I’d much rather have potential “evidence” against me on my phone, than on my laptop.
The stakes are very high though, and the attackers very motivated and well resourced, and I suspect there’s enough political pressure on them both to do only “a good enough job to make it look like they’re succeeding”. If anybody thinks the NSA isn’t several steps ahead of both Apple/Google and NSO/GreyKey, wtheyre fooling themselves...
Edit: it seems that Signal uses db protection but in a way that fails for a cracked phone like this (?): https://news.ycombinator.com/item?id=26096778
> That latter acronym stands for “after first unlock” and describes an iPhone in a certain state: an iPhone that is locked but that has been unlocked once and not turned off. An iPhone in this state is more susceptible to having data inside extracted because encryption keys are stored in memory.
I do wish Apple would add "restart" as one of the system actions in the Shortcuts app.
Then again, i've been spending most of last year in my home, and i live in a rural area, so not much activity besides my wife and kids. I can only assume that the busier your surroundings, the more power is being drawn for contact tracing.
Even if this 'hackability' is an issue only with the security of the phone/hardware - able to be hacked and thus reach the decrypted signal messages - That also means, that person's Signal contacts also have their real identities exposed. (Where they wouldn't be if the account names/ids could be arbitrary like eg. wickr)
It’s not anonymity focused.
If I want to have private conversations with friends, family or colleagues signal is fine.
We expect heads of state to be able to have “private” discussions while knowing the other heads of state they may be communicating with. I can have “private” conversations with my partner, even though people know who that is.
You can also choose to anonymously communicate with no privacy, Reddit or 4chan style...
They may not be totally orthogonal, but I don’t think either privacy nor anonymity are encapsulated by each other.
There is also still privacy in public communications when done anonymously, as you can't tie the information disclosed to the real identity (necessarily). -- Hence why for privacy purposes advertising data is often anonymized. (But again, less private of course, if ie I said I was a 2 fingered man in Poland and there is only 5 people fitting that description)
So I'd still say, perfect privacy cannot occur without anonymity.
Edit: it seems that Signal uses db protection but in a way that fails for a cracked phone like this (?): https://news.ycombinator.com/item?id=26096778
To what end?
If there's no additional authentication required to open the app and just view the messages normally, it's useless because they can just open the app and view the messages.
If they use their existing PINs as key material then, given an OS-level exploit grants access to the underlying database, it can be cracked offline in... basically no time at all.
If they allow you to create a long, secure password for opening the app, basically nobody uses it because nobody wants to type a 30 character password on a phone touchscreen every time they want to check/send a message.
Pretty much any solution that doesn't absolutely destroy usability still relies on the OS performing some sort of authentication first. (As in the current solution where the encryption keys are stored in the OS-level key store.)
If you're that concerned about your security, just go disable FaceID/TouchID so the iPhone never leaves keys in memory when it's locked.
All these articles and "criticisms" of Signal started popping up right after the recent WhatsApp mini exodus. What a coincidence.
Thomas Brewster has been on the encrypted messaging apps and law enforcement beat for a very long time and puts these stories out with regularity