One phone gets compromised and the whole network is identified with their phone numbers.
One phone gets compromised and the whole network is identified with their phone numbers.
You still need to use your phone number to sign up, though.
Which defeats the whole point. What if the FBI politely asks Signal about a phone number?
So the FBI cant ask what phone number is tied to an account, but if a specific phone number was tied to the specific account? (As in, Signal gets the number, runs it through their hash algorythm and compares that hash to the saved one)
But my memory is very very bad, so like i said, i might be wrong
Regarding hashing: while unsalted phone number hashes would be easy to reverse then I doubt that any hashing scheme today is set up like that.
Not only does one have to worry about other Signal users being compromised, one also has to worry about a third party being compromised: the Signal Messaaging LLC
[1] https://en.wikipedia.org/wiki/Communications_Assistance_for_...
Once you get into the national security side, the secrecy is even higher.
Whitfield Diffie and Susan Landau, Privacy on the Line: The Politics of Wiretapping and Encryption (MIT Press: Cambridge, 2007), 372
Italics are mine
Not using phone numbers in chat app doesn't protect you against someone locating you.
When phone is turned on, even without SIM, your location is saved, in inches. Thanks to 5G.
And some phone turns itself on automatically, lol.
Using laptop (without any wifi card) -> Wifi card (rotating fake MAC) -> wifi network/LTE modem with IMEI spoofing
Signal is a desktop app, as well. Even if you wanted to run it on Qubes in a Faraday cage, you'll need a phone number to register to use the app.
In the ideal situation, no one would be using Signal, phones or computers, the design of the internet is inherently identifying and non-anonymizing.
Also, if someone's phone is confiscated, and you're in their Signal chats and their address book, it doesn't matter if you're hiding your number on Signal.
It's better to just not require such identifying information at all.
If you don't want to link your contacts... don't link your contacts...
But this doesn't have the result that the GP claimed. The whole network doesn't unravel because in big groups like these one number doesn't have all the other contacts in their system.
For people that need it:
| Settings
|- Chat
| |- Share Contacts with iOS/Android <--- (Turn off)
|- Privacy
| |- Phone Number
| | |- Who Can See My Number
| | | |- Everybody
| | | |- Nobody <----
| | |- Who Can Find Me By Number
| | | |- Everybody
| | | |- Nobody <----
| |- App Security
| | |- Hide Screen in App Switcher <---- Turn on
| | |- Screen Lock <---- Turn on
| |- Advanced
| | |- Always Relay Calls <-----
If you are extra concerned, turn on disappearing messages. This is highly suggested for any group chats like the ones being discussed. You should also disable read receipts and typing indicators.Some of these settings are already set btw
If we go full tinfoil, then do you really trust Apple and Google to keep your Signal keys on your device safe from the US government?
It's probably not that bad, but I do know that we're having some serious discussions on Signal here in Europe because it's not necessarily the secure platform we used to think it was. Then again, our main issue is probably that we don't have a secure phone platform with a way to securely certify applications (speaking from a national safety, not personal privacy point of view).
I do agree with that when you can't hide from the company, you can't hide from the US government either.
Regarding attacks, even if your current app is e2ee then this could be subverted by simply updating it to a newer version that isn't. Yet another is that when somebody gets full control over your phone, then no system will protect you as the device is functioning as intended (showing you the messages), it just doesn't know that it's no longer the owner of the phone reading them.
> Signal's messages are encrypted at rest though? Because Android and iOS are both full disk encrypted.
So just a point for people to be aware of, and that this isn't unique to Signal. Android and iOS can read your Signal messages under 1 of 2 conditions: 1) Toast notifications include messages
2) Keyboard
The first one is obvious as the OS has to see the message. So someone *with access to your phone* (already compromised) might be able to read messages (or at least partial) through this mechanism. Signal allows you to turn this off and if you're concerned, you should do so.The second is less obvious and unfortunately with iOS I don't think there's a solution. Under Android, by default, Signal uses the incognito keyboard. Android promises not to use typing patterns for its learning but like Apple you ultimately have to trust them. But unlike Apple you can install 3rd party keyboards from Fdroid which are entirely local (some even have learning capabilities and plenty have local STT).
But again, neither of these are actual issues with Signal or any other E2EE app. The problem is the smartphone.
> I do agree with that when you can't hide from the company, you can't hide from the US government either.
Nitpick:I don't think you can hide from targeted government surveillance. Or at least you have to go to some serious lengths to. But I do strongly believe that apps like Signal help you avoid dragnet operations and mass government surveillance. We should differentiate these types of things. I'm no doing anything nefarious so I'm not concerned with the former targeted surveillance (though I still dislike it in principle), but mass government surveillance is, in my view, a violation of my constitutional rights and everyone should take steps to fight against it.
Truth is, most mass surveillance can be avoided fairly easily: use an E2EE communication app like Signal (cross platform) or iMessage (security only with your Apple friends), install an ad blocker, set "do not track" in your browser, get a cookie destroyer (or use incognito/private), and disable tracking in each and every app (annoying...). This isn't a perfect defense from mass surveillance but it sure does get rid of like 80+% of it and that's a really good step in the right direction. There's no such thing as perfect privacy or perfect security, there's only speedbumps and walls. The intention is to make it hard and costly.
I nitpick because people do not differentiate these two and become apathetic. Acting as if it is pointless to make these changes. But mass surveillance (and surveillance capitalism) is where the disinformation campaigns and manipulation comes from. Unless you're some elite criminal then framing the conversation as "you can't hide from the government" is naive. Besides, I'm not trying to hide from the government. I have nothing to hide. But the checks and balances are that they have to have a reason to look. Get a warrant or GTFO. That's what making these types of changes is the equivalent of.
Thank you for the nitpick, AI, but this is hn so don't write as if this was fb. :)
> When the phone is taken from you, you'll not be typing them in anyway.
Your phone can be compromised without it being taken from you. You're smart enough to be able to figure that out :)source:
https://soatok.blog/2025/01/14/dont-use-session-signal-fork/
hn discussion:
Tox (if you're addicted to phones): https://tox.chat/
Set up your own XMPP or Matrix server and only expose it via Tor.
Oh wait, we did.