4 ms·
You do not control a phone number. You can control an SSL cert using DNSSEC. So you cannot control your signal end-point. Besides, the signal server is in total
by HIPisTheAnswer 8y ago
You do not control a phone number.
You can control an SSL cert using DNSSEC.
So you cannot control your signal end-point. Besides, the signal server is in total control of your identity. Plus anyone might still use the phone number to send plain-text SMS'.
TLDR: If you don't control the server, there is no security guarantee. So signal, whatsapp and telegram are out.
- dbt00 8y agoDNSSEC is as secure as SMS.
- HIPisTheAnswer 8y agoBut signal also uses name servers to connect clients. HIP, the host identity protocol, is the answer. Check out my nick. I'm not a big fan of the current naming system of the internet. Self-certifying names are needed. Edit: If DNSSEC is as secure as sms, then signal is as secure as sms.
- acct1771 8y agoYou mean for metadata, of course. Not message contents etc.
- snthd 8y agoFor signal the phone number serves as a convenience to label a public key - the security comes from verifying the key. The design is to not trust the server. WhatsApp is the same but has things like key-change messages off by default. I believe telegram doesn't even encrypt by default, and has flawed crypto anyway. You're right that the whole thing is flawed to some degree unless both parties are clued up.