To protect people from such phishing, Signal actively warns users against sharing their SMS code and PIN.
We also want to emphasize that Signal Support will *never* initiate contact via in-app messages, SMS, or social media to ask for your verification code or PIN. If anyone asks for any Signal related code, it is a scam. We make this clear when users receive their SMS code during initial signup.
@signalapp those attacks.would've not.been successful if you weren't a #proprietary, #centralized, #SingleVendor / #SingleProvider "solution" that doesn't do #SelfCustoy of all the.keys nor allows for #SelfHosting nor demands #PII like #PhoneNumbers that can be leveraged for that.
- You know what I need to use @monocles / #monoclesChat or @gajim / #XMPP+ #OMEMO?
- Internet connection and an account on any server.
Can't #phish if one doesn't have credentials for #phishing attacks ffs!
- Can't get #phished if noone demands, stores, process or even demands such details in the first place!
Also which #Government is that incompetent to not be able to setup their own comms?
@signalapp THERE IS NO LEGITIMATE REASON FOR #Signal TO DEMAND A #PhoneNumber (= #PII by circumstances if not mandatory doxxing to the governments aka. " #KYC")…
- so yes I do blame Signal because this attack vector is unique to #Signal's shittyness and would not exist with @monocles / #monoclesChat or even
cock.liof all places…