2 ms·
A bare minimum for a company that offers private communication services to people like whistleblowers and activists is that they clearly/plainly explain to thei
by autoexec 18d ago
A bare minimum for a company that offers private communication services to people like whistleblowers and activists is that they clearly/plainly explain to their users what their risks will be when using the service. Signal fails at this. They outright lie to their users. They've started permanently keeping sensitive user data in the cloud, but they've refused to update their privacy policy to reflect that. Misleading or lying to users about their risks when their lives and/or freedom are on the line is unforgivable and disqualifies Signal as being a service anyone should consider.
- bawolff 18d agoI'm doubtful that this is true. Lying in a privacy policy is a crime.
- autoexec 17d agoLook for yourself. The very first line of their policy is "Signal is designed to never collect or store any sensitive information" At one point in the distant past that was actually true! They used to brag about how many times the government came to them requesting information only to be turned away because they never collected any of that in the first place. In 2020 they introduced a major update where they started keeping user's name, phone number, photo, and (worst of all) a list of their contacts in the cloud. This is exactly the same information governments had been requesting from them. There is no way to opt out of this data being collected. You can opt out of setting a pin, but if you do that a pin is auto-generated for you and the data still gets uploaded even though you won't have any access to it. In 2025 they added yet another new feature called "Signal Secure Backups". This was an optional feature that let users store actual message content in the cloud as well. They've refused, for years now, to update their privacy to reflect any of that. Their privacy policy is frozen as of May 25, 2018 See: https://web.archive.org/web/20250117232443/https://www.vice.com/en/article/signal-new-pin-feature-worries-cybersecurity-experts/ https://web.archive.org/web/20250117232443/https://www.vice.... https://web.archive.org/web/20230519120156/https://community.signalusers.org/t/proper-secure-value-security-pins-are-too-easy-to-brute-force-sgx-is-not-reliable-enough/15096/2 https://web.archive.org/web/20230519120156/https://community... Personally, I think their refusal to update their privacy policy is a big fat dead canary warning users that the service has been compromised and shouldn't be trusted. They may be under gag orders from saying so outright, but while the US government can order companies not to tell the public something, they can't force them to say something. For that reason, unless somebody sues them over it, I doubt their privacy policy will ever be updated.