Registration without a phone number on Signal will use zero-knowledge proofs
201–209 of 209 posts
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#202Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#203Is Signal still a trusted company in the industry? They are based in the USA.
see: https://web.archive.org/web/20250117232443/https://www.vice....
https://web.archive.org/web/20230519120156/https://community...
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#204Is Signal still a trusted company in the industry? They are based in the USA.
Country of origin doesn't tell you much on its own. Linux is American too, and few question its trustworthiness. What matters is the code being open source and auditable, not where the maintainers live.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#205I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".
Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there. I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#206Earlier quoted context omitted.
"Federation freezes the technology" https://signal.org/blog/the-ecosystem-is-moving/
That's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/ In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardiz…
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#207Earlier quoted context omitted.
That's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/ In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardiz…
As a former XMPP believer, I will say that the extremely fragmented capability state of the XMPP ecosystem, whatever people may claim, is the exact proof that vindicates Signal's position.
I'm certainly not willing trade a theoretical minor annoyance in exchange for my (literally) vital messaging needs to be subject to enshittification, or abuse by a single actor (which controls whether I can access the network, when, whom I can speak with, what features I am allowed to use, and whether it's time to rope me into buying some cryptoshitcoin).
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#208Earlier quoted context omitted.
Maybe WhatsApp gives them a ton of metadata like all their contacts, when they chat and with who, IPs, etc. Signal only gives out either time registered or last used last time I checked.
WhatsApp uploads decrypted chats to the cloud once a week.
Re: Registration without a phone number on Signal will use zero-knowledge proofs
#209Earlier quoted context omitted.
Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
> Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)? (Note that I don't care about cryptocurrencies except for the cryptography behind it) There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made…