8 min read

Signal's Biggest Update In Years, Plus Rival App Stores Arrive In The Play Store

Signal's Biggest Update In Years, Plus Rival App Stores Arrive In The Play Store
đź“°
Listen to the weekly podcast on Apple Podcasts, Spotify, other podcast apps, or RSS. You can also watch Surveillance Report on YouTube or Techlore.TV

On My Radar 🎯

Signal Just Had Its Biggest Week in Years

Signal is one of my favorite messengers that strikes a solid balance between privacy, security, and usability—making it a strong alternative to mainstream messengers. But it's had a short list of persistent, legitimate annoyances, and this week that list is getting smaller:

  1. First, Signal has always required a central 'hub' device, with other devices being 'linked' devices. Unfortunately, a second mobile phone could never be a linked device, only desktops and the iPad. This practically resulted in the inability to use the same Signal account on more than one phone. But Signal has now changed this behavior! Newer versions now let you link another phone and Android tablets for the first time, so if you dual-wield a work phone and a personal phone, this is a huge workflow unlock 🙌
  2. The second is automatic key verification. Signal's existing safety number system lets you verify the encryption keys between you and a contact still belong to that contact, ensuring that nobody can easily impersonate them. This new feature attempts to automate the process, using what amounts to a network of trust, audited by Cloudflare and Trail of Bits. You'll find it under Settings → Privacy → Automatic Key Verification, or per-contact under "View Safety Number." It only works when you're connected via phone number, so username-only or group-only contacts won't show it. It doesn't replace safety numbers, and it doesn't take anything away if you'd rather not use it. But this is another nice-to-have feature.
  3. The third is speculative. There's some GitHub activity suggesting Signal will let you register without a phone number in exchange for a one-time payment. I know how that reads: the thing people have asked for over years, finally arriving with a price tag, grumble! But I really don't think that's what this is...the phone number requirement exists as a spam barrier for a free app anyone can download, and a small one-time payment does the same job. Proton does effectively the same thing, requiring stricter verification on free accounts, or letting users pay out of verification. My one hope is that they accept a private payment method, since if the reason you're avoiding a phone number is anonymity, paying with a card doesn't get you there either.

What you can do: If you've been stuck on one device, update Signal and link your second phone or tablet. Then open Settings → Privacy and turn on Automatic Key Verification. And if you've never verified a safety number with the people you talk to most, try it out! It's five minutes and it meaningfully improves the security of your conversations. I have a whole guide on verifying safety numbers and why to do it here.


Bits & Bytes 🤖

~ Story 1: Following Its Epic Loss, Google Starts Hosting Rival App Stores
Google is now hosting third-party app stores inside the Play Store itself, starting with Aptoide. While this sounds great, there are some real caveats:

  • It costs the app store $15,000 up front.
  • Google may charge more if costs climb.
  • Google's own landing page says it doesn't review every app in those stores.
  • Finding them means going into apps → categories → third-party app stores; you can't just search.

My take: Imagine opening the App Store to download Cydia, that's effectively what this is! I'd love to see F-Droid listed here, but will F-Droid spend $15,000 and accept open-ended future charges to get there? I suspect that's the point.

~ Story 2: A Fake Wi-Fi Network on a DEF CON Flight
On a Delta flight home from DEF CON, passengers spoofed the onboard Wi-Fi. Crew spotted the fake network, flagged it, and shut the real one down. This is an evil twin attack, a convincing clone of a legitimate network that serves a phishing page and harvests whatever people type into it. Oddly, no arrests, no agents meeting the flight at the gate.

My take: I just felt this was an entertaining story and a good reminder to treat Wi-Fi networks with suspicion!

~ Story 3: Three in Five Americans Favor Stronger Oversight of Social Media
A Reuters/Ipsos poll found 66% back age verification laws for users under 16, 61% want firmer oversight of social media companies (71% of Democrats, 62% of Republicans), and 85% say social media can be addictive for children.

My take: We've watched governments try to lock down the internet using terrorism, national security, porn, and "protect the children" as the reason...but none of them got the public fully behind it. Regulating social media is the first one that has, bipartisan and global. I'm not going to defend these platforms, but I believe regulation should give you more rights, not fewer. Uploading an ID to every website you visit doesn't hold a single company accountable for anything; it holds you accountable for something you never did, and it puts your identity documents in the hands of every site that asks, all while restricting your access to information. I'd rather see the actual problems addressed: what data gets collected, whether you can opt out of infinite scroll by default, whether dark patterns get named and banned, better privacy controls, etc. I feel people are treating 'regulation' as a position, per se, when really regulation can be pro-consumer, or anti-consumer. I generally support pro-consumer regulation, which these social media bans are not.


This Week on Techlore 📺

We had some weird scheduling issues last week, so thank you all for your patience with this newsletter 🙏 I interviewed Alex from Strongbox on Techlore Talks to discuss my favorite KeePass client and get to know them a bit:

KeePass for Apple Devices: Syncing, Security, and Cross-Platform Gaps (Strongbox Interview)
Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.

I announced the unfortunate news to formally cut our Nextcloud Made Easy series. I covered what went wrong, why none of it was Nextcloud's fault, and why knowing when to drop something is a skill I wish I'd learned sooner:

Five Years Later, Why We’re Scrapping Our Nextcloud Series
In November 2021 I promised a Nextcloud series. Today, after five years, two restarts, and a few lessons already in the can, I’m scrapping it. Here’s what went wrong, why none of it is Nextcloud’s fault, and why knowing when to drop something is a skill I wish I’d learned sooner.

And finally, I made some dedicated coverage for the Steam Deck & Framework data breaches, how people can protect themselves from all data breaches, and what made these ones particularly bizarre:

Steam Deck & Framework Data Breaches: What To Do And How To Prevent The Next One
Steam Deck and Framework owners both got caught in data breaches, but the plot twist is neither company was directly hacked. Here’s exactly what to do if you were affected, step by step. From phishing to aliasing to password management.

Action Item âś…

If you're a Signal user, it's time to re-explore your workflows to see if the new features have created something new. Download the update and play with the new features! Otherwise, keep an eye out on the Google Play Store to see if any other third-party app stores hit the market.

Until next week 🫡

This Week's Sources

Highlight: Signal's Largest Updates in Years

Story 1: Following Its Epic Loss, Google Starts Hosting Rival App Stores

Story 2: Delta Investigates a Wi-Fi Deauth Attack on a DEF CON Flight

Story 3: Three in Five Americans Favor Stronger Oversight of Social Media

Story 4: AI Agents Are Now Running Their Own Cyberattacks

The Defense Bulletin

Data Breaches

Threats

FOSS+ Updates

Get Ahead of the Snoops with Surveillance Report

Surveillance Report: what matters in privacy, security, and digital rights. Weekly, free.