How do they prevent sybil attacks and bots then?
Registration without a phone number on Signal will use zero-knowledge proofs
181–190 of 206 posts
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#182Earlier quoted context omitted.
It's standard cryptography, not some new-fangled tech! Wikipedia even has some easy examples: https://en.wikipedia.org/wiki/Zero-knowledge_proof Main caveat is that ZKPs are probabilistic. The protocol (number of rounds etc) determines how sure, e.g. 99.9%. But never 100%. Second caveat: tech- and crypto-bros play fast and loose with the term "ZKP", either because they don't know any better (marketing) or they straig…
https://eprint.iacr.org/2020/141.pdf
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#183Earlier quoted context omitted.
For reference: In Britain, and presumably India: "get you knocked up" = "get your door knocked on". In the US: "get you knocked up" = "get you pregnant".
In Britain it means get you pregnant too. Source : I'm British
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#184Earlier quoted context omitted.
That's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/ In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardiz…
Matrix is a vastly different protocol with vastly different privacy implications. Things like leaking reaction metadata outside of the encrypted envelope (though there finally is an MSC to fix that) should make that obvious. Matrix is cool tech and I use it every day, but comparing Matrix to Signal doesn't make much sense. You can't do what Signal does with Matrix or XMPP, simply because the lack of federation afford…
could you expand on this in detail?
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#185Earlier quoted context omitted.
Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company? As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it. Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#186Earlier quoted context omitted.
Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company? As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it. Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#187Earlier quoted context omitted.
> Or throwing it all away anyways when it's using Apple/Play services for notifications delivery? What do you mean by "all"
https://www.wired.com/story/phone-notifications-reveal-more-... Apple, at least, maintained a historical database of your phone's notifications, that it did not clean up after they expired. That includes all notifications from Signal telling you that person XXX has sent you a message that starts YYYY
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#188Earlier quoted context omitted.
> Just allow monero payments or something. This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.
Wouldn't a payment of about $0.05 do the trick? My understanding of most kinds of spam is that it relies on being able to deploy hundreds of thousands of bot accounts just to get a few hits.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#189What a headline! Meanwhile SimpleX and Delta Chat (over chatmail protocol) have it by default for years without any payment requirements, offer relatively better level of data security and are available on F-Droid main repo.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#190Earlier quoted context omitted.
https://www.wired.com/story/phone-notifications-reveal-more-... Apple, at least, maintained a historical database of your phone's notifications, that it did not clean up after they expired. That includes all notifications from Signal telling you that person XXX has sent you a message that starts YYYY
Forgot about that and that def was bad, though imo not really on Signal and would have just as much affected any XMPP app, no? To me this definitely didn't "[throw] it all away" as in your messages were still only on your phone and never decrypted on any server or w/e.
Anyway, I'm not OP, and they have a mad setup (XMPP via Tor) which is a flaky solution most people wouldn't go for. In general, if you're not going to such extreme measures of hiding among the crowd of Tor users to mask your metadata, you're better off directly connecting and hiding among the crowd of Signal users, rather than hosting your own instance.