But... yeah. Yeah. Which is why I got as many people on Signal as I could. Baby steps. The goal here, right now, is reasonable privacy, not perfection.
You can verify the security number out-of-band, and the process is straightforward enough that even nontechnical users can do it.
That's as much as can possibly be done, short of an app that literally prevents you from communicating with anyone without manually providing their security number.
Also, the Signal does not give any warnings or indication that chat partner identify is manually verified. Users are supposed to trust Signal and not ask difficult questions
I'm not sure what else you'd expect. The alternative would be for Signal not to handle key exchange at all, and only to permit communication after the user manually provides a security key that was obtained out-of-band. That would be an absolutely disastrous user experience.
> Also, the Signal does not give any warnings or indication that chat partner identify is manually verified
That's not true. When you verify a contact, it adds a checkmark next to their name with the word "verified" underneath it. If you use the QR code to verify, this happens automatically. Otherwise, if you've verified it manually (visual inspection) you can manually mark the contact as verified and it adds the checkmark.
Ahem. I'd expect something that most xmpp clients could do 10+ years ago with OTR: after establishing an encrypted session the user is given a warning that chat identify of a partner is not verified, and is given options on how to perform this verification.
With CA you can make a mild warning that identity is verified by Signal, and give an options to dismiss warning or perform off-the-band verification.
Not too disastrous, no?
> That's not true. When you verify a contact, it adds a checkmark next to their name with the word "verified"
It has zero effect if the user is given no indication that there should be the word verified.
It is not true what you say. This [1] is what a new user sees in Signal - absolutely zero indication. To verify a contact user must go to "Conversation settings* and then "View safety number". I'm not surprised nobody ever established a verified session with me.
[1]: https://www.dropbox.com/s/ab1bvazg4y895f6/screenshot_2021080...
And it does warn about the contact being unverified directly in the chat window, until you go and click "Verify". The problem is that people blindly do that without understanding what it's for.
[1]: https://www.dropbox.com/s/ab1bvazg4y895f6/screenshot_2021080...
Aside: Signal data never touches iCloud Backup (https://support.signal.org/hc/en-us/articles/360007059752-Ba...). That’s an improvement over a lot of apps.