5 ms·
I love Signal and use it as my only messenger, but there's no guarantee the server side code is as secure as they say. For a private citizen like myself it cer
by acoard 5y ago
I love Signal and use it as my only messenger, but there's no guarantee the server side code is as secure as they say. For a private citizen like myself it certainly looks secure enough (eg in their warrant responses), but I wouldn't want a state to bet it's security on Signal's honesty.
- jeffrallen 5y agoThe promise of end to end encryption is that even if the server side put what it sees of your messages on a billboard in Times Square, nothing bad would happen.
- gaius_baltar 5y agoI suspect their objections come from traffic analysis (adversary sees that phone A sends messages to a lot of others→must be a commander or so; a burst of traffic among phones marked as commanders in an unexpected moment→something is being planned, etc.). Also, availability if Internet of cell coverage is cut by the adversary.
- mwint 5y agoThis would be a pretty cool advertisement, streaming server logs from production in Times Square. A foolish risk, perhaps, but imagine the buzz.
- jeffrallen 5y agoI love it! Especially if in response to some claimed attack on the public logs the company would say, "hah, hah, JK, the stream has been xor'd with /dev/random all along anyway".