4 ms·
Author here. The server doesn't know who is in the call. It can't build any graph.
by pthatcherg 5y ago
Author here.
The server doesn't know who is in the call. It can't build any graph.
- codethief 5y agoHow does this work? I mean, I suppose the server must at least know the IP addresses of the participants?
- pthatcherg 5y agoYes, it knows the IP addresses of the clients. The other thing it knows is that you have provided a proof that you are a member of a the group conversation associated with the group call (basically a proof that you are allowed to join the call). And that proof is based on Signal's "zkgroup" system. That's it. Once the server has the proof, it forwards packets for you. And it doesn't learning about you from then proof (other than what the proof proves: that you can join).
- godelski 5y agoBut isn't knowing the IP a decently good identifier? I know signal is trying to be as trustless as possible, but since IPs don't change often can't this be used to deanonymize people relatively easily? I mean supposing the server became hostile/hijacked?
- codethief 5y agoThis was already the case before group video calls and, yes, IPs can be used as identifiers. I don't think this can be prevented on a technical level[0] – you will always need to trust the server here. Signal does have a good track record, though: https://signal.org/bigbrother/ https://signal.org/bigbrother/ [0]: Unless you do p2p routing of video calls – with the known downsides regarding traffic, performance and NAT. But even then you would probably still need a server as rendez-vous point.
- up6w6 5y agoI'm interested in a explanation for that too. Signal recently introduced the same sender key method for groups [1] and, correct me if I'm wrong, this is first formal mention of the "Selective Forwarding" method we have. I get that Signal's open-source implementation doesn't store this type of metadata, but is very misleading to see the founder of Signal tweeting that "doesn't have access to the data" [2] while it's not that much better than Whatsapp in the technical side. [1] https://community.signalusers.org/t/sender-key-feature/33599/6 https://community.signalusers.org/t/sender-key-feature/33599... [2] https://twitter.com/moxie/status/1457005910136549379 https://twitter.com/moxie/status/1457005910136549379
- walrus01 5y agoDPI of the network traffic at the ISPs upstream of the server side (Whether ordered by US national security letter or other) would collect some very interesting data on ASN/IP traffic origins and time of day usage patterns, however. Or even something much less than DPI and just high sampling rate netflow.