3 ms·
Signal uses Curve25519, AES-256, and HMAC-SHA256 for its e2e encryption. So unless you believe those algorithms are insecure, there's no reason to think that th
by WolfeReader 4y ago
Signal uses Curve25519, AES-256, and HMAC-SHA256 for its e2e encryption. So unless you believe those algorithms are insecure, there's no reason to think that their server setup is a compromise on your messages' security.
Fear of "future decryption" applies equally to all forms of encrypted communication, regardless of which servers the messages go through. And since AES-256 is known to resist quantum computing decryption, there's no actual reason to think future decryption will be an issue.
Signal has actually been approached by governments for whatever user data they have, and exactly none of it included messages - encrypted or otherwise. https://www.dailydot.com/debug/signal-grand-jury-subpoena-data/ https://www.dailydot.com/debug/signal-grand-jury-subpoena-da...
As for everything you said about F-Droid and forking, see https://molly.im/ https://molly.im/ . It's not a "branded" fork but it does connect to Signal's servers.
- anonym29 4y agoYou don't need to break encryption to engage in censorship based on unencrypted metadata. OWS is based in San Francisco. The US federal government has compelled providers to introduce backdoors or start logging information that was not being logged before for certain IP addresses or user identifiers - phone numbers in this case, and done so under gag orders that prevent companies from disclosing it. Judges can rule that use of a warrant canary as intended can violate these gag orders as well. Just because Signal can share 1 or 2 instances of cases where information was requested and they did not comply does not mean they never have, weren't able to in the past, or aren't able to in the future. As others have stated, using Signal is putting a lot of trust into the OWS legal entity, and proper cryptosystems should not rely on trust. I hadn't heard of Molly and am checking it out now, thank you for sharing.