Registration without a phone number on Signal will use zero-knowledge proofs
201–206 of 206 posts
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#202Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#203Is Signal still a trusted company in the industry? They are based in the USA.
see: https://web.archive.org/web/20250117232443/https://www.vice....
https://web.archive.org/web/20230519120156/https://community...
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#204Is Signal still a trusted company in the industry? They are based in the USA.
Country of origin doesn't tell you much on its own. Linux is American too, and few question its trustworthiness. What matters is the code being open source and auditable, not where the maintainers live.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#205I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".
Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there. I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#206Earlier quoted context omitted.
"Federation freezes the technology" https://signal.org/blog/the-ecosystem-is-moving/
That's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/ In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardiz…