Following my video detailing every major security vulnerability found in WhatsApp, it's now Signal's turn. As one would expect, Signal has FAR fewer vulnerabilities than WhatsApp, however there are still a few, and more confusingly, some that are still unaddressed... seemingly considered "features", rather than bugs, despite leaving many users' data vulnerable.
Every WhatsApp Hack Ever: • Every WhatsApp Hack Ever
Why You Should (not?) Use Signal: • Why You Should (not?) Use Signal
Full List of Vulnerabilities:
October 2019, Remote Microphone: https://thehackernews.com/2019/10/sig...
October 2018, Open Decryption Key: https://www.bleepingcomputer.com/news...
October 2018, Plaintext Chat History:
https://www.bleepingcomputer.com/news...
May 2018, Code Injection via Link: https://thehackernews.com/2018/05/sig...
May 2018, Code Injection via Text:
https://thehackernews.com/2018/05/sig...
May 2018, macOS Notification Center Retains Deleted Messages: https://thehackernews.com/2018/05/sig...
April 2018, Bypass Local Passcode on iOS:
https://www.hackread.com/17-year-old-...
January 2018, False Group Management Messages, Join a Group w/o Invitation theoretical
https://eprint.iacr.org/2017/713.pdf
September 2016, Bypass MAC Validation & Add Random Data: https://thehackernews.com/2016/09/sig...
September 2016, Remotely Crash Someone’s Client:
https://pwnaccelerator.github.io/2016...
2015, No Intention of Adding Phone Number Privacy:
https://github.com/signalapp/Signal-A...
2014, Unencrypted Password after Export: https://www.syssec.ruhr-uni-bochum.de...
2014, Unknown Key-Share Attack *theoretical*: https://www.syssec.ruhr-uni-bochum.de...