Look no further than Signal's supboenas and how they respond to them. With all the information they hold about an account. Which is just the creation date and last connection date. https://signal.org/bigbrother/eastern-virginia-grand-jury/
Look no further than Signal's supboenas and how they respond to them. With all the information they hold about an account. Which is just the creation date and last connection date. https://signal.org/bigbrother/eastern-virginia-grand-jury/
Signal's subpoenas have always left a sour taste in my mouth. I just can't believe that they are getting so few, at least some cases they'll just send the standard letter out and will try to get something. Having no list of how many they have rejected would at least increase my confidence in them a bit.
But the bigger issue is, that they data they provide is just too good to be true for the majority of users. Signal has a push token for the vast majority of accounts otherwise they wouldn't be able to send out push notifications on iOS and would waste at least some battery on devices with Google Play services installed. The subpoenas always seem to affect people who have an Android phone without Google Play services installed. In my eyes is too strange of a coincidence to be true.
Signal does at least a bad job of explaining what kind of data they keep on an average user.
It's technically possible for them to not know which phone numbers correspond to which devices and tokens.
It doesn't matter. The problem with Signal is that it is vulnerable to being shutdown easily.
So Google or Amazon or where ever Signal is hosted can just shut it down and will receive a request by the authorities to show that it is aiding and facilitating in illegal activities and will blame it on the tons of criminal networks, terrorists, insurrectionists and gangs all using Signal.
Thus, Signal really is a centralized dead end in the long run. Anything that is decentralized or allows self-hosting is the way to go.
The only place you'd find technical talent is in the federal police or a few guys higher up in the major urban police forensics labs.
Exactly. It could be the truth or Russian psyops to undermine the trust among users, which happens very often from all sides involved, not just during war time. It should be noted that all governments hate private communications systems, except when they suit their needs. That's one more good reason to push for systems offering full e2e encryption by default.
Signal, WhatsApp, iMessage and Threema seem to do just fine.
Unrelated to this, but for all intents and purposes, iMessage cannot be considered e2e encrypted if either party has iCloud backups enabled. Apple has access to your iCloud backups, and they contain the iMessage keys.
Well, except Threema. Last time I used it, it was not possible to receive their messages across multiple devices simultaneously.
A talk on the technicals can be found here: https://www.youtube.com/watch?v=7WnwSovjYMs&t=1762s
Why not? You can encrypt a message with more than one key, no? It’s still e2e, just that there are multiple ends.
Apple’s Messages is e2e (until SMS is used) and they have group chats.