logoalt Hacker News

aembleton • 02/20/2025 • 1 reply • view on HN

> In each of the fake group invites, JavaScript code that typically redirects the user to join a Signal group has been replaced by a malicious block containing the Uniform Resource Identifier (URI) used by Signal to link a new device to Signal (i.e., "sgnl://linkdevice?uuid="), tricking victims into linking their Signal accounts to a device controlled by UNC5792.

Missing from their recommendations: Install No Script: https://noscript.net/


Replies

cassepipe • 02/20/2025

No Script is a browser extension. Signal is an Android/Ios/Electron app so no

➕ show 1 reply