Edit: Wait, haven't installed anything yet, but I read the getting started guide. I have to sign up using a phone number? That throws all expectation of anonymity and thus privacy out the window.
Edit: Wait, haven't installed anything yet, but I read the getting started guide. I have to sign up using a phone number? That throws all expectation of anonymity and thus privacy out the window.
src: https://news.ycombinator.com/item?id=11672199 (2016)
alternative: https://signal.org/android/apk (2017)
If you don't use it beyond the trial, it's like the public payphone option mentioned by another commenter - someone could take your number. But if you choose to get a paid account (which, among other methods, can be acquired using Bitcoin, Bitcoin Cash, or a prepaid gift card purchased with cash), then the number will be yours. JMP is probably the most anonymous way of getting a phone number.
1) what's your number, and 2) with whom you connect or communicate.
That is, there's still the danger of social graph analysis: "Oh look, this person's communicating with a known journalist!"
If the target use case was people that could reasonably do the job of limiting the information just the use of their devices leaked, it might matter. But the target use case is replacing SMS and the like, so it really doesn't matter (except that people want to pretend that the use case is something other than replacing SMS).
https://medium.com/@thegrugq/signal-intelligence-free-for-al...
Signal wants to distribute a binary with a checksum. Once the checksum is different all bets are off, that's why it's not in F-Droid
Now the question is: (when) will this be supported by F-Droid?
[1] Scroll down for a big graph https://wiki.debian.org/ReproducibleBuilds
[2] https://github.com/signalapp/Signal-Android/wiki/Reproducibl...
The real question is, when will Signal finally support it?
The end result is an app that keeps shooting itself in the foot and being beaten by Messenger and WhatsApp.
At the same time, maybe I don't want everybody who has my phone number to see that I am on Signal.
But it won't improve your anonymity significantly, unless you also use it over TOR.
Use a voip phone number if you want, you only need it to get started.
You need a phone number that can receive texts for the initial setup, but once you're set up people can add you by @username and never need your number. Stuff like https://www.textnow.com/downloads works just fine for the initial text. Once you have a single device set up, it messages your existing devices rather than sending SMS when you try to connect another device.
One of the main people behind Signal actually tried to spread a bunch of FUD about Telegram years ago, saying the crypto was weak, but it's really not. No working POC code was provided to decrypt anything, just FUD.
Protocol details here: https://core.telegram.org/mtproto They just released MTProto2 in the last year.
Group chats aren't end-to-end encrypted, and 1 on 1 chats are only end-to-end encrypted if you make it a Secret Chat.
(Actually I think Messenger might support E2EE group chats, but I'm not sure.)