Signal is secure, as proven by hackers
kaspersky.co.uk
kaspersky.co.uk
While they never classified them as data breaches, they had all the numbers in their system extracted number of times.
If someone was using a real phone number, even if Signal was secure — just knowing the number alone would give an attacker addition information. When Moxie was in charge, he repeatedly refused to allow new users to signup without phone, even though in there numerous ways this could have been done and are being done by their competition.
Lastly, all three Signal board members have held the top leadership role in past year, which is highly unusual, in fact, never heard of anything like it.
Also, might be wrong, but appears Signal’s secure enclave, which is based on Intel’s SGX technology, is known to be vulnerable to side-channel attacks and Intel’s SGX code & hardware is not open source:
https://medium.com/@maniacbolts/signal-increases-their-relia...
Basically all it does is given Signal plausible deniability for public search warrants:
https://signal.org/bigbrother/
It would do nothing to stop national security letters. Basically, you should assume the functionality provided by the secure enclave is only in name; given the NSA ATT national security letters enabled both physical access and system modifications, see no reason to believe others would not be required to do so as well:
https://en.m.wikipedia.org/wiki/Room_641A
Again, average person does not have a threat model that makes this relevant, but to say Signal does not have access to the SGX data is purely based on trust, not mathematical proofs.
If your threat model does not allow it, use manual e2ee with pigeons. Otherwise, well secure enclave will get better with time, which will make Signal better too.
Intel already dropped SGX from their new line up of CPUs (11th gen +).
1. SGX is just an implementation, could be replaced by something else. 2. SGX still works on CPUs that have it.
There's not necessarily "alternatives" most of the competitors offer a much richer feature set and Signal has stripped away those features down to what they see as the bare minimum.
> As such, the cybercriminals managed to pull off the attack by impersonating the victim of the attack for roughly 13 hours.
All the contacts of that victim would have received a warning that the victim had changed their encryption keys (WhatsApp has that warning too, but unlike Signal it's disabled by default), and IIRC, that warning shows up before you try to send a message. Even if they're not the kind of people who checks whether the encryption keys match (it's very easy to do if you're meeting in person, but not many people do), that warning can be enough to alert the contact that something odd is going on.
Title is low-brow and weak.
"secure from a small group of specific hackers" is not as catchy though.
> And, of course, install a security app on your smartphone.
And as such, Signal/Telegram/Whatever that requires me to enter phone number, has zero trust from me. I don't care who analyzed the protocols security, what the safety measures are, what cipher algorithms you use, how many hackers tried to break in and failed, what other PR/SEO methods you use.
Just the fact, that you require information that is so deeply PII as phone number is a reason that overrides everything else. From my standpoint, software that requires that, is honeypot.
(btw, this is my personal opinion, you don't have to agree - I can (from any device, without giving any PII, now or 20 years in past) login into IRC network (vpn/... is outside this topic) and use asymmetric cryptography (with exchanging public key safely by some other method, stenography anyone?) to chat completely secure. I can send email (with exchanging public key safely by some other method, stenography anyone?) and communicate completely secure. I can use Counterstrike chat on random server to do the same. So what does the Signal does for me in terms of safety of exchanged information? Show me a nicer UI so I can use graphic smileys?)
But I agree with you, asking for the phone number and telling me this app is secure is ridiculous. Let me register with something less intrusive, if I want to go the phone number way, then let me use that. Give me an option.
Can you trust your information stored at your messaging app's servers stay secure forever? Can you trust that company to never get compromised? So yeh, they go through all the hassle of making things "secure" but attach everything to something(phone number) most of us can't get without revealing our actual details. So yeh, its ridiculous to go through all this hassle to make things private and secure, but force people to use something that de-anonymizes everything about them.
I don't write anything that would be interesting to the NSA, I'm not a target for them, so I don't care if they see I use Signal.
BTW, say you have an anonymous Telegram username, I'm pretty sure it's trivial to find your name from the content of your messages. Or just from the metadata.
If I told my mom to install some app and we'd connect to each other using some random IDs, we'd probably still be using SMS.
Can someone explain how this is possible? How does my phone know when to notify me that a friend has joined signal?
Edit: apparently it's "private contact discovery", I need to give this a proper read later.
This is surprising to me, since it was my mother's generation that got me into Skype (where you have to manually add the other person by their username), almost twenty years ago.
(Even worse, not long before that you had to manually punch the other person's "ID" into the device every time you wanted to talk to them!)
Security and privacy are not the same thing.
Among many other differences: security is a binary (can an attacker gain access to information) but privacy is a spectrum (what kinds of information do I want to leak).
Only if you're looking through a very narrow lens.
There are a range of potential attackers out there with different motivations and resources available to them. The question you have to ask (for each attacker) is whether the value of the thing you are trying to secure is worth more to them than the cost it would take them to break your security.
In aggregate, that looks a lot like a spectrum of security, with different people being secure against more or fewer different attackers.
Maybe you're saying that some information is more sensitive than others, which is true, but some security failures are worse than others (e.g. denial of service vs. remote code execution, or ability to forge messages vs. ability to decrypt messages).
I do not understand what privacy security or anonymity I can have, when we start with sharing my most identifiable personal information with the app and all my desired contacts. (whatsapp takes it further by refusing to work without full access to your contacts which... Just, no).
I feel I'm in a twilight zone as everybody cheerful regresses to apps you have to bootstrap with your phone number and then proceed to basically only work well with your phone - teeny tiny screen with awful keyboard, instead of allowing me seamless access across my communication devices and preferences.
Messaging seemed like a solved problem until we made it inexplicably and massively worse.
I’ve never given WhatsApp access to my contacts. Works fine. Just don’t get numbers matched to contacts, which makes sense.
I can only talk to people if they've granted access to their contact list, and initiate conversation with me (which is not a solution, just a shifting of problem to others).
On android at least, I cannot initiate a conversation with somebody I don't have a going chat with. It won't let me just type in a phone number.
Specifically, Clicking "new chat" asks me for contacts permission, and if I say no it simply closes. I have to contact a person out of band and ask them to initiate whatsapp with me. By no definition is my experience "just fine". Is this not your experience?
Can two people who have not granted access, converse?
(I would still not call it "just fine" in terms of normal app usage, but it makes my life easier so I thank you for that :)
Yes. There is a little write icon on the top-right of my iOS screen. Click that and paste in the number.
How would this other method make it hard/expensive/infeasible for a malicious company to produce 100M accounts to cause problems with spamming, DoS, and related issues? Phone numbers are finite, cheap, but not zero cost. If sending a spam email cost $0.01 much of spam would disappear.
How would this other method protect a user's social network without having to upload that meta data in signal? Currently this is handled by a user's address book hosted outside of signal. How many users would you lose if you required some key exchange in person?
Sure it's easy to think about generating a key pair, uploading the public key to a DHT, and allow people to communicate directly without a central server. However that has a fair number of practical issues that would be worse for the average signal user, not the least of which would be much worse battery life and bandwidth charges.
So you pay $5 on a credit card, which connects you to said handle, much like buying a SIM. How is that any better?
Someone in your social network joins signal next week, how would they find you?
I know which of my coworkers use signal, despite them not telling me themselves. That seems wrong.
Buying things anonymously is a solvable problem. Gift cards, cash, etc. Let people resell your $5 sign up card.
So the reason signal is so useful is because so many people use it, which depends on things like contacts showing up immediately when you join.
Seems like it's a common theme that people want a messaging client with a huge number of users, but don't want the features that made it popular in the first place.
Signal could use payments (eg via Monero) as spam prevention and revenue stream.
This would not damage any current feature/user
https://community.signalusers.org/t/usernames-in-signal/9157...
I understand the whole concept behind it. I understand why they want a phone number. BUT. This is not secure (oh, really, my phone number is hashed, how long do i need to brute force a few numbers in range of 0-9, a few seconds on my laptop, maybe?)
On the other side, I can use a simple email/irc/counterstrike chat to be MORE secure. Why? As it doesnt require any PII from me.
So why bother? Yes, sure, I can use it as a nice chat interface, I can use it as another way beside ~20 chat applications I need to use to contact people I know ( https://imgs.xkcd.com/comics/chat_systems.png ). But dont sell me security. With requiring PII they broke it.
If you are not interesting for the NSA, giving your phone number to Signal is fine. If you are... run. The counterstrike chat won't hide you.
complex captcha and/or expensive PoW. and an option to use a phone number instead
>How would this other method protect a user's social network without having to upload that meta data in signal? Currently this is handled by a user's address book hosted outside of signal. How many users would you lose if you required some key exchange in person?
store it on the server, encrypted by the client. jesus.
How do you find each other?
If it's feasible for an end user, say 30 seconds of a phone's CPU, you can be sure that a spammer could generate millions.
You don't, because that's something that's fundamentally impossible to do in a privacy-preserving way - no way around it.
> If it's feasible for an end user, say 30 seconds of a phone's CPU, you can be sure that a spammer could generate millions.
You're picking overly conservative numbers for "feasible". Choose parameters such that it takes something like half an hour on a phone. Inconvenient? Yes, but privacy is inconvenient in general.
And yes, a spammer will still be able to generate lots of these fake identities, but now the cost is much higher, while the expected profit is roughly the same - and that's how you defeat spam.
So if signal was privacy preserving, didn't show or tell contacts about others using the service, do you think it would be as popular? Or do you think we'd be discussing a different popular e2e encrypted app and complaining about the very features that made it popular?
by exchanging public keys over an established communication channel
>If it's feasible for an end user, say 30 seconds of a phone's CPU, you can be sure that a spammer could generate millions.
yeah, that's an inherent limitation of PoW, so it has to be an option rather than a requirement. then people who don't care about privacy can do the SMS thing, and those who do can opt to do the 30 minute PoW.
but this is irrelevant to Signal. it's not the phone number verification itself that people have problem with. if the only purpose it served was to prevent attacks on the service by ratelimiting it to one account per one phone number, that would be largely fine. the problem is that your phone number is your Signal identity, which is utterly moronic for a "privacy-first" service, and the reasoning and excuses for this stink to high heaven.
I get the appeal, but seems like requiring out of band key exchange will add significant friction and make signal much less popular compared to the competition. I've got a few dozen signal contacts, only a few of them close enough to do a key exchange. If I only had a few, not sure I'd use signal.
Signal has been resisting making special cases for the few, and I get it. Why spend developer time on some feature that's not going to benefit the majority of users?
> the problem is that your phone number is your Signal identity, which is utterly moronic for a "privacy-first" service
I can't think of anything that would work as well and result in so many (40M monthly) people communicating securely. They do seem to be considering their options to help with this, in particular: https://signal.org/blog/secure-value-recovery/
Allowing social networks, surviving the death of your phone, frictionless on boarding, account recovery, etc all interact in complex ways.
Personally I like that there's not a contact database/social graph inside signal.
how do you exchange phone numbers and email addresses with people?
>and make signal much less popular compared to the competition
is popularity among the (COMPLETELY) tech-illiterate worth giving up privacy for?
>I can't think of anything that would work as well and result in so many (40M monthly) people communicating securely.
and virtually everyone who had ever used the internet has an email, despite its apparently cumbersome sign-up and contact discovery procedures.
>surviving the death of your phone, ... , account recovery
are less likely if your account is tied to the phone number or email. they can be lost, they can be stolen, they can be seized.
I don't want to find people on Signal, or be found by them. I want a way to securely communicate with people I've decided I trust enough to be contactable by them - that is, people I've met and sufficiently liked face to face.
But why then do you even need a phone number to use WhatsApp? If it is a texting and calling service that is used to circumvent carrier fees, and is almost exclusively used on WiFi (because data is even more expensive than texts), why not just let them make an account and not use the phone number? That way they don’t have to pay a secondary company to use WhatsApp…
https://hn.algolia.com/?query=Threema&sort=byPopularity&type...
(anyone down-voting this post - you don't agree? You are welcome to join the experiment too. Why don't you put your livers where your mouth(fingers) are? I know for myself that immediately when you would show me rubber hose (not even coming to wrench!!!) I would tell you whatever you want to know. But you can obviously do it better, so lets test it. I have a nice, 1kg french wrench waiting for your beliefs (and knees). Yeah, I know I am not politically correct, but facts are facts and you deny them for unknown reason. /s)
I'm actually with you here. But anonymity is HARD. Way harder than people give credit. We're not anonymous here on HN. But Signal is doing this step by step and I think that is the right way. Yes, the wrench attack works, but it doesn't always work. It would be better if it was hard to use the wrench attack, but protecting against it is surprisingly difficult. Signal seems to be taking this into account and also working on this in steps.
What is hard are their other use cases. Preventing rotten eggs entering the system. And they cut shortcut here, sacrificing security of their users to keep the bills down. The phone number requirement is not there to protect you but to protect their ecosystem and even more their resources (if I take it as lightly as possible, check the last line).
Again I will use IRC as an example, it was able to connect so many people without requiring PII, yes there was spam (same as with emails, I host my own mail server and I dont see spam, it is 100% filtered out by rspamd), for what, 30 years(?), they can do it too. I don't see any excuse for their requirement.
But ok, lets be fair - easy to connect. I have around 400 phone numbers in my phone of people I asked for their phone number - they were relevant to me at some point, for instance primary school schoolmates. How many, do you think I communicate with? I went to count history for last year - 35 numbers. 35! Out of those, I would communicate over secure channel with 6 (current company). And now this is an issue?
Let me say it again, with all the facts, I can only take them as a honeypot.
It is hard to respond to you in good faith because it does not feel like you want to engage that way. Maybe I am misunderstanding your statement. So I will engage in good faith once more (reminding you that this is a HN rule).
Anonymity is nowhere near as simple as not requiring PII during registration. Even from the provider side. We can agree that it is difficult to maintain anonymity from the user side. But choices made by the provider can make these things impossible. Let's suppose Signal gives me one username that I can use and I must use that continuously. What do I choose? If I use "godelski" then I've made a permanent connection between that identity and my real life identity. After all, I do talk to friends, family, and coworkers on Siganl. If I choose another name and share that name through this name, then those two are linked together. All of this is information leakage and highly valuable to OSINT people. I'm sure someone here has significantly more experience than me and would be happy to expand upon this too. But it is extremely naive to believe/claim that anonymity is provided simply by removing the phone number. It is far more complicated than that. Hopefully you now know that.
Super hard to prove though...
For me personally the strongest hints are the fact that it's centralized, there's no getting around connecting to their server(s) for the app/clients to be useful and that it's impossible to know what exactly their server is running (by design?).
Oh, and Signal is based in the US. That fact by itself pretty much means all bets are off when it comes to security or anonimity.
I don't see how the NSA would not be pwning that server or owning/creating that server and/or organization (indirectly or directly).
Or to put it differently: why would it be hard or illogical for the NSA to setup an innocent seeming "good guys" radiating non-profit chat service that is supposedly secure (yet centralized and non-anonymous by design and also a honeypot)?
https://news.ycombinator.com/newsguidelines.html
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Can we not point out when corporate entities are comprised of these things?
It has to be based somewhere right? Would you trust it if it was based in China or Russia? Or even mid tier countries like UAE or Singapore? Even "neutral" countries like Switzerland isn't safe, as we've seen with Crypto AG.
I hate web3 hype as much as the rest of HN, but this seems like a genuinely useful application for it.
Let's also investigate the inverse side of this. Supposing Signal works, would the NSA not instead want to launch a disinformation campaign against them and exaggerate downsides? I think such action would also be easy and logical.
But I don't think that's happening, to be clear. I think people are just passionate about the subjects and with passion people are often excessively head strong (this is something disinformation campaigns prey on btw. They often play both sides because chaos is often more effective pushing a singular narrative. See "malinformation").
> Oh, and Signal is based in the US. That fact by itself pretty much means all bets are off when it comes to security or anonymity.
(anonymity. FTFY) I do agree that being US based comes with certain risks, but the US is not authoritarian and is unable to force companies to collect data. This is enough to raise suspicion but not enough to be damning. The suspicion is also reduced given that Signal publicly discloses subpoenas that they receive. Insiders like Snowden also advocate for its usage as well as many major players in the security community, globally. One can come back and suggest that this is disinformation but that increases the complexity of the honeypot campaign and as history has shown, complex conspiracies unravel quickly. Especially in high profile cases, and since Signal is universally suggested as the gold standard by the security community, I'd argue it is pretty high profile.
The problem with conspiracy theories is that it is easy to turn evidence against a conspiracy into part of the plot and coverup. But this just exponentially increases complexity. And anyone that has worked for or with the government will gladly tell you how ineffective they are (often in the form of complaints). After all, two can keep a secret only if one of them is dead. The fact that it is difficult to prove (and people have been trying for over a decade without yielding any more evidence than you have put here, +RadioFreeAsia) is actually evidence to the contrary. More should have been uncovered if there was a real plot (especially considering how complex it would need to be).
The point of their private contact discovery is to leverage SGX enclaves so that you can verify what code is running on their server.
Sealed senders allow you to send a message without revealing to the server who you are.
The whole point of Signal is to build something that you don't have to trust. But of course you need to put some effort to understand it (and what it means, e.g. if you don't trust your OS running the client or if you don't trust the SGX enclave).
To the best of my knowledge, Signal's use of phone numbers does not meaningfully compromise the security or privacy of my conversations with my friends or family.
Tell me your threat model, and then I'll tell you whether "anonymity is security" or not. Anything else is just you talking past other people.
This is why Omertà–basically a vow of secrecy achieving anonymity as far as the police are concerned–is taken so seriously and why it has been such a big deal the few times it’s been broken. But Omertà isn’t the only tool employed–they use guns, safe houses, all kinds of other tools and methods to ensure their security.
Anonymity is security through obscurity, by definition.
This is my problem, not my messaging service's problem.
> Given Signal is meant to be used by people who don't know what OpSec is
???
I guess people could call this a growth hack, but without this kind of thing it's likely the number of signal users would be 10-100x smaller and the network effect would mean it's near useless for most.
Just imagine someone installing signal, not seeing anyone they can chat, and never using it again.
They should know only if I ask them to. I don't want to share this sort of information to everybody in my contact list by default. If I think somebody needs to know, I would tell them. If I don't think they need to know, then they shouldn't be told.
Anyway, the consequence of Signal being this way is that I refuse to install Signal at all, and don't recommend it to any of my friends or family. Instead I tell them that everything on phones is insecure and they should never believe or behave otherwise.
If you do not want someone to message you, why have you given them your number?
My assumption would be that if you trust someone enough to give them your number then it shouldn't matter if they know that there is another app that they can use to message you through. Of course this is only my assumption and I am just curious as to your reason why you would not want some particular person to know that they can message you through Signal rather than some other, less secure, app.
To be honest, it doesn't really bother bother me, but just because I communicate with someone does not mean that I want to share any information beyond the contents of my communications. We might both be Signal users, but you're not my friend. If you were, I would already know it.
Almost every communication app requires a phone number now. The claim is that this limits spam which is probably true but I suspect there is tremendous value in having real phone numbers and the ability to do pervasive tracking. We know mobile phone providers sell data on phones. The best that can be said about the Signal org is they are non profit but this is not very reassuring especially given the threat model of people who might be using Signal.
But that's not what's valuable. What's valuable is the social graph: who are your contacts, and who are you writing to. Signal works very hard to not know any of that. And it does it better than the alternatives I know.
But what about PII? Goes against your Signal argument.
Signal needs a phone number, not necessarily yours.
2) Usernames are pretty close. In fact, you can build the beta and use them now. [0] So your worries will be over soon. I really think you're exaggerating the simplicity of replacing the identifier in a way that is not personally identifiable. I mean my name here is only semi-anonymous but it would be a grave mistake to think one couldn't figure out who I am fairly easily.
3) What alternatives do you have? Yeah there are some that don't require this but also haven't had as extensive of audits, open sourced code, or the proof of time. Personally it does matter who analyzed protocols, safety measures, ciphers, etc because I can recognize that I'm not an expert in everything AND even if I was that dual verification is better than singular. With something as important as this, N-verification is important. IMO.
[0] https://community.signalusers.org/t/usernames-in-signal/9157...
In my eval, phone numbers are barely PII, starting with when ISPs and carriers started selling mobile data 2 decades ago.
So, my phone number is very much out there now. No issues using it for secure comms IMO.
If you want truly anon comms, I’m not using signal, but that’s not what signal does anyway.
The Signal app is a messaging platform built on this protocol by the same developers. That is what requires a phone number.
Anyone can build their own messenger using the Signal protocol and use whatever means of authentication they want.
I think there is also a useful distinction between "anonymity" and "privacy". The protocol is capable of facilitating both. The Signal app itself primarily focused on just the latter. Signal knows who you are, at least in so far as they know a hash of your phone number. You are not totally anonymous to them. But they do not know what you are saying. Your interactions on their platform are private.
I couldn’t agree more. In August this story was trending here using basic 101 growth hacking tactics https://news.ycombinator.com/item?id=28340542
Trace the source. The account got deleted from Reddit.
Whoa now ol' timer! j/k.
I like signal because it make switching people away from other platforms easier. It is not anonymous, but it is secure (until proven otherwise). I'll take the latter if I cannot have both.
That being said, they have room to improve. I dislike the work-around I have to do to use two separate phones and keep a single conversation going.
By disabling Signal’s access to phone contact address book, Signal server would not have a hash value of each and every (10,000+) phone numbers in your phone’s contact address book. This disabling comes with small costs of:
- being notified that someone in your phone’s contact address book has just recently signed up with Signal. (Pop your finger from your mouth)
- of ease of NEW lookups of a friend using your expansive 10,000+ contact address book that your phone maintains. Ummm, your focus is the secured messaging with just the targeted friends of yours, and not one of your crazed ex-girlfriend nor deranged boss.
You still have a separate but more secured form of a contact address book maintained by Signal (and yes, remote Signal server has a hash value of these smaller but limited set of Signal-capable phone numbers of your friends).
The key thing is no one else can see the content of your messaging … over Signal … except who you converse with … by Signal app, unless your phone ends up in the hand of a digital forensic guy before you did the steps of doing “Settings->Account->Delete Account”.
On a separate topic, you should refrain from using Avatar and discourage your friends from doing so. That’s an out-of-band lookup that is available for nation-state or hacker to profile further with.
Thankfully the one friend that was using Signal finally gave up on it since everybody else was always missing his messages, so I no longer have to re-link every single computer every time I use the app. (with a 30 day expiry and 3 computers, it meant virtually 100% of the time I tried to use the desktop app I had to relink to my phone).
If I keep the MacOS client open and active every few days, it doesn't have to relink. If I don't open it for a while, I'll have to relink.
This kinda response is common with Signal. It won’t even allow backups on iOS and refuses to handle scenarios where one may have a broken device or a lost device (the only way to retain chats and change devices is through a device-to-device transfer when they’re in close proximity; there is no iOS<->Android chat transfer either). Signal seems like it’s meant for chats that don’t have much value, where losing messages isn’t a big deal. But the app, at least on iOS, will never stop pestering you often if you don’t give it access to contacts. Something is broken between the vision for the platform and the implementation.
Carrying car keys (or a fob)
House keys.
Wallets.
IDs.
They all require some mental effort.
If anonymity was a factor, and not ease of use, they’d never only allow phone numbers as login.
(I can't remember the exact switches, but if I recall correctly I was notified I needed to switch from a Chrome app to a Snap, then to a Deb, and finally to a Flatpack.)
This conclusion — “no reason to…” — sounds strange and premature. Such attacks may not get older messages, but contacts of the person whose phone number has been used can still message the new device, which the hacker would get and could launch further attacks on the contacts. Since practically almost nobody verifies “safety number” changes, the contacts of the phone number that has been taken over may not realize they’re chatting with someone else. Isn’t that reason enough to be scared? This problem exists for any app that relies on an external identifier, especially one like a phone number that’s easier to take over (including through SIM jacking).
Signal may be secure for specific definitions, but your contacts may not be safe with such takeovers.
How do we know with certainty that the messages are not stored anywhere else? Don't they go through servers to get to the end user?
You just take their word for it. They could always phone home any kind of data using steganography!
I replied to Moxie’s opposition to decentralized open source software, with arguments like this.
Signal cannot do anything if your phone got compromised by Pegasus, but they never claimed they could.
That's exactly equivalent with decentralised software.
So from an information theoretic point of view, arguably no, the message was never stored anywhere else, even though Signal is indeed a store-and-retrieve arrangement. The encrypted message was stored briefly by Signal, but only its sender and intended recipient could decrypt it.
The keys are ephemeral, so if you have exactly bit-for-bit copies of encrypted Signal messages I sent when I was arranging to play Red Dead Redemption 2 with friends, nobody knows how to decrypt those. I can't decrypt them, the people who received them can't decrypt it, even though we saw them at the time, and even though you have the encrypted messages and even if you have our phones, the keys are gone so that's that.
Anything that goes over a network could be stored.
"user messages are stored only on their devices, not on Signal’s servers or anywhere else."
Whether or not a 3rd party, outside Signal's knowledge and/or control, is storing messages is entirely out of their control.
Suppose I promise you that qMsVOrgWDZTo0Fet9xLhIQ is the base 64 encoded, 16 byte encrypted message I just sent, but I used OTP. Do you in some sense "have" a copy of my message ? No. That is completely useless without the key, it could have literally been any message, without the key there's no difference.
And sure enough, even today the most practical attacks on DES are in effect brute force on those too-small keys and too-short blocks - this brute force is practical although very expensive.
Now, in 2001 DES was superseded by AES, which is used for this purpose by Signal. In AES the keys are larger (128, 192, or 256 bits, Signal uses 256) and the block size is longer too (128 bits), thus fixing the only problem DES still had. We are done.
So, while of course nobody can prove it won't happen in 30 years, it is extremely unlikely.
You might think to yourself, surely computers get faster and smaller, so the brute force problem would still arise maybe in a few decades? Nope. In the late 20th and early 21st century humans experienced something that's only going to happen once, and it has distorted our perspective on the matter. The machines are not, in fact, going to keep getting faster and smaller, there are physical limits imposed by the universe. They will get gradually a bit faster than they are now, and we will make a lot more of them, but nowhere close to enough even if (for some insane reason) our civilisation decided its only goal is to decrypt my old Signal messages.
[1] https://signal.org/bigbrother/central-california-grand-jury/
[2] https://signal.org/bigbrother/eastern-virginia-grand-jury/
If they have a special deal with government, the court wouldn't even know about those, or might be instructed not to ask them and not disclose anything.
E.g. could we build it ourselves in, say, Xcode, and compare a hash of the resulting app binary with the installed one?
Not sure about Signal.
The point is not just that everyone can make their own, but that anyone who is competent enough can prove that their client code is exactly what is used to produce the version that gets distributed.
This means that with Telegram it shouldn't be possible to hide a backdoor in the client in a way that is impossible to spot.
If it matters to you, you should build it from source.
If it's just out of curiosity... yeah reproducible builds are a thing, but generally that's not super straightforward in practice, I would say.
Now realistically, most people can do that, so they have to trust that somebody who can actually did it. Security experts have been and are looking into messengers like Signal: they have an interest to do so as security researchers, because that would look good on their CV.
Of course there is trust somewhere, you cannot do without trust. But Signal is amongst the best you can find.
See my other question. Audit how? Sure, you can examine the source.
But how can one tell the app blob in their phone is the same as the one produced if you build the code?
https://github.com/signalapp/Signal-Android/blob/main/reprod...
(I haven't tested this myself.)
Edit: You can also build the client yourself and use your own version. No need to use the Google Play store version.
The problem being that apps as installed from the App Store come (to my knowledge, could be wrong) encrypted. So you can't just compare an unencrypted local build with the encrypted installed app (and you can't decrypt the app or encrypt your build the same way, because you don't have the key, e.g. Apple has it - and iirc, there's no access to it, because it's held in the secure enclave in iOS case).
Very strange. There is no additional security by hashing phone numbers. Not that I trust anything form this source but anyway.
I was out of context. You can use salt, pepper or both but if these attacks are done buy Signal developers it would most likely be easy to crack the hashes. In the case of a data leak it can help depending on how difficult it is to figure out how the hashing works.
It's not just a hash, it's an SGX enclave.
Your contact list is only ever shared with the secure enclave, which cryptographically ensures that nobody else can read it, and the code being run in the enclave is open source and authenticated (so you can verify that the enclave is not sending your contact list to the Signal developers).
If you trust the secure enclave, then your contact list is not shared with the server.
Actually secure enclaves exist?!
That would avoid any such vector relating to SMS, albeit at the expense of making it more difficult to recover an account from a new device.
The great point about your contact list is that it is decentralised, and it exists already (so you don't have to exchange an ID with all your friends manually).
Solution? Store your contacts list on your device. Back it up with your offline chat backups (android does external chat backups now, IOS should be enabled plus give em icloud backups to boot).
with a new signal app on a new phone, you restore your chat backups and poof your contacts list gets loaded back. your new signal instance reconnects with the other clients and poof, Signal's excuse for using phone numbers and storing your contacts list on their servers is demolished.
It seems so simple to me, but I feel like I'm failing to understand something about why this is so hard.
Then your backup idea works, but kind of sucks in terms of UX (at least in Signal's point of view), and therefore they decided to go with phone number first, and work on going towards usernames later.
Don't worry, you haven't invented anything. It's just that your idea is not at the level of UX provided by WhatsApp/Signal, and the solution is more complex than you think.
See: https://github.com/signalapp/Signal-Desktop/issues/2383#issu... and in this paywalled article https://www.sueddeutsche.de/wirtschaft/signal-meredith-whitt... where they roughly say
>We are currently working with high priority on the fact that you can assign usernames and hide your mobile number. However, it will still be necessary in order to register. There are several reasons for this, including the fight against spam.
IIRC audio and video calls are E2EE as well (in addition, the four emoji that appear on a call allows both parties to check that no one is eavesdropping)
Look here is the most criticism that was given https://www.cryptofails.com/post/70546720222/telegrams-crypt...
Well most people don’t use Telegram. So maybe their stuff isnt encrypted either. So what? If you want to use it it’s available.
The problem is only when people fail to understand that the only private chats in Telegram are the ones that remove all the UX benefits, and instead believe that their "normal chats" and groups are private.
It's why you are able to just login to your Telegram account on another device and magically get all of your message history.
So while the tech might be solid, the keys are still out there. They can be leaked. They can be subpoenaed, etc.
The vulnerabilities that allowed such users and devices to steal keys have been fixed.
Secret chats are secure, and you cannot access them except on the device you start them with. It's one of the pain points for people that use them: they don't sync like normal chats.
Secret chats by default wouldn't make sense for telegram. It's not a secure messages app anymore... It's a social media platform with a secure chat feature.
If you want privacy, use Signal. If you want UX, use Telegram. Just don't pretend Telegram is private. Both are fine, but people need to know what they are doing.
That's an entirely different problem than TFA (an attacker accessing and being able to impersonate an account by subverting a third party 2FA middleman), which Telegram guards against as as soon as you have one device enrolled the code is sent over Telegram, not SMS.
> It's why you are able to just login to your Telegram account on another device and magically get all of your message history.
Being able to log in and get your history to sync is not a telltale sign that history is not encrypted and thus visible server side.
It could be stored encrypted and upon login decrypted locally (how to achieve that is left as an exercise to the reader, see 1password, restic, borg, and many others that store with zero trust yet are accessible by multiple devices, or even multiple parties)
(side note: claims that multi-device messaging can't be done because E2E are incorrect, e.g iMessage does it, by having each message encrypted multiple times, once for each device of the recipient account)
> So while the tech might be solid, the keys are still out there. They can be leaked. They can be subpoenaed
IIRC it was advertised that Telegram keys (presumably for data at rest) are stored split upon two (or more) different servers residing in different jurisdictions so that subpoenas would only get at most half of it or require international cooperation.
But then if you enter that ground, Telegram just as much as Signal could be court-pressured to produce a client that wiretaps data right where it's decrypted and phone home, so E2E only saves you if you audit every client version that this does not happen.
As always in matters of security, first step is to define your threat model, and who you want to secure against, as there's no such thing as perfect security.
> No analysis needed.
I would definitely like to see one done by an unbiased party, because everything I can find are blanket gut-feeling statements without reference.
EDIT: just found this, which is a bit light but still something: https://restoreprivacy.com/secure-encrypted-messaging-apps/t... and this: https://arxiv.org/pdf/2012.03141v1.pdf
Having secret chats is mostly for marketing, to pretend it's private. But it's mostly confusing.
Following scenario:
1) X communicates with Y using Signal trying to hide from Iranian police
2) Y is getting arrested and who ever is found to have his phone number is getting in to trouble as well
3) X deletes Y from its contacts
4) Y stays in X's contacts on Signal no matter what
now what should X do? delete Signal? theoretically the police could reinstall it and see who you had in your contacts.
There have been several issues opened for this problem on GitHub for years. They all get closed by their bot after couple of weeks.
I have several ghost numbers and even ghost user names on my Signal clients. Super annoying and cluttering my list of contacts. For me Signal is just one option to avoid WhatsApp. But boy do I prefer Telegram ...
So you want to register a new device with your Signal account and you don't have the previous device, either because you're a malicious attacker or you lost or destroyed it. Covering the attacker case, presumably you already can't access the message history. I don't see how you could reasonably do anything different for the lost device case, but I guess it's not that big a deal to lose message history. But if the message history is already gone either way, why not make it a entirely new and separate account?
Telegram, on the other hand, is mostly not e2e encrypted, so their cloud can read all of your messages.
Pick your favourite.
and if Signal did not require a phone number, this wouldn't have happened at all
Lets assume that today that Signal is able to deliver messages securely between users, without maintaining a plaintext association between sender and receiver's phone numbers.
Why would switching identifiers from phone numbers to some other identifier require that they change how that works? (Other than the obvious 'substitute out a phone number for some other identifier' thing)
I perhaps should have clarified but I was talking about group messaging without phone numbers attached
Also worth mentioning that Matrix isn't just working on encrypting contacts databases. They are also working on decentralization, which is a much more difficult problem. So I'm not surprised that they are running into issues every once and a while (though Signal has had security problems in the past too [1])
[1]: https://thehackerblog.com/i-too-like-to-live-dangerously-acc...
This is secure messaging. It has to work, or it's just LARPing. Can the Matrix team honestly say that their system is ready to handle life-or-death secrets?
> By default, Registration Lock is disabled, as was the case for at least one of the hacked accounts. As such, the cybercriminals managed to pull off the attack by impersonating the victim of the attack for roughly 13 hours
Do they complain with their mobile company about getting a "broken number" or with Signal?
The edge case would be someone that continued to use signal with their old phone number, effectively blocking its new registration.
It’s basically a dumb idea to use the account while someone else owns the number, eventually you’ll lose access to it
I’d change “require” to “allow”.
If, for example, Signal operated like it did now, but optionally let you sign up without a phone number, with a warning to users that not using a phone number would result in not being able to receive messages to their phone number, I bet most users would still use a phone number.
Phones themselves are as secure as know vulnerabilities of whatever version of the phone hardware and OS version.
The phone number requirement should be removed if Signal wants to be taken seriously. Maybe the next hit might affect more users than 1900 people.
Using PII which is also a joke, “secure” implies “private” also, else it is just “encrypted”. When someone knocks on your door in a Ukrainian or African or … village and asks for the pass, you give it.
The non private money sending also a joke of privacy. A monero-like solution would be good enough.
Less features than whatsup or viber or telegram so why bother? It is really easy to copy each others’ features, but each app’s developers think that they are the smartest people in the room.