I thought Signal was all about privacy by default? :D
Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.
51–60 of 64 posts
I thought Signal was all about privacy by default? :D
Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.
You already have the peers IP address for p2p call right? How is this better than that?
Here, regardless of if you have that setting enabled or not, and regardless of if you accept the call, contacts and non-contacts can cause your device to make a DNS request, which will leak your DNS server. And if using a DNS server with EDNS Client Subnets, the first 3 octets of your IP address will also be leaked.
I think there's another issue like what you're describing which can kind of obviate this, though: the vast majority of Signal users probably use Signal on their regular mobile phone and its number, not a burner phone/SIM/number. (Few users probably even own a burner phone/SIM/number or understand what that is or why they might want one or how they'd obtain one.) So... everyone can just see your phone number, which probably has an area code corresponding to your city or close to it, and the other digits can possibly pinpoint it even more precisely than that.
Anyone who isn't tunneling all of their DNS traffic with a VPN or otherwise probably also isn't anonymizing their phone number and just has the app installed on their personal, standard cell phone.
If they aren't traveling and haven't moved recently, you can probably see what city they're in just from that. (This exposure does allow coarse location detection even when someone's traveling, though it's a lot more coarse than the area code, unless the Client Subnet value is being sent.)
> if a Signal user wishes to hide their private/public IP addresses even from contacts who call, then it has an option “Always Relay Calls” in its privacy options I thought Signal was all about privacy by default ? :D Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.
EDIT: What I meant by this, as upon re-reading it seems unclear, is that the privacy as I understand it is not supposed to protect one party from the other party with which they are communicating, but rather conceal the conversation from third parties.
> if a Signal user wishes to hide their private/public IP addresses even from contacts who call, then it has an option “Always Relay Calls” in its privacy options I thought Signal was all about privacy by default ? :D Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.
> if a Signal user wishes to hide their private/public IP addresses even from contacts who call, then it has an option “Always Relay Calls” in its privacy options I thought Signal was all about privacy by default ? :D Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.
In my opinion, this is a reasonable default: Relaying all voice calls would use significant resources and might increase latency for users far away from the nearest relay (topologically or geographically).
Also, what's with the snarkiness? Are Signal's security tradeoffs or vulnerabilities somehow making Telegram more or less secure?
The two of them intentionally make different security/usability tradeoffs (the most significant one being Telegram's choice to provide a server-side message history visible to the service operator).
Of course this tradeoff isn't inherently bad, but weird communication and branding on Telegram's side in the past has given this a weird aftertaste that, at least for me, is still sticking around.
The only universal fix I can think of for this class of attacks is to have routers bound latency to a lower limit (eg. 200ms), with fixed latency buckets (eg. 500ms granularity) when it goes beyond that. That is, no traffic would traverse the router in less than 200ms, and every other flow would be fixed at 700ms, 1200ms, 1700ms, etc amounts of latency. Tweaked correctly that would limit location to continent, unless…
To some extent, this already happens. My cable modem adds about 30ms latency no matter the destination. I think this is a combination of buffer bloat (wait for buffer to fill before talking on the network) and waiting for a transmit time slot (shared access to the physical layer). I haven't looked at it in detail, but it is very surprising to me that I get 60ms RTT to Blizzard's servers in Chicago (a speed of light d…
That's not buffer bloat (but might nevertheless be something that happens on DOCSIS modems, although I haven't heard of buffering several packets before contending for an upstream send grant).
Buffer bloat, while also rampant especially in shitty CPE like most DOCSIS modem/router combinations, would only occur when your upstream is saturated.
Supposedly though, on DOCSIS, the upstream access contention algorithm used can sometimes add the latency you describe, adding latency even for single packets.
Earlier quoted context omitted.
How does Edward Snowden acquire a laptop or phone in a way that he can trust it? I don't think it matters what protocols and applications he uses: he does not enjoy privacy.
I order to get a device that is not explicitly compromised with custom targeted malware one could: take a walk, enter a random shop, buy a device. Now you only have the standard malware that everyone gets preinstalled on their devices. How to keep it free of custom targeted malware? That is another question!
> if a Signal user wishes to hide their private/public IP addresses even from contacts who call, then it has an option “Always Relay Calls” in its privacy options I thought Signal was all about privacy by default ? :D Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.
I'm unclear why you claim that "private is not the only kind of call." [EDIT below to clarify.] Also, your IP address is only potentially revealed to your contacts, which is rather different from the Telegram situation in which another party that you don't specifically authorize has access to your data. EDIT: What I meant by this, as upon re-reading it seems unclear, is that the privacy as I understand it is not supp…
Signal's conscious choice is to interpret a user adding another as a contact as an implicit signal to mark them trustworthy enough to forfeit the second kind of privacy in exchange for better voice quality (latency and bandwidth) as well as to lighten the strain on their resources.
Earlier quoted context omitted.
To some extent, this already happens. My cable modem adds about 30ms latency no matter the destination. I think this is a combination of buffer bloat (wait for buffer to fill before talking on the network) and waiting for a transmit time slot (shared access to the physical layer). I haven't looked at it in detail, but it is very surprising to me that I get 60ms RTT to Blizzard's servers in Chicago (a speed of light d…
This is extremely unusual to me. Personally I notice it when my ping to local game servers go from 5 to 25. I’d recommended you look into it, and potentially get another modem. If all my requests started taking another 30ms, I’d consider my network degraded.
This effectively means that even if your share of the total upstream link of a network "collision domain" (shared coaxial medium really) is low (i.e you're using less than 1/n and accordingly should not be experiencing queueing in the modem), you might be seeing latency spikes due to having to compete and wait for transmission timeslots.
My local DOCSIS link is experiencing anything between 0 and 60 milliseconds of latency which I suspect is mostly due to this (since it's inversely correlated to upstream bandwith).
Earlier quoted context omitted.
Can one use Signal via Tor? If so, a URL would be useful. But one can use Session (a fork of Signal) over Lokinet (an onion routing network, which is similar to Tor). Even the updated version of Signal merely relays stuff through a proxy. That is, there's just one hop, and that's trivial to deanonymize. With Lokinet, there are multiple hops, so adversaries must compromise multiple nodes. Also, Session requires no PII…
Lokinet seem to claim ( https://medium.com/@LokiNetwork/lokinet-b8f738fefe7a ) that their network is more resistant to sybil attacks by introducing different incentives (an internal cryptocurrency) and not having a central authority (which TOR does have, and which users have to trust). It's unclear how this helps against a wealthy adversary determined to control the network via its own nodes.
Creating a new service node requires a providing a stake in Loki, which I believe currently costs on the order of $5000. And the only source is Loki held by existing service nodes. So arguably, as the creation rate for new service nodes increases, the price of the requisite Loki stake increases, perhaps supra linearly, or even exponentially.
There's also the issue that service nodes that behave maliciously lose all of their Loki, both the initial stake, and anything that they've earned.
I don't know specifics, however. So I don't know just how high the bar is for malicious service nodes.