How do we know with certainty that the messages are not stored anywhere else? Don't they go through servers to get to the end user?
How do we know with certainty that the messages are not stored anywhere else? Don't they go through servers to get to the end user?
[1] https://signal.org/bigbrother/central-california-grand-jury/
[2] https://signal.org/bigbrother/eastern-virginia-grand-jury/
If they have a special deal with government, the court wouldn't even know about those, or might be instructed not to ask them and not disclose anything.
E.g. could we build it ourselves in, say, Xcode, and compare a hash of the resulting app binary with the installed one?
Not sure about Signal.
The point is not just that everyone can make their own, but that anyone who is competent enough can prove that their client code is exactly what is used to produce the version that gets distributed.
This means that with Telegram it shouldn't be possible to hide a backdoor in the client in a way that is impossible to spot.
If it matters to you, you should build it from source.
If it's just out of curiosity... yeah reproducible builds are a thing, but generally that's not super straightforward in practice, I would say.
Now realistically, most people can do that, so they have to trust that somebody who can actually did it. Security experts have been and are looking into messengers like Signal: they have an interest to do so as security researchers, because that would look good on their CV.
Of course there is trust somewhere, you cannot do without trust. But Signal is amongst the best you can find.
See my other question. Audit how? Sure, you can examine the source.
But how can one tell the app blob in their phone is the same as the one produced if you build the code?
https://github.com/signalapp/Signal-Android/blob/main/reprod...
(I haven't tested this myself.)
Edit: You can also build the client yourself and use your own version. No need to use the Google Play store version.
The problem being that apps as installed from the App Store come (to my knowledge, could be wrong) encrypted. So you can't just compare an unencrypted local build with the encrypted installed app (and you can't decrypt the app or encrypt your build the same way, because you don't have the key, e.g. Apple has it - and iirc, there's no access to it, because it's held in the secure enclave in iOS case).
So from an information theoretic point of view, arguably no, the message was never stored anywhere else, even though Signal is indeed a store-and-retrieve arrangement. The encrypted message was stored briefly by Signal, but only its sender and intended recipient could decrypt it.
The keys are ephemeral, so if you have exactly bit-for-bit copies of encrypted Signal messages I sent when I was arranging to play Red Dead Redemption 2 with friends, nobody knows how to decrypt those. I can't decrypt them, the people who received them can't decrypt it, even though we saw them at the time, and even though you have the encrypted messages and even if you have our phones, the keys are gone so that's that.
Anything that goes over a network could be stored.
"user messages are stored only on their devices, not on Signal’s servers or anywhere else."
Whether or not a 3rd party, outside Signal's knowledge and/or control, is storing messages is entirely out of their control.
Suppose I promise you that qMsVOrgWDZTo0Fet9xLhIQ is the base 64 encoded, 16 byte encrypted message I just sent, but I used OTP. Do you in some sense "have" a copy of my message ? No. That is completely useless without the key, it could have literally been any message, without the key there's no difference.
And sure enough, even today the most practical attacks on DES are in effect brute force on those too-small keys and too-short blocks - this brute force is practical although very expensive.
Now, in 2001 DES was superseded by AES, which is used for this purpose by Signal. In AES the keys are larger (128, 192, or 256 bits, Signal uses 256) and the block size is longer too (128 bits), thus fixing the only problem DES still had. We are done.
So, while of course nobody can prove it won't happen in 30 years, it is extremely unlikely.
You might think to yourself, surely computers get faster and smaller, so the brute force problem would still arise maybe in a few decades? Nope. In the late 20th and early 21st century humans experienced something that's only going to happen once, and it has distorted our perspective on the matter. The machines are not, in fact, going to keep getting faster and smaller, there are physical limits imposed by the universe. They will get gradually a bit faster than they are now, and we will make a lot more of them, but nowhere close to enough even if (for some insane reason) our civilisation decided its only goal is to decrypt my old Signal messages.
You just take their word for it. They could always phone home any kind of data using steganography!
I replied to Moxie’s opposition to decentralized open source software, with arguments like this.
Signal cannot do anything if your phone got compromised by Pegasus, but they never claimed they could.
That's exactly equivalent with decentralised software.