Signal might be open source but the servers are still run in the USA and thus are subject to the US "legal system" (which in turn is subject to the mood of its president).
Correction: The signal servers don't even have that bit of metadata. See [1], they only store the last time that a user connected to the server.
https://signal.org/bigbrother/eastern-virginia-grand-jury/
Signal turned over everything they had on this user (which was two time stamps: user creation and last access), and fought the gag order to be able to publish the subpoena and the response. Signal would have to be pretty stupid to lie to a federal court.
Think what you want, but Signal doesn’t have any metadata to turn over.
Even if I couldn't break the encryption I'd have timing and connectivity data.
So, if I were a user, I would always operate on the assumption that info would leak.
Getting people to use Tor for everything is hard enough, good luck getting people to use stuff even more obscure.
Note that it's what they claim at least. It's not verifiable client side, and to be honest, it's hard to come up with a scalable protocol where this is the case, but you should still not repeat their claim as a matter of fact while in reality we only have their word that the code actually matches what's deployed. And even if they don't store anything, AWS could still provide interested entities access to the infrastructure to capture what Signal doesn't want to capture. Yes, features like sealed sender are awesome and are an important step, but the service still gets ip addresses, which do provide hints about the sender. Again, likely Signal doesn't store ip addresses but people with access to their infrastructure could.
Furthermore, Signal's encryption doesn't help against people storing all of Signal's traffic and waiting until attacks on crypto algorithms become practical (quantum computers, theoretical progress on attacks). Some secrets become irrelevant with time, others increase in value. The best defense is never having the message leave your country's network in the first place.
And there's the DOS problem. What happens if the american president decides that the EU should be cut off from all US network connections? The EU parliament members can't even organize a good response to this because they use an american service...
As an EU citizen, I'm half puzzled and half horrified at how happy the EU institutions are to rely on foreign products: especially coming from a country that has a history of being trigger-happy and cutting people off in the name of a "trade war".
This also is not for official communication , it's just for any case where staff would currently use WhatsApp or similar spyware.
[] i.e. the build installed on my phone, not the build available no Google's server to download.
Just keep relying on some Californian dude that insist i give him my and my friends phone numbers?
And harass me so i give him more info to “personalize my profile” !?
session (very bleeding-edge p2p signal fork) https://github.com/Loki-project / https://getsession.org/
- There is a fixed pop under at the bottom of the screen asking me to confirm my profile name, with “Get Started” or “remind me later” (which is apparently every time i come back to the app), and no “never“ option. I had already put a first name but that’s not good enough. Had to do it again to confirm i don’t want to share a last name with him / them.
- why does he care about the distinction between a “first name” (mandatory) and “Last Name” (optional)
-> Only the user should care about the name.
=> Why should the app / he / them get access to my contacts list to update a contact name? I’m perfectly willing to have duplicate contacts siloed in a “secure messaging app”.
Also, could someone explain why the app need phone numbers ? They only send some initial token over SMS, which can be spoofed.
Looking at the other comments, the European alternatives don’t look very secure, so it looks like they prioritized security here.
In what way are Wire and Matrix not very secure, though?
A half-broken service would be better than one under US control as the US is the one doing the most snooping on EU. Getting everyone to switch if Signal ever stops being secure would be way harder than to pick a better service now and help secure it.
Matrix would be a better choice for one. Saying EU services isn't secure is hyperbole.