Star Trek Website
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@lemmy.zip to Privacy@programming.dev · 6 months ago

Signal knows who you’re talking to – Sane Security Guy

sanesecurityguy.com

external-link
message-square
13
link
fedilink
  • cross-posted to:
  • privacy@lemmy.ml
5
external-link

Signal knows who you’re talking to – Sane Security Guy

sanesecurityguy.com

cm0002@lemmy.zip to Privacy@programming.dev · 6 months ago
message-square
13
link
fedilink
  • cross-posted to:
  • privacy@lemmy.ml
alert-triangle
You must log in or # to comment.
  • wildbus8979@sh.itjust.works
    link
    fedilink
    arrow-up
    18
    ·
    6 months ago

    Kinda of a poor write up. I have my issues with this but signal doesn’t really use phone numbers internally, it uses hashes of phone numbers. It’s not as straight forward as this article makes it seem, and this is readily available information that the author could have found.

    • gtr@programming.dev
      link
      fedilink
      arrow-up
      6
      ·
      6 months ago

      Hashing doesn’t really do anything because there are too few possible phone numbers. Easy to bruteforce. See the researchers who enumerated the WhatsApp users database recently via the internet…

      • IceFoxX@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        6 months ago

        deleted by creator

  • staircase@programming.dev
    link
    fedilink
    arrow-up
    9
    ·
    6 months ago

    My vague memory is that Signal doesn’t keep that information, so it couldn’t be subpeona’d, indeed they’ve been asked for it before and declined to share.

    BUT IT’S MOOT IF YOUR MESSAGES ARE VIEWED by sender or receiver ON ANDROID, WINDOWS OR IOS. Those operating systems can just view everything you type regardless.

    • gtr@programming.dev
      link
      fedilink
      arrow-up
      2
      ·
      6 months ago

      How does signal match your contacts based on their phone number then?

      • ReversalHatchery@beehaw.org
        link
        fedilink
        arrow-up
        2
        ·
        6 months ago

        by having you trust intel instead of themselves: https://signal.org/blog/private-contact-discovery/

        • gtr@programming.dev
          link
          fedilink
          arrow-up
          2
          ·
          6 months ago

          Oh but that’s still better than I expected.

      • staircase@programming.dev
        link
        fedilink
        arrow-up
        1
        ·
        6 months ago

        Hence “vague memory”. I don’t know.

  • onlinepersona@programming.dev
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    6 months ago

    Should’ve known this was going to be an ad for SimpleX. They have a hard-on for anti-Signal content. It’s nearly as laughable as GrapheneOS’s hate for anything not GrapheneOS.

    • gtr@programming.dev
      link
      fedilink
      arrow-up
      2
      ·
      6 months ago

      SimpleX is good tho.

      • onlinepersona@programming.dev
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        edit-2
        6 months ago

        Sure, if you like Nazis

        • gtr@programming.dev
          link
          fedilink
          arrow-up
          1
          ·
          6 months ago

          Sorry what?

  • gtr@programming.dev
    link
    fedilink
    arrow-up
    6
    ·
    6 months ago

    In addition to that, in most European countries you have to register with your ID in oder to get a mobile phone number. So its provably end-to-end related to your identity.

    I prefer apps that require no phone number. Like Threema, SimpleX, Session, Status, XMPP, or Tox.

    • IceFoxX@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      6 months ago

      deleted by creator

  • 🇰 🌀 🇱 🇦 🇳 🇦 🇰 🇮 @pawb.socialBanned
    link
    fedilink
    English
    arrow-up
    6
    ·
    6 months ago

    I would hope so. It’s facilitating us talking; it kinda has to know who I am trying to talk to.

  • IceFoxX@lemmy.world
    link
    fedilink
    arrow-up
    2
    arrow-down
    1
    ·
    6 months ago

    deleted by creator

Privacy@programming.dev

privacy@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !privacy@programming.dev

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 371 users / day
  • 1.21K users / week
  • 2.39K users / month
  • 6.83K users / 6 months
  • 2 local subscribers
  • 4.52K subscribers
  • 1.57K Posts
  • 8.54K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • danielintempesta@programming.dev
  • BE: 0.19.18
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org