4 ms·
I think Signal provides deniable authentication, i.e. you can forge messages which cannot be distinguished from a real conversations. I wonder if it has any imp
by tracnar 5y ago
I think Signal provides deniable authentication, i.e. you can forge messages which cannot be distinguished from a real conversations. I wonder if it has any impact legally speaking, but I guess it would not matter unless there's evidence of tampering.
- zamadatix 5y agoSignal uses sender certificates and end to end signing the messages. Even if you don't set a pin to enable registration lock and someone steals your phone number temporarily without you noticing and they know who to send the forged messages to everyone will get a big warning message about the key being changed and to verify it's the other person. Unless you just mean completely invent evidence on a controlled device in which case sure just edit the local message database like you would anything.
- tracnar 5y agoI'm referring to this cryptographic property: https://en.wikipedia.org/wiki/Deniable_authentication https://en.wikipedia.org/wiki/Deniable_authentication which means that once a message is received you cannot re-authenticate it, so evidence on any device is no better than with unencrypted messaging. This is in contrast with classic public key authentication like PGP which provides further evidence that the message is legit and was indeed sent by who it says.