logoalt Hacker News

Einenlum01/21/20251 replyview on HN

The attacker uses a patched version of Signal to be able to intercept requests and to block a get request to the attachment they have just created. At least it is my understanding.


Replies

punnerud01/21/2025

That’s just to be able to use their APIs to get the location of the sender.

Example you used the normal Signal app without patch and sending me a message, and I have the patched version.

Just to remove certificate pinning, to be able to see the API traffic because of encryption.