> Both of those statements are false.
Pop on over to wikipeida, you will how wrong you actually are.
>> "Signal uses standard cellular mobile numbers as identifiers"
>> "The applications include mechanisms by which users can independently verify
>> the identity of their messaging correspondents and the integrity of the data
>> channel."
That is what I described, its trust us first, and maybe verify later if you
think of it.
>> "Open Whisper Systems introduced the second version of their TextSecure Protocol
>> (now Signal Protocol)"
Looks like it is Open Whisper, just V2 and renamed... Well maybe TextSecure.
> hacks PGP came up with to authenticate ciphertext resulted both in stripping
attacks and, indirectly, in the Efail attack from last year.
A quick look at Efail shows clients were at fault and the fix was fix was
patching clients. I can assure you my email client had no such issue. So again,
you are blaming something on PGP that really just involved PGP. If Signals code
has a bug in it too can leak encrypted messages after the client decrypts them.
> key format that resulted in the GnuPG/SKS attacks
Again you are back on keyservers, a method of offline verification to a 3rd
party.
> Signal also doesn't verify identities with phone numbers.
Yes it does, unless you do the second step of verification, which is not done by
default. Have you used signal before? When I installed it on my phone magically
people I knew showed up base off -- what is that? A phone number.
And again Wikipedia - " Signal uses standard cellular mobile numbers as
identifiers, "
> These are just basic, fundamental factual problems with your claims.
You keep conflating things with PGP that are not PGP, thus I have to refute
insane statements that don't have to do with pgp, but things like email clients,
or now how signal actually works. You thus far have just said I am wrong, but
yet not described how any of this works. Yet I am here pointing to and describing
in great detail how you are wrong. Simply saying I am wrong, and not
demonstrating it does not make you right.
> We're not even getting close to serious comparisons between the two systems;
You are right, because you are talking about end to end encryption and I am talking about the importance of verifying who you are talking to. Signal fundamentally solves a different problem that PGP is attempting to solve -- and it does so giving up some very strong benefits that PGP brought to the table. Signal is amazing if you don't want onlookers to see your message, not so good if you want to authenticate the sender (unless you go through the extra steps, in which case it is the same cumbersome process as pgp keys.)
In any case, i don't have any more time to spend on this. If you chose to reply I will read it but I am done because think we are going to come to a agreement.