• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

FBI Warns iPhone And Android Users—Stop Sending Texts

erek

8=D
2FA
Joined
Dec 19, 2005
Messages
17,953
“While messaging Android to Android or iPhone to iPhone is secure, messaging from one to the other is not.


Now even the FBI and CISA, the US cyber defense agency, are warning Americans to use responsibly encrypted messaging and phone calls where they can. The backdrop is the Chinese hacking of US networks that is reportedly “ongoing and likely larger in scale than previously understood.””

Source: https://www.forbes.com/sites/zakdof...-iphone-and-android-users-stop-sending-texts/
 
I suppose adding encryption across platforms is just too technical for the megas?

It has to so with the battle over RCS.

Apple didn't like the fact that adopting RCS meant that they oculd no longer shit on Android users as a marketing tactic, and they were also throwing a hissy fit that RCS gave Google too much control, so they only reluctantly slow walked RCS on the iPhone very recently.

Most iPhones still don't support RCS.

So when you message Android to Android RCS is used automatically, and it is encrypted. (though Google may be collecting data, not sure, haven't had time to read the latest on that)

When you message iPhone to iPhone iMessage is used automatically and it is encrypted.

The problem happens when iMessage sends a message to a device that doesn't support iMesssage, or RCS supporting devices send messages to devices that don't support RCS. Rather than fail, they then fall back to plain old fashioned SMS, which was never particularly secure, but now since the Chinese hack has been blown wide open.
 
Great troll post.
Always!

Actually it would be nice to see this incident force a little intervention to get our communication infrastructure secured and less 'all over the place' with proprietary crap or data harvesting. Apple and Google play their games and we get screwed.
 
Always!

Actually it would be nice to see this incident force a little intervention to get our communication infrastructure secured and less 'all over the place' with proprietary crap or data harvesting. Apple and Google play their games and we get screwed.

To be fair, secure messaging that doesn't share contents with creepy tech big brother exists, and is easy to set up.

It literally takes like 60 seconds to get started with Signal, and it identifies you based on your phone number and uses your contacts, so there is very little barrier to entry.

...and unlike the Googles and the Facebooks of the world it is true end to end encryption without anyone outside of who is added to the conversation having the keys to peek at what you are sending to eachother.

But unfortunately even that minimal level of effort is too much for most people to avoid even potentially catastrophic security issues, so outside of a select few, it never seems to get much traction.
 
Or you could just convince Apple to use RCS instead of proprietary garbage.
And at that very moment, Microsoft introduces Fabric for Azure Remote Teams, an encrypted messaging app with low monthly cost, which works on all platforms using Modern Auth.
 
To be fair, secure messaging that doesn't share contents with creepy tech big brother exists, and is easy to set up.

It literally takes like 60 seconds to get started with Signal, and it identifies you based on your phone number and uses your contacts, so there is very little barrier to entry.

But unfortunately even that is too much for most people, so outside of a select few, it never gets any traction.
Oh for sure, but unless it is installed and running out of the door with a phone, 99% of the population will never use it, thus the communication overall is not secure.
 
Oh for sure, but unless it is installed and running out of the door with a phone, 99% of the population will never use it, thus the communication overall is not secure.

Which is utterly ridiculous considering how we all used to download AOL Instant Messenger and ICQ to chat.

The extent to which people will go to avoid even a few seconds of minimal effort never ceases to baffle me.
 
And at that very moment, Microsoft introduces Fabric for Azure Remote Teams, an encrypted messaging app with low monthly cost, which works on all platforms using Modern Auth.

No one is ever going to pay for a messaging app. You can't stick that genie back in the bottle. People expect basic applications to be free.
 
I suppose adding encryption across platforms is just too technical for the megas?
RCS doesn't support it as a standard.
SMS doesn't even have it as an option.
iMessage has encryption baked in from the ground up.
RCS had it added later as an extension but it works by translating the phone number to an email address and back again and that is handled by a 3'rd party server so the encryption isn't technically end to end, and its why you need to register your phone number and email address as part of the setup.
 
Which is utterly ridiculous considering how we all used to download AOL Instant Messenger and ICQ to chat.

The extent to which people will go to avoid even a few seconds of minimal effort never ceases to baffle me.
I think of my parents. When I was younger, they ran and setup their own IPX network at the house to play duke nukem together. Now I gotta show how to make their phone font size bigger.

I feel like that is how you said, we used to just all set up stuff without thinking.

That said, there needs to be more awareness of Signal and the problem it's solving. I think a lot don't realize they have a problem.
 
That said, there needs to be more awareness of Signal and the problem it's solving. I think a lot don't realize they have a problem.

Maybe that will be the silver lining of this little "mishap"

Probably not. But one can hope?

I keep recommending it to everyone I know, but thus far I have only had a few start using it, and most of them only use it to communicate with me :/
 
It has to so with the battle over RCS.

Apple didn't like the fact that adopting RCS meant that they oculd no longer shit on Android users as a marketing tactic, and they were also throwing a hissy fit that RCS gave Google too much control, so they only reluctantly slow walked RCS on the iPhone very recently.

Most iPhones still don't support RCS.

So when you message Android to Android RCS is used automatically, and it is encrypted. (though Google may be collecting data, not sure, haven't had time to read the latest on that)

When you message iPhone to iPhone iMessage is used automatically and it is encrypted.

The problem happens when iMessage sends a message to a device that doesn't support iMesssage, or RCS supporting devices send messages to devices that don't support RCS. Rather than fail, they then fall back to plain old fashioned SMS, which was never particularly secure, but now since the Chinese hack has been blown wide open.
Google does, since RCS natively doesn't support encryption only direct messaging via a phone number in the E.164 format.
As part of the Google RCS encryption they don't actually do end to end they use a processing server in the middle to do the encryption and translation from E.164 to an email address, then back to E.164
Google has in their ToS that they scan all incoming and outgoing messages for actionable content and keywords, but it's kept anonomous.
RCS was never built to be secure, it was built as a marketing service and one that Google controls through its RBM platform

But yeah for more information look into the Google Jibe platform.
 
It has to so with the battle over RCS.

Apple didn't like the fact that adopting RCS meant that they oculd no longer shit on Android users as a marketing tactic, and they were also throwing a hissy fit that RCS gave Google too much control, so they only reluctantly slow walked RCS on the iPhone very recently.

Most iPhones still don't support RCS.

So when you message Android to Android RCS is used automatically, and it is encrypted. (though Google may be collecting data, not sure, haven't had time to read the latest on that)

When you message iPhone to iPhone iMessage is used automatically and it is encrypted.

The problem happens when iMessage sends a message to a device that doesn't support iMesssage, or RCS supporting devices send messages to devices that don't support RCS. Rather than fail, they then fall back to plain old fashioned SMS, which was never particularly secure, but now since the Chinese hack has been blown wide open.
I do think there's a point to be made about giving Google too much control over RCS.

It's great that RCS between Android devices uses encryption. But it's Google's approach to encryption, so that company gets to dictate the communications standard. Now, Apple might well be spiteful and responding to regulatory pressure, but it also has a point that the encryption should involve actual standardization. Hence why it's supporting the common RCS standard for now and pushing for encryption once there's a truly neutral option.

This is consistent with the way Apple has usually acted: it's fine with standards so long as they're real standards that aren't owned by someone else. It went with FairPlay media DRM because the "standard" at the time, Plays For Sure, would have chained iTunes to Microsoft. But it was also one of the first big digital music retailers to push for DRM-free downloads. And I remember how Adobe and Google demonized Apple for not supporting Flash Mobile on the iPhone and iPad, even though it was a terrible format that would have tied the future of the mobile web to Adobe. Apple instead advocated for a real web standard, HTML5.

(Side note: I still laugh at one of the BlackBerry PlayBook's major selling points was "it runs Flash!" Yeah, turns out that was more of a liability than a feature.)
 
Google does, since RCS natively doesn't support encryption only direct messaging via a phone number in the E.164 format.
As part of the Google RCS encryption they don't actually do end to end they use a processing server in the middle to do the encryption and translation from E.164 to an email address, then back to E.164
Google has in their ToS that they scan all incoming and outgoing messages for actionable content and keywords, but it's kept anonomous.
RCS was never built to be secure, it was built as a marketing service and one that Google controls through its RBM platform

I assumed something like that was happening. No way Google was going to give up a source of data.

I just hadn't had the time to read up on the details.

In the grand scheme of things, as much as I hate data collection and use, if it has to go to anyone, having it go to Google is probably the most innocuous option.

While the risk of misuse or theft is always there, at least their business reasons for collecting it are pretty clear, and they have an incentive to protect it, as using it for marketing purposes is their competitive edge and bread and butter all in one, and they don't want anyone else to get it.

So, from a perspective of "your data not getting out to anyone else" their interests are at least somewhat aligned with ours.

I still prefer none of my data be used by anyone for any reason though, and that's why I'd rather use Signal for everything. Its my data, I should be able to control it.
 
I assumed something like that was happening. No way Google was going to give up a source of data.

I just hadn't had the time to read up on the details.

In the grand scheme of things, as much as I hate data collection and use, if it has to go to anyone, having it go to Google is probably the most innocuous option.

While the risk of misuse or theft is always there, at least their business reasons for collecting it are pretty clear, and they have an incentive to protect it, as using it for marketing purposes is their competitive edge and bread and butter all in one.

So, from a perspective of "your data not getting out to anyone else" their interests are at least somewhat aligned with ours.

I still prefer none of my data be used by anyone for any reason though, and that's why I'd rather use Signal for everything.
I updated my comment to include the name of their RCS authoring servers, Google calls it Jibe.
I had forgotten the name while typing that out.
However, Google's control of the service is why Apple was so against including RCS and why they are only implementing it in the base form and not with any of Google's extensions, so no encryption for the phones that have been updated to include RCS.
Google's control over RCS is also why the EU isn't pressuring Apple to implement the encryption; instead, it is working with Apple to develop a secure replacement to both iMessage and RCS that is open and secure.
 
Google's control over RCS is also why the EU isn't pressuring Apple to implement the encryption; instead, it is working with Apple to develop a secure replacement to both iMessage and RCS that is open and secure.

Hopefully this will be successful, and not watered down with countless political loopholes, and then will be implemented globally without modification.

It's probably a pipe-dream, but we have to do something to keep the hope alive, right?
 
China: <hacks my text messages>

My text messages:

war with china.jpg
 
  • Like
Reactions: -zax-
like this
Two words: Sig Nal
This. Signal is great. Easy to use, good features, secure (as far as we can tell), etc. My family has used it for years since we live in different countries and don't want to pay for texting each other. Good for voice calls too, the call quality is actually better than the cell network, higher bandwidth codec.
 
This. Signal is great. Easy to use, good features, secure (as far as we can tell), etc. My family has used it for years since we live in different countries and don't want to pay for texting each other. Good for voice calls too, the call quality is actually better than the cell network, higher bandwidth codec.
Signal will just be the next target, moving the goal post

all seems to be security by obscurity
 
Signal will just be the next target, moving the goal post

all seems to be security by obscurity
Not really. While yes, it'll be a target, that doesn't mean things are just "security by obscurity". There are better and worse things for security. A well-designed system, with enough layers of security makes it real hard for an attacker to do anything. The problem with SMS is that it is not a well-designed system from a security standpoint. Signal is much better. There's no perfect in security, physical or virtual, but that doesn't mean we shouldn't try for better. You really can keep the bad actors out, including state actors, with good enough security that you keep up on.
 
Me: get signal
ugh I don't want another app. too much work.
Me: ok
OMG DID YOU HEAR ABOUT THIS NEW SOCIAL MEDIA PLATFORM?! It's just like all the other ones, you just have to download another app to use this one! ill tell you more about it over text or insta DMs or tiktok or snap. btw its owned by china.

i just dont fucking get it. definitely didn't help that Signal decided that supporting sms would be too helpful with getting a market share and decided to drop that, so now even Android users need two apps.
 
Just need messaging apps to send a response back to those using SMS "your messaging app is not secure, please use a Secure one and then try to resend the message" should clear itself up shortly... or fuck the fact most phones tell you an update is coming have it update the default messaging app too
 
So this "expert" in the Forbes link recommends using WhatsApp. Now that's hilarious. Screw Meta and Zuckerberg. Any packet associated with that detritus is stripped from our network layers here for good reason. We've checked out Signal and for the most part it seems OK.
 
It has to so with the battle over RCS.

Apple didn't like the fact that adopting RCS meant that they oculd no longer shit on Android users as a marketing tactic, and they were also throwing a hissy fit that RCS gave Google too much control, so they only reluctantly slow walked RCS on the iPhone very recently.

Most iPhones still don't support RCS.

So when you message Android to Android RCS is used automatically, and it is encrypted. (though Google may be collecting data, not sure, haven't had time to read the latest on that)

When you message iPhone to iPhone iMessage is used automatically and it is encrypted.

The problem happens when iMessage sends a message to a device that doesn't support iMesssage, or RCS supporting devices send messages to devices that don't support RCS. Rather than fail, they then fall back to plain old fashioned SMS, which was never particularly secure, but now since the Chinese hack has been blown wide open.
Not sure why you’re blaming Apple when it’s google who has lobbied to keep RCS as a standard completely unsecure. Apple adopted the RCS open standard, and I’m glad they didn’t give in to googles bullshit of “securing” RCS by pushing everything through googles servers. At least iMessage is end to end now as much as people want to shit on Apple. Older devices not supporting RCS is a bit irrelevant since open RCS is just as a security problem as SMS.
 
Back
Top