5 ms·
> doesn't store data, not even metadata Isn't that just a promise? Also, even then, it is based on your contacts, which are seen by google.
by dependenttypes 7y ago
> doesn't store data, not even metadata
Isn't that just a promise? Also, even then, it is based on your contacts, which are seen by google.
- literallycancer 7y agoYou can use some of the gapps alternatives. Google only sees contacts if you sync them through your Google account or use Google contact book app, right?
- Forbo 7y agoIt's a promise that got taken to court and survived. https://signal.org/bigbrother/eastern-virginia-grand-jury/ https://signal.org/bigbrother/eastern-virginia-grand-jury/ You can use a different contacts app, you don't have to give all your information to Google. My contacts are managed by a Nextcloud instance.
- dependenttypes 7y ago> You can use a different contacts app, you don't have to give all your information to Google As far as I know OWS does not mention this anywhere on their site nor on their program -- aren't the issues with usability of other programs and lack of sane defaults (such as with gpg) often given as an argument by signal supporters on why you should prefer it? That being said, is that even possible? I admit that I am not too familiar with how Android phones work. Signal requires the google play services in order to work, right? Is this not enough for google to see your information?
- Forbo 7y agoGoogle Play Services and your contacts are completely different things. I'm confused on what information you think is being sent. As far as I'm aware, all FCM does is provide a push that tells the app to check in with Signal's server. No contact information is in play. Signal also released a WebRTC version that doesn't depend on Google Play Services if that floats your boat.
- tialaramex 7y agoSignal's source code is published so you can go look for yourself. If you believe that despite precautions the source code won't match what actually runs on your phone then realistically you've no real option to use any technological artefact and will be obliged to resort to maybe whispering coded messages to close confidants. As a large technocracy this is not a practical option for the EU. Your phone number is sent to Signal's servers during sign-up and it uses the conventional SMS service to "close the loop" and prove this number is under your control. Having signed up you can use a PIN to lock the number to you so that anyone without that PIN can't do the "new phone" dance (this expires if you stop answering PIN questions correctly) If you choose to do so a digest of your contact's phone numbers can be sent to Signal for them to match against the set of (also digested) numbers of Signal users so they can tell you who has Signal enabled. Whether you choose to give your contacts to Google, to Facebook, to Apple or whoever is up to you and outside Signal's control. Signal does let you create an encrypted profile, and then your device can tell other people's devices the keys to look at the profile if you want to allow that. You don't have to use a profile or trust anybody else if you don't want to. Signal doesn't learn the keys (unless I guess you deliberately sent them those keys) so they can't read the profile. Unlike many of its competitors Signal's messages can't be read by Signal, in most cases this includes who sent them (Signal's "Sealed Sender" means in most cases if you correspond with someone the indication of who sent them a message will be encrypted such that they can tell you sent it but Signal only knows it was someone they authorised to send them messages). When you attach images Signal avoids learning how large the images are exactly, and if you use a service like GIPHY to add typical meme images like Stephen Colbert eating popcorn Signal double-proxies this so that they don't learn which GIF you used, and GIPHY doesn't learn who used it. Edit: Fixed name of GIPHY. Huh.
- dependenttypes 7y ago> so you can go look for yourself I can look it out for myself but there won't be any point as they can simply run different code on their servers. > If you believe that despite precautions the source code won't match what actually runs on your phone On their servers Also what precautions? As far as I know their binaries are not reproducible. > this expires if you stop answering PIN questions correctly After a week if I remember correctly. > a digest of your contact's phone numbers > also digested A hash? This does not protect against anything. There are much less than 2^32 active mobile phone numbers per country. It would be trivial to brute-force it. > Whether you choose to give your contacts to Google, to Facebook, to Apple or whoever is up to you and outside Signal's control. The point is that someone* other than you will be able to see the metadata. It does not matter if it is Signal or not.
- iudqnolq 7y agoYou can see it from their court filings. I think it's an amazing technical accomplishment that the only information they have stored in the clear under a user's phone number is the last connection date and account creation date. https://www.aclu.org/open-whisper-systems-subpoena-documents https://www.aclu.org/open-whisper-systems-subpoena-documents You can also disable contact backup on Android.