> Again: the overwhelming threat model is here is "two individuals that already know each other want to communicate privately." That's what Signal facilitates, and it does so pretty well given the purity compromises that need to happen to do that for non-technical users. They're not worried about leaking phone numbers, because they're already shared.
Well there is no justification for that threat model beyond "our leader said so". Especially when they expressly fight state level censorship and interference but something as simple as someone shoulder surfing you defeats it. Threat models are for security professionals not regular people. Regular people don't model threat or assess securitu risk properly. They don't know encryption is useless if you don't authenticate. And signal's refusal to be independntly usable outside of smartphones given how much law enforcement and spies love to abuse mobile phone infrastructure leaves me to be very suspicious of their intent. Making phone numbers opt-out just makes you less discoverable at best. They have 50 million dollars and various projects no one asked for yet this is too difficult and complex? You still have't given me a reason to accept that beyond "trust me, i know".
> Finally: there's a good chance you being downvoted here because (1) these comments are indistinguishable from FUD, and (2) you're making claims (and now talking about examples) without citing them.
Disagreeing with you is FUD? What claims did i make that need citing? Please challenge me then?
For anyone who reada this thread, do you really want to use Signal given the hostility a person would get for questioning their terribly questionable choices?
> know that the FBI can only retrieve minimal metadata from Signal[1], and various foreign intelligence services have more luck deploying malware to phones[2] than they do actually breaking anything about Signal's design. Nation state adversaries don't have trouble finding peoples' phone numbers.
Do you freaking realize that you are making my point for me here? The problem is being able to connect signal messages with phone numbers. Of course they know everyone's phone numbers! But reporter A talking to source B is all they need to know because they can get access to either's phones! There are very few cases where a real life adversary cannot at some point access one party's phone over time.
If the only protection is against man in the middle attacks then signal is by far the weakest app in that category because wire, briar,etc.. i can just use them on any device.
I had advocated for signal for many years and have gotten burned by it more than any other messaging app. The worst security tools are the ones that lead you to trust them more than you should, the more cultishly supportive their supporters are the more wary of them you should be.
For the target audience of signal, imessage on an iphone is a better choice. For the real users of signals that need higher security wire and briar are better. Signal compromises on too much and then claims too much security guarantees.