Sidenote: Signal is based in the USA. They do not have the benefit of the doubt.
Sidenote: Signal is based in the USA. They do not have the benefit of the doubt.
Unless it is the end-device being "accessed"/compromised, which any nation-state can do.
Also "which any nation-state can do" is an interesting angle.
Let me put that differently: why would Signal NOT be a honey-pot operated by the CIA/NSA/other? Sounds almost too easy to not be true.
It says so on their website:
"Only client devices store user profiles, contacts and groups; the messages are sent with 2-layer End-to-end encryption."
What it does NOT say is that message content remains encrypted on their server like Signal does.
It is like time, money, resource: pick only two. But in secured communication, that would be personal anonymity, personal privacy, and personal security: only can pick two.
The privacy policy is very explicit about it.