What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be downloaded if they do not add the backdoor in? Is there a workaround that will allow people to use it still? I've heard people mention locating the servers in other countries, but wouldn't the various App stores be bound by US law and still not allow them?
Looking back at how Signal works
31–40 of 301 posts
Re: Looking back at how Signal works
#32Earlier quoted context omitted.
Don't you have to keep paying for the sim, otherwise someone else might "steal" your account once your phone number gets reused?
Signal has an option to prevent this by locking the number with your PIN. This capability introduces plausible deniability that a phone number assigned to a SIM is actually associated with the number of a Signal account. Don't know if that matters legally or not. Also the people doing shady things are generally hopping accounts regularly anyway.
Re: Looking back at how Signal works
#33What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be downloaded if they do not add the backdoor in? Is there a workaround that will allow people to use it still? I've heard people mention locating the servers in other countries, but wouldn't the various App stores be bound by US law and still not allow them?
Time for a privacy focused app store!
Re: Looking back at how Signal works
#34Earlier quoted context omitted.
Don't you have to keep paying for the sim, otherwise someone else might "steal" your account once your phone number gets reused?
Signal has an option to prevent this by locking the number with your PIN. This capability introduces plausible deniability that a phone number assigned to a SIM is actually associated with the number of a Signal account. Don't know if that matters legally or not. Also the people doing shady things are generally hopping accounts regularly anyway.
Re: Looking back at how Signal works
#35But it just feels cheap and detrimental to LARP as a tool for revolutionaries. I want a clear concept of privacy for a stable society to rely upon. That even the most trustworthy authority be kept out by design as a security principle. I don't want my messaging app to be opinionated, pick sides or declare themselves part of the ongoing "progress". Will they sing the same tune when it's other group taking the streets? Because everyone has a different idea of the kind of revolution that is needed, and certainly my phone should not have a say.
Re: Looking back at how Signal works
#36Earlier quoted context omitted.
In most European countries you need to submit your ID to get any sort of working SIM card.
If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers. As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up. These other apps send your social graph to their servers, track and store metadata, don’…
Re: Looking back at how Signal works
#37What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be downloaded if they do not add the backdoor in? Is there a workaround that will allow people to use it still? I've heard people mention locating the servers in other countries, but wouldn't the various App stores be bound by US law and still not allow them?
Signal started open-source, it was TextSecure, I'm sure there'll be an open-source alternative if the commercial entity fails, though I hope they do not.
Re: Looking back at how Signal works
#38Re: Looking back at how Signal works
#39Earlier quoted context omitted.
If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers. As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up. These other apps send your social graph to their servers, track and store metadata, don’…
> roll their own cryptography Signal did the same thing. They invented their own cryptographic algorithms. https://en.wikipedia.org/wiki/Double_Ratchet_Algorithm And the social graph IS sent to servers by Signal. It's protected only by hashing (trivial to circumvent) and by the Intel SGX technology (a bit harder to circumvent, but I doubt that the US govt can't do it).
Am I wrong?
Signal’s cryptography has also gotten a ton of attention, I don’t think the same is true for competitors.
Re: Looking back at how Signal works
#40Earlier quoted context omitted.
If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers. As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up. These other apps send your social graph to their servers, track and store metadata, don’…
I feel comfortable with giving my Telegram username out to random people on the internet and posting it on my website because it doesn’t mean anything outside of Telegram. I wouldn’t post my phone number publicly.