Users should be warned of perils of phones not quite under their control. Set up a proper FOSS machine that you understand, and use own encryption (be it PGP or some other tool serving the same purpose).
Users should be warned of perils of phones not quite under their control. Set up a proper FOSS machine that you understand, and use own encryption (be it PGP or some other tool serving the same purpose).
Edit: or generate a UUID type random string for each new device.
To be fair, you've always been able to verify safety numbers (i.e. fingerprints i.e. public key hashes).
I was referring to ways to establish such secure secondary channels. Either verify a key yourself, eg, in person, or use distributed trust to average out the noise.
For example, keybase has an approach: linking various identity information to keys.
Signal is secure in a strange narrow interpretation of the security. There are problems if you look more broadly.