4 ms·
>Is it documented Yes, it’s documented: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/ >(and provable)
by anjbe 6y ago
>Is it documented
Yes, it’s documented: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/
>(and provable)
As the post says, their non‐SGX method requires you to trust the server: “This has meant that if you trust the Signal service to be running the published server source code, then the Signal service has no durable knowledge of a user’s social graph if it is hacked or subpoenaed.”
To eliminate that requirement, they developed an SGX‐based method: “Since the enclave attests to the software that’s running remotely, and since the remote server and OS have no visibility into the enclave, the service learns nothing about the contents of the client request. It’s almost as if the client is executing the query locally on the client device.”
Of course, there are plenty of attacks on SGX (I’m not enough of a cryptographer to know how practical they are to apply to Signal’s methods or not); but at some level you are going to have to trust servers you don’t control, whether your system is federated or centralized. I’m mostly willing to give Moxie the benefit of the doubt here.