I also suspect the NSA has automated how they find vulnerabilities in source code.
But yeah, so far it seems we let security be an open party, instead of requiring companies to audit a software or face penalties.
That’s a vulnerability all right, but not a security bug in Signal itself. Having every employee manage their own contacts is bad for an organization’s security.
Maybe Signal having UI to distinguish between organization members and outsiders might help make it more suitable for work use? It might require OS support, though.
[1] https://www.theguardian.com/us-news/2025/apr/06/signal-group...
vlovich123•2h ago
[1] https://heimdalsecurity.com/blog/zero-day-exploit-prices-sig...
mindslight•1h ago
What we need to be doing is mocking them instead. Like, really, "I didn’t see this loser in the group" ? Maybe the problem was that he was only expecting to see a list of fellow losers like himself? And maybe this loser who failed upwards needs to listen to his grandkids when they try to tell him that a cell phone works a little differently than TV remote?
Discussions of digital security are better when they are focused around how us citizens can protected ourselves from the government, and that goes so much more with this current government.