7 ms·
Does anyone know if using a Jabber client instead of a carrier can work to prevent this sort of thing?
by moose44 3y ago
Does anyone know if using a Jabber client instead of a carrier can work to prevent this sort of thing?
- gaogao 3y agoBetter to use something with robust end-to-end encryption like Signal
- _8j50 3y agoIs that why Signal collects your phone number? Hah. Any E2E app that doesn't collect your phone number or any identifiable info that you can use as a standalone app on the desktop and E2EE is the only way it works (not optional or opportunistic like jabber/xmpp, whatsapp, matrix, telegram,etc...) and is developed ouside the US by a well known/reputed dev(s). Is what I recommed. Check out wire and briar if they meet these requirements. Personally, I would not use digital media if I don't want the US gov knowing about it entirely. The solution is legislative not technical. Kind of like how you get a free TSA body massage at the airport, the people have willed it.
- jvanderbot 3y agoWell there's layers here. You could easily snoop who is messaging whom, but it's very different than knowing what is being messaged. End to end encryption would protect the second. Carrying a second phone intuitively protects the first, but in reality does not.
- woodruffw 3y ago“End-to-end encrypted” and “private identity mapping” are orthogonal properties: a chat system can have both, but doing so is significantly harder (both in terms of engineering complexity and teaching users to operate the system safely). Signal chooses (or more accurately chose, since they’re working on eliminating it) to depend on telephone numbers for identity mapping, which was and is a reasonable design constraint given their target audience.
- throw10920 3y ago> which was and is a reasonable design constraint given their target audience Who do you think their target audience is, and why do you think that this a reasonable constraint?
- barsonme 3y agoTheir target audience is literally the general population. It should be obvious why phone numbers are a reasonable constraint.
- _8j50 3y agoNo, that's the deception of signal. The general population is already using other identifiers like whatsapp and viber numbers (which almost every country outside the US use even more than sms). Signal refuses to opt-out of phone number collection and usage. With the tens of millions at their disposal and with the time they spend on mobile payments, crypto,etc... you are telling me they can't auto-generate identifiers as alternative to phone numbers? They can't make it alphanumeric and consider any id that is all numbers a phone? It's all culting around tech/crypto personalities and ignoring the obvious things that don't pass the smell test. Explain to me why Signal is special as opposed to more popular apps made for the general population that also do E2EE? Explain to me specifically why phone numbers and mobile usage is not optional? Even after like a decade of people begging for it? This is a lot like PGP email, the same circles of people promoted it (still do in some cases) but the government loves it because email metadata is unencrypted and tech circles insist on email dependency on every app because of the same cult mindset even though hostile middle parties love it. Everything I do in amazon, netflix, uber, slack you name it you can tell my whole life pattern just looking at email subjecte in the clear on an MTA! All because of tech sector refusal to apply critical thinking and creativity when it comes to these things. So again I ask, if I am allowed to criticaly examine Signal: why is it special and unique that it needs phone numbers no matter what? Especially given device compromise of people you talk to is not in their threat model. e.g.: you are a source and the journalist's phone is compromised, that is exactly what governments do! If signal didn't collect phone numbers all they would see on the journalist's phone would be your nick or in-app id, but thanks to signal they can find out who the source is, and using exploit kits like pegasus this way is not uncommon! Real people are put in danger by signal. Look at all my downvotes and tell me this is not tech sector conspiracy or at best culting after personalities.
- moose44 3y agoI use signal but, most of my contacts do not. I've opted for porting my phone number to JMP.chat which does offer E2EE. However, the recipient must also have an encrypted Jabber account.
- madars 3y agoThe claimed features (see pg 5 of https://www.wyden.senate.gov/imo/media/doc/wyden_hemisphere_surveillance_letter_112023.pdf https://www.wyden.senate.gov/imo/media/doc/wyden_hemisphere_...) operate at a cell service level, so as long as your phone is still connecting to base stations the answer would be "no." Take, for example, "Linking multiple devices/phone numbers to an identified target" -- even if you use Signal on two phones and never do regular text/call, if the two devices travel together (e.g. connect to the same carrier base stations) one can make a guess that they are related. This has much wider applicability than the drug investigation mandate: e.g. you could use such capability to identify who is meeting with which investigative journalist.
- rollcat 3y agoI think most privacy-conscious people have a pretty good idea about how to maintain proper private key hygiene (key should never leave the device, use FDE + a passphrase or a hardware token, etc). But we've been leaking metadata (such as mail headers) left and right ever since PGP was a hot new thing, something which should've been our primary concern no later than since Snowden/2013. It would be good to have a proper field guide written down, that's a little more in-depth than "leave your phone at home", weighing risks vs convenience, going into detail on what kinds of metadata you might be leaking, etc. Most of us have some rough idea but it isn't at all obvious the way we know "MD5 is broken".
- moose44 3y agoInteresting. Thank you for sharing. So faraday bags and removing sim cards all together is the best course of action?
- xethos 3y agoIf you want generic advice, it's "Faraday bag or pull the battery". "Off" isn't "Everything is off and nothing will communicate via any radio" on every handset, and some will connect to towers without a SIM in case you need to make an emergency call.
- upofadown 3y ago
- fredgrott 3y agoits the meta-data they are accessing not the call itself, which means the title is somewhat misleading as no one would ever need a warrant in the first place!