Earlier quoted context omitted.
>I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. I understand your concerns, and if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either. But, like the vast majority of us, I am not any of those things. As such, for my (and most…
> if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either. I mean that's really bad, right? Supposedly Signal is the go-to alternative to doing things the hard way (e.g. GPG over email), but apparently it's just not good enough for those with the highest security needs. Given that the alternative is that these people go back to using extremely brittle software, shouldn't…
Is it? If that's what you got from my comment, then I certainly didn't communicate my thoughts clearly.
Signal is great for what it is. And that's as a centralized encrypted messaging platform that's easy to use.
Have some tradeoffs been made (e.g., not strictly p2p, some data is stored, in encrypted form, on their servers, etc.) in making Signal easy to use? Yes.
For the majority of folks, Signal is more than good enough.
AFAICT, Signal has been quite successful in that space.
However, if you're the target of motivated folks and/or state-level actors, any product that relies on third-party interaction of any kind is suspect. For that use case, you need more.
Why is it Signal's responsibility to do that? Should they be held responsible for the (lack of) OpSec[0] of others, whether they're Signal users or not?
I mean, I get it. Why should you (or anyone else) have to do any work (other than download this handy app) to protect yourself, especially if your communications are of interest to motivated hostile adversaries?
The whole "telephone number as identifier" bit, and the network discovery it provides, is the primary reason Signal has had the level of adoption it has. And is something of a red herring in this case, IMHO[1].
And Signal is a centralized service. All messages (stored until they're delivered) and metadata (the stuff that Signal stores for each user) are stored on Signal's servers.
Storing anything on systems accessible to the Internet is risky. Plain text is much worse than encrypted blobs, but there's definitely still a non-zero risk.
That alone makes it unsuitable for those whose life may depend on their ability to maintain secure communications.
There are other tools that folks can use (a bunch of folks have mentioned Matrix, which is great too), but which should be either fully p2p or privately hosted/managed on hardware under one's physical control, again assuming that you might be harassed, imprisoned or killed for your communications.
But for most of us, myself included, Signal is more than good enough.
[0] https://en.wikipedia.org/wiki/Operations_security
[1] Since Signal is a centralized service, they need a mechanism(s) to identify their users. In some respects, using a phone number for that purpose is sub-optimal, but it doesn't really impact the security of messages sent through the service, nor does it attach (other than an optional photo and other information voluntarily provided by the user) any information that could be used to personally identify the user in question. A such, even if the encrypted blobs were to be accessed and decrypted, they wouldn't be all that useful anyway, except as a self-selected list (those who have registered with Signal) of phone numbers. I'm not sure how much of an issue that is for most folks, given that dozens, perhaps hundreds of other organizations (almost all of whom don't give a rat's ass about your security) have your phone number associated with your name, your address, your shopping/browsing/travel habits and a raft of other PII.