4 ms·
My understanding is that this component was added to their server code. If their clients are still verifyiably encrypting the content and limiting the metadata
by approxim8ion 5y ago
My understanding is that this component was added to their server code. If their clients are still verifyiably encrypting the content and limiting the metadata for your messages, it should not be much of an issue.
- robryk 5y agoEvery time you send a message with Signal, you inform the server which user the message is for. Thus, the server can remember (sending IP, target phone number) pairs and, for similar reasons, (phone number, IP of the user when retrieving messages) pairs. We rely on the server to discard this information; if not discarded, it reveals the social graph and the phone number<->IPs used mapping.
- sam_lowry_ 5y agoAnd since Snowden we know that meta-information is as important as information. So Signal being E2E encrypted goes only halfway towards ensuring the privacy of our communications.
- approxim8ion 5y agoI'm aware of this, but it's not like it's a new concern with this piece of code. This has always been the case.
- BelenusMordred 5y agoDon't really understand the cries for their server code to be constantly updated or even open sourced, you can't ever verify that's what they are running anyway. Maybe there's some sort of cryptographic attestation out there which could fulfil such purposes but quite sure it's not that practical.
- robryk 5y agoThat's true and it's one reason I'm not too comfortable with Signal's access to metadata (even though they are the best nonfederated communicator in that regard). There are a few reasons why I would prefer them to provide source code that they claim is running in the service due to the metadata issue: a) if it's actually running there, people can find simple bugs in it that could allow that metadata to be stored or revealed by accident, b) if it's not actually running there, but something very close is (i.e. that code with small amount of patches), then the advantage above still applies and if those patches come to light, they can be easily evaluated for intent and effect, c) if they're running something completely different (which would be very weird), it'd be noticeable and it would be an obvious lie once exposed.