Live data from Hacker News

Registration without a phone number on Signal will use zero-knowledge proofs

community.signalusers.org

211–220 of 224 posts

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#211
post #99

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims abou…

"...otherwise they would welcome third party clients..."

Signal app can update itself at any time

The app is constantly phoning home to Signal servers checking for updates even when it has not been launched and is not being used

That means the client could change at any time, for any reason, unbeknownst to the user

If the advanced user is free to write, edit and compile source code for a Signal client, software developers might call this a "third party client" because there is allegedly some "business transaction" between Signal Corporation and the user where Signal Corporation and the user are first or second parties (although, curiously, the Signal app and service are free)

But it's arguable the more important use of the term "third party" in this context, i.e., "secure" communications, is to indicate a party that is not a first or second party to the communication, a potential eavesdropper

Signal Corporation is a third party to the communication

Because it forces users to use its closed source client software that can be updated at all times for any reasons when it's installed on a user's computer, there exists the potential for remote code execution and, for example, eavesdropping

For example, a US corporation subject to US law could be legally forced to eavesdrop on a particular user. This could be done with an "update"

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#212
post #71

Earlier quoted context omitted.

> the surveillance networks can capture metadata - who talks to who and when If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.

I'm not familiar with SimpleX, but keep in mind only some types of onion routing is secure against a global passive adversary. Famously Tor is not.

One idea I had for an improvement to Tor wrt sybils was to split traffic up and send different pieces to different nodes, possibly using different circuits for the pieces, so that even if you have control over all the nodes in one path, you most likely won't have full control over all the paths it sprays the pieces over.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#213
post #92

Earlier quoted context omitted.

> the surveillance networks can capture metadata - who talks to who and when If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.

Session uses onion routing. SimpleX does not.

> SimpleX does not.

https://simplex.chat/faq/

> Private message routing is, effectively, a two-hop onion packet routing.

And actually, it's even better than that:

> Private message routing routes packets (each message is one 16kb packet), not sockets. Unlike Tor and VPN, it does not create circuits between your client and destination servers. The forwarding server creates one shared session between itself and the destination, and forwards all messages from you and other clients to that destination server, mixing messages from many clients into a single TCP session.

> As each message uses its own random encryption key and random (non-sequential) identifier, the destination server cannot link multiple message queue addresses to the same client. At the same time, the forwarding server cannot observe which (and how many) addresses on the destination server your client sends messages to, thanks to e2e encryption between the client and destination server. In that regard, this design is similar to onion routing, but with per-packet anonymity, not per-circuit.

> This design is similar to mixnets (e.g. Nym network), and it is tailored to the needs of message routing, providing better transport anonymity than general-purpose networks, like Tor or VPN. You still can use Tor or VPN to connect to known servers, to protect your IP address from them.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#214

Earlier quoted context omitted.

A bare minimum for a company that offers private communication services to people like whistleblowers and activists is that they clearly/plainly explain to their users what their risks will be when using the service. Signal fails at this. They outright lie to their users. They've started permanently keeping sensitive user data in the cloud, but they've refused to update their privacy policy to reflect that. Misleadin…

I'm doubtful that this is true. Lying in a privacy policy is a crime.

Look for yourself. The very first line of their policy is "Signal is designed to never collect or store any sensitive information"

At one point in the distant past that was actually true! They used to brag about how many times the government came to them requesting information only to be turned away because they never collected any of that in the first place.

In 2020 they introduced a major update where they started keeping user's name, phone number, photo, and (worst of all) a list of their contacts in the cloud. This is exactly the same information governments had been requesting from them. There is no way to opt out of this data being collected. You can opt out of setting a pin, but if you do that a pin is auto-generated for you and the data still gets uploaded even though you won't have any access to it.

In 2025 they added yet another new feature called "Signal Secure Backups". This was an optional feature that let users store actual message content in the cloud as well. They've refused, for years now, to update their privacy to reflect any of that. Their privacy policy is frozen as of May 25, 2018

See: https://web.archive.org/web/20250117232443/https://www.vice....

https://web.archive.org/web/20230519120156/https://community...

Personally, I think their refusal to update their privacy policy is a big fat dead canary warning users that the service has been compromised and shouldn't be trusted. They may be under gag orders from saying so outright, but while the US government can order companies not to tell the public something, they can't force them to say something. For that reason, unless somebody sues them over it, I doubt their privacy policy will ever be updated.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#215

Earlier quoted context omitted.

>Figure out your adversaries, how much power they have and what they are willing to spend. All of it.

Unless your adversary is divine this isn't true. In general people who believe this way make really bad trade-offs and as a result probably have worse security than most people.

Go on.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#216
post #134

Earlier quoted context omitted.

Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company? As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it. Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.

[deleted]

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#217

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

When news leaked that federal agents and contractors had access to WhatsApp "end-to-end encrypted" messages using the "Signal Protocol", WhatsApp users sued Meta

Faced with mounting statutory damages per violation for wiretapping claims under CIPA and Pennsylvania's wiretap act, Meta forced arbitration

https://ia801900.us.archive.org/6/items/gov.uscourts.cand.46...

"48. After Meta acquired WhatsApp in 2014, WhatsApp partnered with Open Whisper Systems to integrate the Signal Protocol, which is an end-to-end encryption cryptographic protocol, into the WhatsApp platform.26 The integration of the Signal Protocol onto the WhatsApp platform was completed by April 5, 2016.27

58. Recent reporting has confirmed that WhatsApps numerous promises that no one other than intended recipients has access to users communications is false. Indeed, contrary to WhatsApps repeated assurances otherwise, Meta, WhatsApp, their employees, contractors, and/or third-parties personnel have access to users WhatsApp messages.32

59. According to whistleblower accounts reported to federal investigators, employees of Meta and WhatsApp and third-party contractors employed by Accenture are able to access the contents of users messages, contrary to the privacy representations made by the company.33

60. Former Meta contractors reported to special agents with the U.S. Department of Commerces Bureau of Industry and Security that they and some of their colleagues had broad access to the substance of WhatsApp messages that were supposed to be encrypted and inaccessible.34 The two sources confirmed that they had employees within their physical work locations who had unfettered access to WhatsApp, and one stated that she spoke with a Facebook team employee and confirmed that they could go back always into WhatsApp (encrypted) messages.35

61. Moreover, these whistleblowers have outlined much broader access by Meta employees and third-party contractors than the limited access described in WhatsApps Privacy Policy and website.36

32. Jake Bleiberg, US Has Investigated Claims WhatsApp Chats Arent Private, Bloomberg (Jan. 29, 2026, at 16:22 ET), https://www.bloomberg.com/news/articles/2026-01-29/us-has-in....

33 Id.

34 Id.

35 Id.

36 Id."

Unless users control the client software, "end-to-end encryption" is just marketing

Closed source apps and backends by US companies means communications can be monitored if US law requires it

A "backdoor" in the client app can be easily installed remotely by the company through an "automatic update"

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#218
post #99

Earlier quoted context omitted.

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims abou…

"...otherwise they would welcome third party clients..." Signal app can update itself at any time The app is constantly phoning home to Signal servers checking for updates even when it has not been launched and is not being used That means the client could change at any time, for any reason, unbeknownst to the user If the advanced user is free to write, edit and compile source code for a Signal client, software devel…

Are you a LLM? In this context, a third party client clearly refers to "a Signal app/client software that's not distributed by Signal",

The point I was making is that this goes against Signal's terms of service, and can get your user account terminated. That's a very oppressive clause in practice, you may want to use a non-signal client for all kinds of legitimate reasons (porting to a non supported platform, to adapt for accessibility needs, for privacy, for compliance, to remove nagging and dark patterns, etc). Signal don't want that, they want to control your user experience, even if this makes it worse for their user.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#219

Earlier quoted context omitted.

I'll see your conspiracy theory and raise you one: What if the feds fund tech privacy projects specifically so that people like you won't trust them, and instead embrace privacy nihilism? This is a known strategy of the Kremlin, by the way. They fund opposition groups which protest them, and then leak the fact of that funding so that people who are genuinely upset at the Kremlin get confused about who is captured opp…

They funded it from the start via Radio Free Asia (CIA) and the Open Technology Fund. Signal is for protecting opposition groups that help in regime change operations. Why would people embrace privacy nihilism? The Signal shills also agitate against gpg/PGP, so we know it is secure and you should use that instead.

>Signal is for protecting opposition groups that help in regime change operations

SMS registration flow is trivially blocked in places where regimes are controlling telecom infra. And Twilio is unreliable in dozens of places for non-political reasons. Signal is very first-world centric from this point of view.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#220

Earlier quoted context omitted.

to be clear though notifications do the decryption on device themselves. signal uses apple/play services only to notify the device that there has been a message, none of the contents are delivered over these services. if you cant trust the device to do that then no messaging app could ever be secure enough

> if you cant trust the device to do that then no messaging app could ever be secure enough This is the whole point. Signal actively prevents me from using it outside of the Apple-Google duopoly. Other messaging apps are not like this.

De-jure it's against the ToS, but it's not being enforced besides "don't be an asshole, don't abuse the network and be careful with Signal branding". Technically, you can use Whisperfish on SailfishOS, Flare on mobile-linux-of-the-day or even signal-cli as a primary device.
Post reply on HN