

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.by chews
- Ditto for Trail of Bits, worked with them recently and they do some really impressive quality work, and have some very sharp guys working for them.
- And apparently, just like Telegram, just like WhatsApp, they readily merge the username with your number if numbers are already saved.
- They will allow registering without phone number as a paid option soon.by ortekk
- It is extremely rare to find pro-privacy people speak out against Signal's phone number registration system. It is a very obvious privacy flaw that all hobbyist cryptographers will be eager to wave away for some or another reason. Truly shameful. Thanks for voicing your Signal scepticism. I am a Signal sceptic too.by kevin061
- Signal's mission is to provide maximized privacy in a form the non-technical public can use.
A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?
Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.
by mmooss - Bit of a positive piece amid a negative headline this week: https://cybernews.com/privacy/police-telegram-whatsapp-signa...by pizzaiolo
- For any high-trust system, users need to know exactly what was verified, what was not, and which assumptions the verification depends on.by soltanov
- That requires access to the actual phone and the unlock code in the case of WhatsApp (you need to identify to add a WhatsApp web client).
For telegram it's a bit easier yes, but the user can set up an additional password. I have done so of course. Note that telegram is not E2EE so they can give your stuff to the police at any time unlike WhatsApp and signal.
For signal I don't know as I don't really use it but i understand it works the same way as WhatsApp, scan a QR code and authenticate to the phone.
Also, with all 3 systems it's clearly visible when you look at the linked systems.
by wolvoleo - Recently a bureaucrat who wanted to make a mass protest out of his criticism of Indian Election Commission's drive to remove voters, was picked up by Indian Police and his Signal metadata was accessible to the Police. What is the solution to this thing?
His interview does not tell us if it was metadata or actual calls that were surveilled which could point to device compromise too.
"What caught him by surprise, he told ThePrint, was the Special Cell officers' access to his calls made via Signal"
https://theprint.in/india/ex-civil-servant-ashish-joshi-reca...
by iamshs