This just provides an additional layer of protection, allowing you to chat with people without revealing what is increasingly linked to your actual identity in some countries.
To mitigate spam.
They explicitly mention, next, that this is not for US users. From what you, and they, say, Signal is not good if your threat includes the US government. It is good cover agaisnt India, Taiwan, Mexico. Probably not agaisnt UK or Israel, eg.
Signal is useless against anyone willing to do a deal with Cellebrite/NSO group and the like. Which is pretty much everyone, especially the countries you mentioned.
The solution you're forced to use if you can't get genuinely secure equipment is of course to not use electronic communications. Genuinely sensitive meetings should be held outside, with no electronic equipment brought and at an unexpected place and time.
In a perfect world? Yeah sure. But in the real world that's simply untenable. Every major browser has critical CVEs every few months. Clearly they're not "100% secure against hacking". Are you suggesting that we "can't really use [them] for business"?
>Genuinely sensitive meetings should be held outside, with no electronic equipment brought and at an unexpected place and time.
The physical world is anything but secure, especially when you're up against the local security services with tens of thousands of agents. Parabolic microphones exist. Bugs can be installed. "unexpected place and time" might make those hard/expensive to pull off, but it doesn't make it "100% secure". Moreover, how are you supposed to coordinate all of this cloak and dagger stuff without electronic communications?
You just go off into the woods randomly during lunch, or some other time that is unlikely to be anticipated.
Coordinating it would just destroy the security.
Also, isn't it better to be overheard by somebody with a parabolic microphone than to have everything collated and stuffed into an LLM without anybody having to do anything?
That might work if you're planning to start an "insurrection with the boys", but how are you going to "go off into the woods randomly during lunch" if you're a journalist working with an anonymous tipper?
But yes, it's not an approach that can help journalists at all.
Signal is 0% secure because it is the main target of their attacks.
1. This is a non-sequitur. Just because they're trying hard to break it, doesn't necessarily mean it's broken right now. Moreover, even if we grant that they have 0days stockpiled, it doesn't necessarily mean they're going to burn those on any target.
2. What are you going to use instead of signal? Some off-brand messenger that's not "the main target of their attacks" but is also less well scrutinized? I'd rather not engage in security by obscurity.
The cryptography is such that even nation states almost certainly can't crack it either. But then, if you were a specific target, they would just compromise your phone, not attack the crypto.
To what extent it is used against particular targets I'm sure is quite secret.