Multiple Russia-aligned threat actors actively targeting Signal Messenger
121–130 of 329 posts
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#122Earlier quoted context omitted.
Even if everyone agreed that the system was secure, and they absolutely don't, see for example https://web.archive.org/web/20210126201848mp_/https://palant... https://www.vice.com/en/article/pkyzek/signal-new-pin-featur... I think we should all agree that outright lying to users on the very first line of their privacy policy page is totally unacceptable.
You cited this so I think this is what you mean: "Signal is designed to never collect or store any sensitive information." I interpret this, I think reasonably, to not include encrypted information. For that matter they collect (but probably don't store) encrypted messages. The question is, does PIN+SGX qualify as sufficiently encrypted? This line is a lie only if it does not. Sorry I skimmed those articles, I don't…
Why? Encrypted information is still sensitive information.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#123Impossible these are our newly minted allies
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#124I'd love to have more of my socializing happening on Signal. Anyone got a good way to convince the non-paranoid to use it?
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#125"Russia-aligned threat actors" has a whole new meaning this last week.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#126Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#127"Russia-aligned threat actors" has a whole new meaning this last week.
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#128Earlier quoted context omitted.
[flagged]
[flagged]
Were you aware that Wire keeps a high-fidelity plaintext database of exactly who talks to who on their platform?
And people were reliably startled. But all that was happening was that ordinary users have no mental model for how a secure messenger is designed, and hadn't thought through how serverside contact lists that magically work no matter what device you enroll in the system were actually designed.
So here I'll just say: the stuff you're saying about Signal is pretty banal and uninteresting. The SGX+Enclave stuff is Signal's answer to something every other mainstream messenger does even worse than that. By all means, flunk them on their purity test!
Re: Multiple Russia-aligned threat actors actively targeting Signal Messenger
#129Earlier quoted context omitted.
It is also possible to communicate without using Meta services.
Good luck with that depending on where you live.