None of my friends use Signal, so I'm in four group chats where I'm the only member (Journalists from The Atlantic notwithstanding). One is for transferring files between devices, one is for notes, one is for reminders, and one is for frequent backups of things like my browser bookmarks.
At the blinding speed of technology development in today's timeline, I rarely go back more than a couple years. It's usually stale and outdated even just 2 years ago.
Sticking with the snail mail analogy, what happens when two pen pals keep sending mail to each other from their homes without including return addresses in their envelopes? The postal service might not know who exactly is sending each piece of mail but, over time, they would know that Address A in Lower Manhattan, New York, keeps on getting one-way mail from the post office in 3630 East Tremont Avenue, the Bronx, New York; and Address B in the Bronx keeps on getting one-way mail from the post office in 350 Canal Street, Lower Manhattan.
I mean, no, all they know is that they ALL users get one way mail all the time?
The "over time" in "but, over time, they would know that..." does a lot of heavy lifting. Would they? How would they know that?
Sure, if there were only two participants in the system, I would agree. But we have way more than 2 users on signal.
Someone logging timestamps for messages received on both ends of a conversation would be able to determine that two people are probably talking to each other given enough data. Signal is probably not doing that, but Signal's other security guarantees provided by an open source client that encrypts communications end to end hold even if the organization was infiltrated or taken over by a bad actor. The anonymity of participants in a conversation is not protected as strongly as the contents of messages.
Wasn't Signal only able to disclose first and last timestamps when a user has connected to their servers when receiving legal requests? I just assumed their protocol made it so that they can't do it, or they theoretically can but don't store such logs.
The Signal messenger introduced “Sealed Sender” in 2018 to keep their server infrastructure ignorant of who is sending a message to a set of recipients. It is particularly important because the Signal server knows the mobile number of each account, which is usually associated with a passport identity.
Even if chatmail relays do not ask for any private data (including no phone numbers), it might still be worthwhile to protect relational metadata between addresses. We don’t foresee bigger problems in using random throw-away addresses for sealed sending but an implementation has not been agreed as a priority yet.
21 Comments
LambdaRX@sh.itjust.works · 59 pts · 257d
Thankfully i don't have this problem, almost all of my contacts use only proprietary messengers instead of this shady Signal.
Tenderizer78@lemmy.ml · 7 pts · 257d
None of my friends use Signal, so I'm in four group chats where I'm the only member (Journalists from The Atlantic notwithstanding). One is for transferring files between devices, one is for notes, one is for reminders, and one is for frequent backups of things like my browser bookmarks.
DetachablePianist@lemmy.ml · 1 pts · 257d
check out Floccus to sync your bookmarks across all browsers & devices. It improved my workflow significantly!
Tenderizer78@lemmy.ml · 1 pts · 256d
I've got my bookmarks synced, it's just I want to be able to recover them if they're tampered with by malware.
Blizzard@lemmy.zip · 53 pts · 257d
Someone dug out a 2 year old article.
irmadlad@lemmy.world · 13 pts · 257d
At the blinding speed of technology development in today's timeline, I rarely go back more than a couple years. It's usually stale and outdated even just 2 years ago.
clot27@lemmy.zip · -7 pts · 257d
I saw this in hackernews bro😣
RodgeGrabTheCat@sh.itjust.works · 10 pts · 257d
So? Its still a two-year-old outdated article.
clot27@lemmy.zip · 8 pts · 257d
It was on the trending page of hackernews so I thought it would be relevant. But ok I get your point
it_depends_man@lemmy.world · 34 pts · 257d
I don't really get it,
I mean, no, all they know is that they ALL users get one way mail all the time?
The "over time" in "but, over time, they would know that..." does a lot of heavy lifting. Would they? How would they know that?
Sure, if there were only two participants in the system, I would agree. But we have way more than 2 users on signal.
Zak@lemmy.world · 17 pts · 257d
Someone logging timestamps for messages received on both ends of a conversation would be able to determine that two people are probably talking to each other given enough data. Signal is probably not doing that, but Signal's other security guarantees provided by an open source client that encrypts communications end to end hold even if the organization was infiltrated or taken over by a bad actor. The anonymity of participants in a conversation is not protected as strongly as the contents of messages.
PiraHxCx@lemmy.ml · 3 pts · 257d
Duke_Nukem_1990@feddit.org · 29 pts · 257d
Another hit piece on signal? Damn they must be doing something right.
kami@lemmy.dbzer0.com · 2 pts · 256d
GrapheneOS is being attacked too, by the French government and law enforcement in particular.
Funny coincidence: .ml is a French instance.
EDIT: just to be clear, I DO think it's a coincidence, especially since other posts in this community are pro-graphene and pro-signal.
pogodem0n@lemmy.world · 25 pts · 257d
Wasn't Signal only able to disclose first and last timestamps when a user has connected to their servers when receiving legal requests? I just assumed their protocol made it so that they can't do it, or they theoretically can but don't store such logs.
Cooper8@feddit.online · 2 pts · 257d
Does Delta Chat / Arcane Chat suffer from the same vulnerability?
https://arcanechat.me/ https://delta.chat/en/
QuestionMark@lemmy.ml · 4 pts · 256d
From https://delta.chat/en/help#sealedsender
Cooper8@feddit.online · 1 pts · 256d
Thanks, that is very clear
not_me@piefed.social · 0 pts · 257d
Crampi@sh.itjust.works · 17 pts · 257d
Too bad its creator seems to like Trump https://mstdn.social/@rysiek/114630877715286899
I prefer deltachat https://delta.chat/
not_me@piefed.social · 7 pts · 257d
MutilationWave@lemmy.dbzer0.com · 9 pts · 257d
Most people in the US are as well but many of them don't vote and the system is rigged in favor of Republicans.
aurelar@lemmy.ml · 2 pts · 253d
If the tech works as it should, that's what I care about the most.
orbituary@lemmy.dbzer0.com · 2 pts · 257d
Have fun talking to yourself.
not_me@piefed.social · 8 pts · 257d