this post was submitted on 21 Sep 2021
24 points (65.8% liked)
Asklemmy
43777 readers
1318 users here now
A loosely moderated place to ask open-ended questions
Search asklemmy ๐
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- !lemmy411@lemmy.ca: a community for finding communities
~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Pretty much everything about it is unverifiable, because its a centralized service and you ultimately don't know what the server is running. Contrast that with self-hostable apps which must pass verifiability checks, because people can host their own instance.
Clients are open source. Independent clients exists and they work. So the server must kind of do what signal claims, otherwise those devs would notice.
You have no idea what the server is running. It has your phone number, ie your real name and address, and it knows who you sent messages to.
But it doesn't though. That information has been subpoenaed from signal in the past. They don't have access to it to give. This is public information.
As comment in thread points out, the subpoenaed info was essentially useless.
Yeah that's exactly my point. Other guys was listing all these things the signal has stored but they really just don't want access to any of it.
IDK if this an issue on my app specifically, but it looks like you put the wrong things in the parentheses there.
Turn on Sealed Sender
https://signal.org/blog/sealed-sender/
This is suspicion on the level of "you can't be sure reality didn't just pop into existence 10 seconds ago". You can never be 100% sure of what others are doing on their hardware, or of anything really, especially if other people are involved. Your chat partners could leak all your chats and metadata for all you know!
What we do know is that Signal is operated by a non-profit foundation, their client and protocol are open source and considered the gold standard for privacy by pretty much every expert on the subject, they had multiple independent audits and a very good track record, they were subpoenaed and couldn't comply because they didn't have the requested data. That's about as good as you can get.
Better use a cipher then for your pen and paper transmission. Invisible ink as well.