logoalt Hacker News

aembletonlast Thursday at 9:07 AM1 replyview on HN

> In each of the fake group invites, JavaScript code that typically redirects the user to join a Signal group has been replaced by a malicious block containing the Uniform Resource Identifier (URI) used by Signal to link a new device to Signal (i.e., "sgnl://linkdevice?uuid="), tricking victims into linking their Signal accounts to a device controlled by UNC5792.

Missing from their recommendations: Install No Script: https://noscript.net/


Replies

cassepipelast Thursday at 3:17 PM

No Script is a browser extension. Signal is an Android/Ios/Electron app so no

show 1 reply