4 ms·
I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveilla
by user3939382 13d ago
I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".
- bawolff 13d agoViewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there. I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.
- mitxela 12d agoWhatsApp is also sufficient for the average person. So is SMS. But they're not even slightly secure.
- bawolff 12d agoThe average person might be legit worried about dragnet (non targeted) evensdropping of non encrypted communication. This is rational given what Snowden said. So for the average person, WhatsApp (which is E2E encrypted) is probably quite secure. SMS is not.
- mitxela 10d agoBoth of them are dragnet surveilled. WhatsApp is theorised to do this through its automatic weekly backups.
- latentsea 12d ago>Figure out your adversaries, how much power they have and what they are willing to spend. All of it.
- autoexec 12d agoA bare minimum for a company that offers private communication services to people like whistleblowers and activists is that they clearly/plainly explain to their users what their risks will be when using the service. Signal fails at this. They outright lie to their users. They've started permanently keeping sensitive user data in the cloud, but they've refused to update their privacy policy to reflect that. Misleading or lying to users about their risks when their lives and/or freedom are on the line is unforgivable and disqualifies Signal as being a service anyone should consider.
- bawolff 12d agoI'm doubtful that this is true. Lying in a privacy policy is a crime.
- autoexec 12d agoLook for yourself. The very first line of their policy is "Signal is designed to never collect or store any sensitive information" At one point in the distant past that was actually true! They used to brag about how many times the government came to them requesting information only to be turned away because they never collected any of that in the first place. In 2020 they introduced a major update where they started keeping user's name, phone number, photo, and (worst of all) a list of their contacts in the cloud. This is exactly the same information governments had been requesting from them. There is no way to opt out of this data being collected. You can opt out of setting a pin, but if you do that a pin is auto-generated for you and the data still gets uploaded even though you won't have any access to it. In 2025 they added yet another new feature called "Signal Secure Backups". This was an optional feature that let users store actual message content in the cloud as well. They've refused, for years now, to update their privacy to reflect any of that. Their privacy policy is frozen as of May 25, 2018 See: https://web.archive.org/web/20250117232443/https://www.vice.com/en/article/signal-new-pin-feature-worries-cybersecurity-experts/ https://web.archive.org/web/20250117232443/https://www.vice.... https://web.archive.org/web/20230519120156/https://community.signalusers.org/t/proper-secure-value-security-pins-are-too-easy-to-brute-force-sgx-is-not-reliable-enough/15096/2 https://web.archive.org/web/20230519120156/https://community... Personally, I think their refusal to update their privacy policy is a big fat dead canary warning users that the service has been compromised and shouldn't be trusted. They may be under gag orders from saying so outright, but while the US government can order companies not to tell the public something, they can't force them to say something. For that reason, unless somebody sues them over it, I doubt their privacy policy will ever be updated.
- user3939382 11d agoIt's binary because you decide to use it or not. If your threat model contemplates run of the mill adversaries you don't need Signal. If it contemplates nation states you don't want it.
- 420official 13d agoIs it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not? I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?
- mmooss 13d ago> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not? While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data. I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.
- 420official 12d agoIt's true someone snooping at either end of a conversation could over time correlate timing and sizes to show that two users are communicating, but that's the most they can do. Signal is not peer to peer so you're not connecting to your recipient, and signal itself has enough raw volume that simply correlating sizes and timing of a small number of messages wouldn't really be sufficient to know who is communicating with who. I think they could make that significantly more difficult by adding csprng delays and padding to the messages. That way you can't really effectively correlate timing and sizes without direct access to signals inner workings. I'm not sure what signal's actual throughput is, but if think as a paid feature it could be economical. Another crazier way would be to send every message to a large number random latched recipients. Good way to 1000x your bandwidth. > The metadata is as valuable as the data. This can be true if you are able to get ahold of a user's device and access their signal messages. It's not true in most other cases. I don't particularly care if you know that I am talking to someone specific as much as I care that you don't know what I'm saying.
- monocasa 12d ago> Ex-NSA Chief: 'We Kill People Based on Metadata' > Hayden made the remark after saying he agreed with the idea that metadata - the information collected by the NSA about phone calls and other communications that does not include content - can tell the government "everything" about anyone it's targeting for surveillance, often making the actual content of the communication unnecessary. https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-kill-people-based-on-metadata/ https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-...