masto.ai is one of the many independent Mastodon servers you can use to participate in the fediverse.
A general Mastodon server for all languages.

Administered by:

Server stats:

2.2K
active users

Nonilex

And, of course…

-wide email recently went out warning about vulnerability

A Pentagon-wide advisory went out one week ago warning against using the messaging app Signal, EVEN FOR UNCLASSIFIED INFORMATION.

"A vulnerability has been identified in the Signal messenger application," begins the department-wide email, dated March 18, obtained by NPR.


npr.org/2025/03/25/nx-s1-53398

NPR · Days after the Signal leak, the Pentagon warned the app was the target of hackersBy Quil Lawrence

The memo continues, "Russian professional hacking groups are employing the 'linked devices' features to spy on encrypted conversations." It notes Google has identified Russian hacking groups who are "targeting Messenger to spy on persons of interest."

The memo adds, "Please note: 3rd-party messaging apps (eg Signal) are permitted by policy for unclassified accountability/recall exercises but are not approved to process or store non-public unclassified information."

…At least as far back as 2023 a memo, also seen by NPR, prohibited use of mobile apps for even "controlled unclassified information," which is many degrees less important than information about on-going operations.

There's…no precedent for the heads of , , & to be sharing such sensitive military intelligence in a forum that was known to be unsecured.

@Nonilex

Keep getting confused about relative security risks of the hardware, the software and the user.

@Nonilex Yes. And of course, this is all going to stay without consequences. Since it isn't about America's safety at all.

@Nonilex when all the senior appointments work for Russia and #gop doesn’t care.

@Nonilex the #Trump administration is producing enough material for two #impeachments per week. By any other president's standards. And gets away with it ...
So frustrating.

@Nonilex Signal addressed the Russian linked device phishing method already. Additionally, there's now a linked device warning notification at random intervals after linking a new device, and explicit warning before linking to ensure what's being linked is trusted.

@Nonilex
Biden knew that, in his administration, he warned that it was only to be used to arrange meetings or more secure methods for the transmission of information.

@Nonilex Wasn’t the vulnerability inviting the press to the group?

@Nonilex
Oh, there's a vulnerability all right. Idiots are using it when they shouldn't.
Oh, right. That is a different kind of vulnerability.

@Nonilex Ahem, on that front, it is not a vulnerability in the Application itself, but more in its use and phishing attacks.