Earlier quoted context omitted.
In the context of privacy, you can pretty much assume every black box is compromised. With Telegram this black box is the server (the client is open source); with WhatsApp, it's the client. I suppose there's threat models where WA still wins, but knowing it's owned by Meta, I have a hard time imagining what such a threat model would look like.
Is the Whatsapp client really a black box? APKs are fairly straightforward to decompile back to Smali or a reasonable approximation of Java, or people on rooted devices can hook it with Frida. Of course source code would be better, but it would be pretty brazen to stick a backdoor in an app store release. App versions for popular apps get archived by numerous third-party sites, so even a temporary backdoor in one spe…
Signal says it won’t compromise on encryption
281–290 of 336 posts
Re: Signal says it won’t compromise on encryption
#282Earlier quoted context omitted.
What is it about that guy, that makes people unable to stop talking about him? Was it not enough for him to be the top story in the news every day for 4 years?
He was our president, every former president is newsworthy. Even when they just speak out. January 6th and the theft of top secret documents including nuclear secrets guarantees that he's not leaving the news cycle anytime soon. If he's not charged with a crime that is disqualifying for president, most expect him to run and deny any loss, ensuring our republic is overthrown by a banana republic as well. Many folks ar…
Re: Signal says it won’t compromise on encryption
#283Earlier quoted context omitted.
It's a non profit so it can receive donations, but the developer is a LLC that's run for profit. It's a similar story in almost all software companies that market themselves as non-profit foundations (Mozilla too btw) https://en.m.wikipedia.org/wiki/Signal_Foundation#Signal_Mes...
There are some things non-profits are not allowed to do. But, owning a for-profit isn't one of them, and the for-profit is allowed to do those things. So hence this is a common strategy. Example: Suppose I bulk buy T-shirts printed with my cool logo for $15 each and I sell them to consumers for $50 each. That's a for-profit activity, if Walmart was allowed to have a "non-profit" arm which did this I'm sure they would…
Re: Signal says it won’t compromise on encryption
#284Earlier quoted context omitted.
There's no reason they couldn't have done both. Signal never used SMS as a transport. It only provided a UI to have unencrypted SMS messages alongside Signal chats. As far as Signal messenges themselves go, phone numbers always were an arbitrary ID string. Having a username that isn't a phone number would have only more clearly segregated the SMS feature from Signal chat; and the desire for that segregation is one of…
> Signal never used SMS as a transport. Signal is a merge of the TextSecure and RedPhone applications; back when it was still called TextSecure, it did use SMS as a transport for encrypted messages.
Re: Signal says it won’t compromise on encryption
#285Earlier quoted context omitted.
I see no reason to back-up my history ever. I don't use signal for anything that needs to be archived. Nor do any of my friends. One of the selling points of signal is the feature that it doesn't automatically save photos, this is a good feature. You manually save the photos you want to save. And I thought people regularly backed up everything worth saving from phones to non phone archive anyway.
> I see no reason to back-up my history ever. I don't use signal for anything that needs to be archived. Every single time this comes up, someone chimes in saying they don't need it. That does not invalidate the users who do need it. If I can't keep my messages from device to device, I'm not going to use Signal. With far more manual effort than should be required, I can move my messages from Android device to Android…
Re: Signal says it won’t compromise on encryption
#286Earlier quoted context omitted.
i think SMS support was part of the reason they could not do it before, since usernames would break that feature. removing SMS makes this a non-issue. the phone number is now just an arbitrary ID string which can be replaced by any other
There's no reason they couldn't have done both. Signal never used SMS as a transport. It only provided a UI to have unencrypted SMS messages alongside Signal chats. As far as Signal messenges themselves go, phone numbers always were an arbitrary ID string. Having a username that isn't a phone number would have only more clearly segregated the SMS feature from Signal chat; and the desire for that segregation is one of…
SMS wasn't removed to make way for arbitrary user IDs. that would have been surprising even though i prefer IDs over SMS support. but if SMS was on the way out already it made sense to wait with implementing arbitrary user ID support until then. and now they have one less excuse not to implement it
Re: Signal says it won’t compromise on encryption
#287Earlier quoted context omitted.
Regardless if they were “compeled” - nation security letter related activities have included actions. For example, this included a room and split: - https://wikipedia.org/wiki/33_Thomas_Street My understanding is that vendors that execute national security letters offer system integration technology to be locally installed to ingest the related data. Signal has the data, it just requires them collecting it — hence my…
Those actions were not the result of a national security letter. NSLs can only require the production of existing records. They cannot require the release of the content of communications nor the collection of records which don't already exist. They must also specify the time period the records request covers which can only include up to the date the NSL was received.
Also my understanding that the National Security Letters vendors can simply reissue them automatically to maintain persistent data feeds. Disclosing actions taken via All Writs Act to enable national security letters would likely be a disclosure of them similar to warrant canary.
Re: Signal says it won’t compromise on encryption
#288Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…
Weird take. Can you imagine the number of bots if it didn't require a phone number?
Re: Signal says it won’t compromise on encryption
#289Earlier quoted context omitted.
Matrix is great, but it leaks a ton of data.
So does Signal: who when with whom Matrix does leak more meta data though, e.g. message relationships for instance, but what does that matter?
Re: Signal says it won’t compromise on encryption
#290Is there anything more secure than signal that is widely used? Maybe something that doesn’t leak metadata or require a phone number?
matrix