Future work can also explore whether private user data is leaked to Apple or other third parties via the push notification infrastructure available to developers in the iOS ecosystem. We selected messaging apps that made claims about the privacy of users’ messages (herein, “secure messaging apps”). For example, Telegram’s homepage promotes its app as “private” and states that “Telegram messages are heavily encrypted” (Telegram, 2023). Similarly, Signal’s homepage encourages people to “speak freely” because the Signal app has a “focus on privacy” (Signal, 2023b). WhatsApp also explicitly markets the privacy benefits of their app and states, “your privacy is our priority. With end-to-end encryption, you can be sure that your personal messages stay between you and who you send them to” (The Drum, 2023; The Verge, 2023).
- In the realm of data sovereignty, the use of global services also means that information can end up stored in jurisdictions with very different access laws , or even laws that contradict local regulations.
- Once a brand is seen as careless with data, regaining public trust is an uphill battle.
- The encrypted Signal app is what Defense Secretary Pete Hegseth and other leading national security officials within the administration used to discuss bombing Houthi sites this month.
- We decided not to analyze Google Messages because it is owned by Google and, therefore, there is no notion of third-party leakage in that app; Google runs the infrastructure that provides the push notifications.
Cybersecurity and Infrastructure Security Agency (CISA) and 17 U.S. and international partners published an update in August 2023 to joint guidance for implementing secure-by-design principles (Cybersecurity and Infrastructure Security Agency (2023), CISA). Attacks attributed to groups like Salt Typhoon against major telecommunications providers have highlighted the fragility of the communications infrastructure that underpins governments, businesses, and critical services. Faced with this sense of vulnerability, many organizations have turned, almost instinctively, to consumer messaging apps as a quick fix to “secure” internal communications. The Pentagon advisory, according to reports, warned against using Signal even for unclassified communications, citing the alleged vulnerability exploited by Russian hackers.
Although messages are encrypted during transmission, many applications encourage backups to third-party services, which don’t always maintain the same level of encryption and can become the weak link. A poorly secured cloud backup can completely negate the benefit of end-to-end encryption. Throughout this article, we will calmly but frankly examine why these tools are not harmless, what real risks they pose, and what alternatives and best practices exist to minimize the potential for disaster. A critical security vulnerability in TeleMessageTM SGNL, an enterprise messaging system modeled after Signal, has been actively exploited by cybercriminals seeking to extract sensitive user credentials and personal data. But are these communication tools secure, reliable, compliant and able to safeguard our data?
Silvanovich adds that similar bugs likely remain undiscovered in mainstream communication apps. She looked only at one-to-one calling, for example, and the iOS group FaceTime vulnerability indicates that group calling may have its own slate of flaws. And she emphasizes that while brief audio or video snippets may not be a guaranteed gold mine for attackers in all cases, interaction-less attacks are often worth trying, because they appear innocuous and are difficult to trace.
Prior research has focused on understanding apps’ and websites’ privacy practices by analyzing disclosures made in privacy policies (Harkous et al., 2018; Andow et al., 2020; Wang et al., 2018; Zimmeck et al., 2019; Zimmeck et al., 2017). Linden et al. (Linden et al., 2018) found that disclosures made in privacy policies improved as a result of GDPR enforcement, but that more improvements would have to be made before they can be considered usable and transparent to users. Other recent studies have also examined the accuracy of disclosures made in privacy policies (Andow et al., 2019; Okoyomon et al., 2019; Wang et al., 2018; Samarin et al., 2023). For instance, in the context of a messaging app, a sender device may send a message to the app server (1), which then sends a push notification request to FCM (2). The problem is that these tools, while offering better protection than SMS or unencrypted email , are not designed for the level of security required for high-value strategic communications. They tend to concentrate the infrastructure in a few of the provider’s data centers, creating single points of failure and prime targets for attackers and legal pressure from foreign governments.
This opens the door both to intelligence gathering by third-party states and to complex legal battles over which legislation applies to each piece of information. Initially, Trump tried to downplay the incident, claiming that no classified or national security-relevant information was shared, and his team accused the magazine of having a political agenda. However, under pressure, The Atlantic decided to publish the group’s full contents so that the public could assess the seriousness of the matter, also revealing disparaging remarks about European allies that had already surfaced at other summits.
The accidental inclusion of The Atlantic’s editor-in-chief, Jeffrey Goldberg, in the sensitive Signal conversation sparked a wave of criticism directed at the Trump administration. Democratic lawmakers expressed outrage over the incident, questioning the judgment of senior officials for using a publicly available app to discuss such a delicate military operation. The administration, while acknowledging the error, maintained that no classified information was compromised. President Trump downplayed the event, characterizing it as a minor “glitch” and emphasizing the administration’s overall effectiveness. In marketing, product launch plans, advertising budgets, and influencer contracts often contain sensitive financial and strategic information.
Our work is highly prescient, as it provides new insights into an emergent threat model. The misuse of third-party SDKs within secure messaging apps may pose a heightened risk to users because those SDKs may leak sensitive information to third parties. In particular, app developers use third-party SDKs to implement push notifications, which display important information to the user, including messages from other app users (Figure 1).
However, Signal countered this assertion, explaining that phishing attacks, the actual threat highlighted in the advisory, are not unique to their platform and represent a persistent risk for any popular app or website. They emphasized that these attacks do not exploit flaws in Signal’s underlying encryption technology but instead rely on deceiving users into revealing their credentials or other sensitive information. Users can link their account to desktop applications, which are often less secure than mobile devices. If an attacker compromises a desktop, they gain access not only to stored messages but to ongoing conversations as well.
This is the equivalent of someone slipping into a secure boardroom meeting by stealing a badge, no need to crack the safe when the door is open. As communication tools become integral to business operations, data breaches involving communication tools can have far-reaching consequences for organizations and individuals. For instance, when email accounts are compromised, sensitive information can be leaked, leading to significant financial losses and reputation damage. Similarly, vulnerabilities in messaging apps can allow unauthorized access to confidential conversations, risking the exposure of trade secrets. In the realm of video https://www.resellerratings.com/store/BestDates conferencing, lapses in security can permit uninvited guests to join meetings, potentially disrupting discussions and leaking sensitive content. We used dynamic analysis to record the contents of a push notification after our device received it from the FCM server.
Cisa Warns Of Telemessage Tm Sgnl Vulnerabilities Exploited In Attacks
More recently, security firm Trend Micro uncovered the “Earth Minotaur” threat group using the Moonshine exploit kit to deploy spyware through WeChat, primarily targeting ethnic minority communities. As technology evolves, vigilance and continuous improvement will remain the foundation of secure digital communication. Regulators will continue tightening oversight — pushing for greater transparency, accountability, and user empowerment. Ultimately, breaches often stemmed from weak surrounding systems, not the encryption itself.
About Securityweek
It might mean setting clear policies about which tools can be used for what kinds of content. The “generate link preview” feature is known to have privacy and security risks and has led to critical-severity vulnerability problems on Meta’s WhatsApp platform. “Once we learned that Signal users were being targeted and how they were being targeted, we introduced additional safeguards and in-app warnings to help protect people from falling victim to phishing attacks. This work was completed months ago,” said Signal spokesman Jun Harada. High-risk individuals face a greater likelihood of attacks against their accounts due to a combination of their role and potential access to sensitive information and important people.
Small Businesses And Cyberattacks: Why Phishing Is Still The Threat To Watch
Hundreds of millions of users now use apps like Signal or Telegram, believing these apps to protect their privacy. These applications are entrusted with a vast array of confidential user data, from personal conversations to potentially-sensitive multimedia content, thereby placing a significant emphasis on their ability to make good on their promises of privacy and security. We are unaware of any substantial changes in Android 13 and 14 that would have a material impact on our observed findings.
