagon fall for phishing scams. How is this a signal vulnerability? Seems like the memo is dumbed down to scare pentagon employees away from signal

[–] Cheradenine@sh.itjust.works 14 points 11 months ago

It's not a Signal problem, this is just bad journalism.

Signal also did an update one month ago to help mitigate phishing https://www.wired.com/story/russia-signal-qr-code-phishing-attack/

To be clear though, phishing was Not the problem in this case. Incompetence was the problem.

[–] jmcs@discuss.tchncs.de 5 points 11 months ago

It depends on the context. If the pentagon has a chat app that only has authorized people with verified identities and using official devices in it, then using Signal introduces an attack vector that was not there before.

[–] ObviouslyNotBanana@lemmy.world 2 points 11 months ago

I mean, there are potential ways for Signal to minimize the ability for phishing but that would impede on functions which may be more valuable to users than shrinking the risk of phishing by 10%.