I trust Signal's end-to-end encryption promise, but I have a problem with the application not offering anonymity or privacy. By demanding users to provide a cell phone number to enable their accounts, they are connecting actual people to the Signal accounts and consequently also allowing them (or someone else) to visualize social networks; in intelligence gathering, data such as who speaks to whom, at what hours, wit…
Just to add... yes, I know it's possible to register a Signal account with a disposable VLN, but how many Signal users can be expected to be "tech literate" to this level? Practically none.
I don't trust Signal (2018)
31–40 of 115 posts
Re: I don't trust Signal (2018)
#32That said, in my time following his blog and Mastodon toots, he's prone to making these hot-takes that take down successful projects that do a lot of public good, but don't tick every check. His repeated criticism of Mozilla is a good example of this.
It often feels like cutting off ones nose to spite the face. Without the Mozillas and OpenWhispers of this world, we've no hope for the DeVaults which create incredible feats of engineering that tick all the ideal boxes but lack some of the creature comforts (e.g. sr.ht, wayland, etc..)
I'm optimistic for the future, and the projects started by Moxie and DeVault are a large part of it.
Re: I don't trust Signal (2018)
#33When it was first published, it included an emphatic recommendation to use Matrix, and, later, Tox --- in fact, the post even included a changelog at the bottom recording the inclusion of Tox. After it was pointed out to the author that Matrix didn't even do E2E by default, the recommendations (and the changelog) were ghost-edited out of the post, but you can still see them on Archive.org.
I don't understand why people take this post seriously.
Re: I don't trust Signal (2018)
#34I reacted to previous posts about this by installing Element (was Riot.im; search for both words) matrix client, setting up a periodic donation to privacytools.io, and making accounts with that as homeserver (chat.privacytools.io) for me and for the rest of the family. (Previously, I had a Librem.one account, but they don't maintain their server, so I dropped it.) It works... Still waiting for anyone else I know to c…
Matrix does pretty well in terms of privacy these days. As for privacytools.io, I can't really agree. They have made a number of suggestions which are less about actual privacy and more about a trend I've come to think of as "privacy roleplaying" - trendy software & services which use privacy and security as a selling point but whose implementation doesn't back it up. An example is Protonmail. When it comes to the pr…
I had thought that parking on a homeserver was not trusting them.
Re: I don't trust Signal (2018)
#35I wouldn't trust such an app for anything actually secret due to the mentioned issues (and phone number req), but I think it's great that we're using high grade encryption to talk about what we had for dinner.
Encrypted and private should be the default no matter what!
Re: I don't trust Signal (2018)
#36What's the alternative to Signal then? For iOS users?
Re: I don't trust Signal (2018)
#37I use Signal because I think it protects my SMS messages from:
a) being harvested and read by other apps on my phone
b) being read by someone who unlocks my phone
c) being passively intercepted and stored by carriers and their snoopy employees
d) opposition researchers or private investigators targeting my friends, acquaintances, and business associates.
For anything targeted and state level, all bets are off anyway, so it's not a solution for people who have that problem. What am I missing?
Re: I don't trust Signal (2018)
#38This post has been on Hacker News several times. For instance: https://news.ycombinator.com/item?id=17723973 . When it was first published, it included an emphatic recommendation to use Matrix, and, later, Tox --- in fact, the post even included a changelog at the bottom recording the inclusion of Tox. After it was pointed out to the author that Matrix didn't even do E2E by default, the recommendations (and the chang…
Re: I don't trust Signal (2018)
#39I love Mr. DeVault's work, and think he consistently shows integrity in his work, to say nothing of his incredible productivity and engineering. That said, in my time following his blog and Mastodon toots, he's prone to making these hot-takes that take down successful projects that do a lot of public good, but don't tick every check. His repeated criticism of Mozilla is a good example of this. It often feels like cut…
Re: I don't trust Signal (2018)
#40As to the interjection that Signal is lacking a FBI canary - Moxie was clear on the subject: https://web.archive.org/web/20141027143819/https://github.co...