Earlier quoted context omitted.
> Remember, when my friend Steve sent me a Signal message last week, Signal does not know who sent that. This seems wrong. How could the Signal server have relayed the message from Steve to you if it does not know the recipient?
It does know the recipient it doesn't know the sender . They call this "Sealed sender" and it is enabled by default for your friends (but you can change who gets this facility). So instead of a message from Steve to tialaramex, it's just a message to tialaramex. Well, duh, of course tialaramex gets messages, why else have message software? My Signal client prepared some "stamps" which are good for one message to me.…
The server fully aware where Steve is logged in from, and sees a message come from there to tialaramex. On top of even that: you then reply back, server sees a message going to Steve, going straight back to the IP address where it already knows he's logged in from.
Another thing people don't consider is that Signal's core server infra is hosted at AWS... so Amazon can also peek into both this network traffic and also dump out that it's your Signal account (ie. phone number) tied to that IP from the EC2 instance's memory.
These folks showed that this sealed sender stuff is broken last year: https://www.ndss-symposium.org/ndss-paper/improving-signals-... (and there's an acknowledgment from the Signal team on page 3 of the PDF).