this post was submitted on 01 Jun 2024
-141 points (3.3% liked)

Privacy

31660 readers
565 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
top 9 comments
sorted by: hot top controversial new old
[–] slazer2au@lemmy.world 63 points 4 months ago (1 children)

This whole article is an advert for this companies own new secure messenger because......

Why Would We Stop Using Signal?

We had a security breach of some root keys for a legacy chat server we were running and it got attacked and destroyed. It was too hard to restore after the attack and was abandoned. We tracked down the data leak to Signal, as the engineers had used Signal to send these keys between themselves.

Human error. Why are you allowing private keys on untrusted devices?

[–] PotatoesFall@discuss.tchncs.de 25 points 4 months ago

The next sentence is the most important:

However, you can never be 100% sure and after the fact it’s impossible to prove with certainty that was the cause….but it made us wonder.

lol

[–] Tempo@lemmy.ml 44 points 4 months ago

This is just an ad for something called PrivateLINE (no relation).

[–] swooosh@lemmy.world 36 points 4 months ago

Who are the donors? Signal costs a lot of money to operate. Who gave it the funds to operate?

If you don't know that, maybe you should start researching before writing a blog post. I'm not doing that part for you because you were to lazy/dumb.

[–] Max_P@lemmy.max-p.me 29 points 4 months ago

That's a hell of a lot of massively unsubstantiated claims and paranoia.

It's end to end encrypted, that it's hosted on AWS or who funded the project doesn't matter. The encryption is open-source and auditable (and has been audited as well). It doesn't even know who talks to who. For notifications, it's decrypted locally on the device by Signal, and can be turned off. It's also encrypted in transit on top of the E2E so only Signal servers can decrypt the little metadata there is, not everyone on the network.

And none of this is confidence inspiring about their own service. It's 2024, how the fuck isn't rebuilding their compromised server not a single command away, and why are they even attempting to fix it in the first place? Why do they even have access to the server at all?

Absolutely zero credibility. None.

[–] autonomoususer@lemmy.world 19 points 4 months ago

This is disinformation to spread anti-libre software (malware).

[–] eager_eagle@lemmy.world 17 points 4 months ago* (last edited 4 months ago)

It turns out that startup funding for Signal was from a US Government tied entity. Some people won’t like that. Here’s an interesting article: Signal Facing Collapse After CIA Cuts Funding

Someone already commented on the "nothing-burger" this article and line of reasoning actually is, so I won't repeat it here.

$19m / 50 = $380,000 per year per employee!!!

This $19M figure includes more things. That's why a blog post shouldn't be read as an accounting report. Report summaries with salary figures are available btw, one search away.

The infrastructure was not designed to minimize the cost of operations, it was designed for another purpose, data collection by third parties:

The quoted text is not evidence for this. Quite the opposite, in fact.

Elon Musk also promotes Signal:

He promotes Linux too. Also, I bet he drinks water.

I see some valid concerns / questions, but it's immersed in a muddy water of arguments that is hard to disentangle.

[–] RmDebArc_5@sh.itjust.works 16 points 4 months ago* (last edited 4 months ago)

So the solution for signals problems is a matrix based app that doesn’t even have passcode rekeying? Also it seems like the source code of the app isn’t available and they literally advertise that they will hand over to the government on request