Meanwhile SimpleX and Delta Chat (over chatmail protocol) have it by default for years without any payment requirements, offer relatively better level of data security and are available on F-Droid main repo.
Registration without a phone number on Signal will use zero-knowledge proofs
171–180 of 209 posts
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#172Earlier quoted context omitted.
Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims abou…
Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
https://docs.getsession.org/contribute-to-the-session-networ...
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#173Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.
Ugh wtf so I need a Google account on Android? That's not going to happen. For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet. Just allow monero payments or something. Alongside Google play for the sheep that want to use that.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#174Earlier quoted context omitted.
Nobody is arguing the e2ee isn't valid, its useful as a metadata collection platform, which is all they care about. Former NSA and CIA Director Michael Hayden famously stated: “We kill people based on metadata." and then he tried to hold back a smile and said "but not with this metadata". It's usefulness as a metadata collection platform becomes much less useful if people don't trust it, so of course it's secure. If…
I'll see your conspiracy theory and raise you one: What if the feds fund tech privacy projects specifically so that people like you won't trust them, and instead embrace privacy nihilism? This is a known strategy of the Kremlin, by the way. They fund opposition groups which protest them, and then leak the fact of that funding so that people who are genuinely upset at the Kremlin get confused about who is captured opp…
Signal is for protecting opposition groups that help in regime change operations.
Why would people embrace privacy nihilism? The Signal shills also agitate against gpg/PGP, so we know it is secure and you should use that instead.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#175Earlier quoted context omitted.
But GrapheneOS relies on a proprietary, black-box security chip from Google... who pinky-promised to open-source it but never did, and that just doesn't sit well with me. I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/…
The government only gets to use this once, and they probably won't use it on you.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#176Re: Registration without a phone number on Signal will use zero-knowledge proofs
#177Re: Registration without a phone number on Signal will use zero-knowledge proofs
#178Earlier quoted context omitted.
Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims abou…
Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
SimpleX, Delta Chat, Matrix
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#179Earlier quoted context omitted.
> if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delive…
> Or throwing it all away anyways when it's using Apple/Play services for notifications delivery? What do you mean by "all"
Apple, at least, maintained a historical database of your phone's notifications, that it did not clean up after they expired. That includes all notifications from Signal telling you that person XXX has sent you a message that starts YYYY
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#180Unrelated. But if you have a spare phone with your account on, e.g. kids or whatever You can install Authenticator and get codes, even if the other phones need biometrics.