3 ms·
You said > The E2EE in Signal only protects the actual content of messages. > [By] (simply saving the data) Signal could get access to things like contacts an
by ylk 5y ago
You said
> The E2EE in Signal only protects the actual content of messages.
> [By] (simply saving the data) Signal could get access to things like contacts and phone numbers.
And the linked blog posts show that for a few years now they've been working on limiting their own access to this kind of data --- i.e. it's not as simple as just saving it (like e.g. WhatsApp is able to and most likely doing 100% of the time to build social graphs).
Now of course all of those things are likely vulnerable to some attacks, but that's another discussion and it doesn't change the fact that Signal doesn't have immediate easy access in the way you claimed in your original comment. The fact is that there are some barriers and they'd have to put some effort into either disabling these protections or exploit flaws in them to get to the data.
- upofadown 5y ago>...it doesn't change the fact that Signal doesn't have immediate easy access in the way you claimed in your original comment. I did not at all mean to imply that. The assertive action that Signal would have to take might involve actual work. The question is if they could be forced to do that work by the authorities of the country they operate from. I doubt that the amount of work would really factor into the legal stuff. Signal of course might of already done the work as part of some cooperation with a national signals organization or simply because someone felt bored and contrary, but they could not admit that if they want to preserve the value of the information gathered. The E2EE encryption part is in the end the only provable aspect of Signal Messenger. The leakage of meta information is inherent when one entity controls all the infrastructure.