3 ms·
As far as I understand Signal can't just save all the data because of how the app/server are architected: They use sealed sender: https://signal.org/blog/seale
by ylk 5y ago
As far as I understand Signal can't just save all the data because of how the app/server are architected:
They use sealed sender: https://signal.org/blog/sealed-sender/ https://signal.org/blog/sealed-sender/
Private contact discovery: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/
And a "Private Group System" which is supposed to keep group membership information from the server: https://signal.org/blog/signal-private-group-system/ https://signal.org/blog/signal-private-group-system/
Though of course they could still push malicious updates.
- upofadown 5y agoSealed sender only means Signal doesn't know who sent a particular message. They have to know who the recipient is so they can deliver it. Like forging the "From:" address on an email. Except in the Signal case the IP address/port of the sender is unique to the user and if the recipient responds then the link between the users is made. The private contact discovery depends on an Intel SGX hardware enclave on their server. Which is good in this case as it implies more work to bypass it but where is the ultimate trust here? Intel? Did Signal ever get this working? In general Signal can just see what IP address/port picks up a particular user's pre-keys if they want to know who is talking to who.
- ylk 5y agoYou said > The E2EE in Signal only protects the actual content of messages. > [By] (simply saving the data) Signal could get access to things like contacts and phone numbers. And the linked blog posts show that for a few years now they've been working on limiting their own access to this kind of data --- i.e. it's not as simple as just saving it (like e.g. WhatsApp is able to and most likely doing 100% of the time to build social graphs). Now of course all of those things are likely vulnerable to some attacks, but that's another discussion and it doesn't change the fact that Signal doesn't have immediate easy access in the way you claimed in your original comment. The fact is that there are some barriers and they'd have to put some effort into either disabling these protections or exploit flaws in them to get to the data.
- upofadown 5y ago>...it doesn't change the fact that Signal doesn't have immediate easy access in the way you claimed in your original comment. I did not at all mean to imply that. The assertive action that Signal would have to take might involve actual work. The question is if they could be forced to do that work by the authorities of the country they operate from. I doubt that the amount of work would really factor into the legal stuff. Signal of course might of already done the work as part of some cooperation with a national signals organization or simply because someone felt bored and contrary, but they could not admit that if they want to preserve the value of the information gathered. The E2EE encryption part is in the end the only provable aspect of Signal Messenger. The leakage of meta information is inherent when one entity controls all the infrastructure.