5 ms·
What prevents anyone from doing the same with Signal or any messaging service that allows one to build a client? This program isn’t pretending to be a bot on Te
by wtmt 7y ago
What prevents anyone from doing the same with Signal or any messaging service that allows one to build a client? This program isn’t pretending to be a bot on Telegram, and it works as a normal user in every way (including the requirement for a working phone number, even if it’s a burner number).
- kaens 7y agonothing aside from things that require actual human interaction, so basically nothing.
- telegrammember 7y agohttps://www.channel-member.com/ https://www.channel-member.com/
- m12k 7y agoWell, Signal comes with a system for verifying a person's identity, so you can be sure it's really someone you know and not an imposter. But sure, for semi-public channels that will let anyone in without verification, something like this would allow you to monitor it. Lesson: If you're using Signal to run a dissident network and organize protests, be sure to verify everyone before adding them to groups.
- kome 7y ago> Well, Signal comes with a system for verifying a person's identity like what? I really have no idea.
- m12k 7y agoThere's an article about how it works in their help section: https://support.signal.org/hc/en-us/articles/360007060632-What-is-a-safety-number-and-why-do-I-see-that-it-changed- https://support.signal.org/hc/en-us/articles/360007060632-Wh...
- AmericanChopper 7y agoThis doesn’t verify an identity, it verifies that somebody has access to a key that at some point in the past, you chose to trust. Signal has no mechanism at all for verifying identity, verifying the authenticity of the safety number is entirely up to you.
- ganstyles 7y agoMaybe I'm missing the point, and if so please correct me, but when I add new people to signal we do so in person and there's a QR code where one can "verify" the person. It obviously links the verified user with their phone, so theoretically someone could steal their phone and pretend to be them I guess. But it is making them a "verified" user, it's just up to me to verify.
- AmericanChopper 7y agoThe safety number is essentially equivalent to a self-signed certificate. You can use it to consistently identify a key holder, but it doesn’t offer you any way to identify who that key holder is. If you want to trust a self-signed cert, then figuring up whether you should or not is entirely up to you. This is the problem that CAs address with CA signed X.509 certificates. If you want to validate identity as a service, then the only options you really have available are a central authority, or a web of trust. Both of which have serious downsides, and neither of which are offered by Signal.
- iudqnolq 7y agoThat's a generally correct statement, but the comment you replied to mentioned a specific case for which it's false. If you can reduce the trust problem by requiring every person to verify out-of-band the identity of every one of their contacts, it becomes a lot simpler. For some Signal users, such as the person you replied to, this appear to be the case.
- AmericanChopper 7y ago
- leppr 7y agoYou can't ever assume that clients aren't logging everything that goes through them, even if there's no official documentation/API for custom clients. If a human can read a message, for all intent and purpose assume that a machine can too. For instance, things like Snapchat self destructing messages rely more on social norm than technology.
- batushka3 7y agoSnapchat messages do not self destruct. They are just hidden. Multiple times during some glitch I saw old messages from weeks ago.
- deleted 7y ago[deleted]
- riter 7y agoThis is effectively true, baseline it is indistinguishable from a "real" person, questioning the security model of openness and potential for mass social engineering. There is a reason why the hurdle of overcoming scaling the creation of a "real" phone number is difficult.