Martin R. Albrecht

@malb.bsky.social

Cryptography Professor at King's College London and Principal Research Scientist at SandboxAQ. Erdős–Bacon Number: 6. He/him or they/them. https://malb.io

Our statement on the UK gov't's demand that all content on all devices sold or used in the UK be scanned, on the presumption of nudity, using a dystopian combination of age verification & content scanning. This proposal will not safeguard children. It endangers us all. signal.org/blog/pdfs/20...

signal.org

I'm reading some papers on AI safety (don't ask). Is the entire field really so naive that they think speaking of "human values" makes sense? Have these people not switched on the news ever? I know we computer scientists do not excell at thinking about the actual world we live in, but this is extra.

Just finished presenting this work at Real World Crypto in Taipei :) TL;DR: We found 2 attacks on Signal (Android, Desktop) where a malicious server can inject messages in conversations. Super fun project! Thanks a bunch to Noemi Terzo, @kennyog.bsky.social, and @cryptojedi.bsky.social

ePrint Updates@eprint.ing.bot · 5mo ago

Signal Lost (Integrity): The Signal App is More than the Sum of its Protocols (Kien Tuong Truong, Noemi Terzo, Kenneth G. Paterson) ia.cr/2026/484

Abstract. Signal is a secure messaging app offering end-to-end security for pairwise and group communications. It has tens of millions of users, and has heavily influenced the design of other secure messaging apps (including WhatsApp). Signal has been heavily analysed and, as a result, is rightly regarded as setting the “gold standard” for messaging apps by the scientific community. We present two practical attacks that break the integrity properties of Signal in its advertised threat model. Each attack arises from different features of Signal that are poorly documented and have eluded formal security analyses. The first attack, affecting Android and Desktop, arises from Signal’s introduction of identities based on usernames (instead of phone numbers) in early 2022. We show that the protocol for resolving identities based on usernames and on phone numbers introduced a vulnerability that allows a malicious server to inject arbitrary messages into one-to-one conversations under specific circumstances. The injection causes a user-visible alert about a change of safety numbers, but if the users compare their safety numbers, they will be correct. The second attack is even more severe. It arises from Signal’s Sealed Sender (SSS) feature, designed to allow sender identities to be hidden. We show that a combination of two errors in the SSS implementation in Android allows a malicious server to inject arbitrary messages into both one-to-one and group conversations. The errors relate to missing key checks and the loss of context when cryptographic processing is distributed across multiple software components. The attack is undetectable by users and can be mounted at any time, without any preconditions. As far as we can tell, the vulnerability has been present since the introduction of SSS in 2018. We disclosed both attacks to Signal. The vulnerabilities were promptly acknowledged and patched: the first vulnerability was fixed two days after disclosure, while the second one was patched after eight days. Beyond presenting these devastating attacks on Signal’s end-to-end security guarantees, we discuss more broadly what can be learned about the challenges of deploying new security features in complex software projects.

I just donated to help equip Lebanon's first responders and firefighters with essential life-saving supplies to help them deal with the massive crises unfolding due to Israeli attacks on civilian areas. Please consider donating: fundahope.com/en/campaigns...

Equipping Lebanon's First Responders 2026

March 2026: We are fundraising to equip Lebanon’s national first responders - The Civil Defense (الدفاع المدني) with essential and life-saving supp

fundahope.com