6 ms·
How is Signal secure? It’s proprietary and they need your phone number.
by midislack 4y ago
How is Signal secure? It’s proprietary and they need your phone number.
- gleenn 4y agoIt's open source and had security auditing over the code. If it makes you feel better, I think Moxie also posts here in HN too.
- greyface- 4y agoTheir server is not 100% open source. https://news.ycombinator.com/item?id=29072031 https://news.ycombinator.com/item?id=29072031 Also, for a period of about a year, the code that was open sourced differed from the code actually running on the servers, adding "mobilecoin" features in secret. https://news.ycombinator.com/item?id=26715223 https://news.ycombinator.com/item?id=26715223
- walterbell 4y agoWire is open-source and does not mandate a phone number or sharing of address book contacts. Wire contributed to IETF MLS multi-vendor open protocol for E2EE group messaging, https://datatracker.ietf.org/wg/mls/about/ https://datatracker.ietf.org/wg/mls/about/
- sneak 4y agoSignal does not mandate sharing of address book contacts either; it works fine without contacts permission. (This is how I use it.)
- h4waii 4y agoSecurity!= Privacy Providing a phone number doesn't undermine the security of Signal at all. I'd also hazard to say that Signal isn't proprietary either, yes, there are parts of the project that are pretty opaque and we can definitely get behind the issues with that, but it's far from proprietary IMO.
- cmroanirgo 4y agoThere are inter- relationships between privacy and security however. You can't maintain good privacy unless you have a secure platform, and what is the point of security if you cannot maintain privacy? Eg. Signal fails privacy requirements with the telegraphing of your phone number when you join a public group. There is no need for a phone number to be available to people that you don't know personally. This can lead to all sorts of physical issues (abuse, doxxing, arrests...). It would be better if a phone number was treated as a private piece of information (like SSN, home address) that is not sent out without your explicit interaction.
- ziddoap 4y agoA phone number. You mean the thing that you hand out to strangers so that they can contact you? The thing that was designed from the start to be shared, and used to be listed in a big book that everyone had? The thing that you put on top of the paper that you hand out to dozens of companies when looking for a job? What are you concerned about with your phone number? In what way does Signal (or anyone) having your phone number undermine your security?
- ArrayBoundCheck 4y agoI might get bashed for this but open source isn't secure at all. Have we had a month where no heavily used dependency gets infected? Proprietary code that's been audited is already better then most projects Not sure why phone number matters. Pretty much anyone can find your phone number
- danjoredd 4y agoHere is the problem...is Open Source less secure because people find more software bugs, or is that accomplishing the whole purpose of open source technology? With the source code public, people find more bugs and it comes across as less secure, but they ultimately get fixed. A lot of those same bugs go unnoticed for years in proprietary software, and as a result its less secure. Yeah, proprietary software can be audited, but you only have like one or two guys doing the audit. They are going to miss something big. More eyes is better than few eyes. As far as the phone number goes, the person above is more focused on anonymity than anything else. You having your phone number tied to it is a pretty big cause of concern if that is the goal you are after unless you use a throwaway number.
- ziddoap 4y ago>Proprietary code that's been audited is already better then most projects Even better would be open source code that's been 3rd-party audited. Because you have formal audits, plus several informal audits. Like Signal.
- ArrayBoundCheck 4y agoThe OS is likely less secure than signal. Google and Apple seem to play a game of wack a mole