3 ms·
https://www.wired.com/story/phone-notifications-reveal-more-than-you-realize-how-to-lock-them-down/ https://www.wired.com/story/phone-notifications-reveal-more-
by amiga386 12d ago
https://www.wired.com/story/phone-notifications-reveal-more-than-you-realize-how-to-lock-them-down/ https://www.wired.com/story/phone-notifications-reveal-more-...
Apple, at least, maintained a historical database of your phone's notifications, that it did not clean up after they expired. That includes all notifications from Signal telling you that person XXX has sent you a message that starts YYYY <facepalm>
- zeratax 12d agoForgot about that and that def was bad, though imo not really on Signal and would have just as much affected any XMPP app, no? To me this definitely didn't "[throw] it all away" as in your messages were still only on your phone and never decrypted on any server or w/e.
- amiga386 12d agoWell that's the thing, you just don't know what happens once you let Signal send notifications via Apple/Google - clearly they get them plaintext, and who knows if they're retained and subpoena-able directly from Apple/Google. The leak via notifications DB not being cleaned up is just the shot across the bow. You pay a price for convenience. Anyway, I'm not OP, and they have a mad setup (XMPP via Tor) which is a flaky solution most people wouldn't go for. In general, if you're not going to such extreme measures of hiding among the crowd of Tor users to mask your metadata, you're better off directly connecting and hiding among the crowd of Signal users, rather than hosting your own instance.
- zeratax 12d agoto be clear though notifications do the decryption on device themselves. signal uses apple/play services only to notify the device that there has been a message, none of the contents are delivered over these services. if you cant trust the device to do that then no messaging app could ever be secure enough
- fsflover 12d ago> if you cant trust the device to do that then no messaging app could ever be secure enough This is the whole point. Signal actively prevents me from using it outside of the Apple-Google duopoly. Other messaging apps are not like this.
- throwaway74354 11d agoDe-jure it's against the ToS, but it's not being enforced besides "don't be an asshole, don't abuse the network and be careful with Signal branding". Technically, you can use Whisperfish on SailfishOS, Flare on mobile-linux-of-the-day or even signal-cli as a primary device.
- fsflover 10d agoLast time I tried to use Signal, it required "a mobile device" to be in charge of all other "desktop" devices.