Rendered at 07:00:33 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
ggm 7 hours ago [-]
For those who missed it, unrelated to this specific ZKP thing the release cycle also now permits Android tablets without a SIM to be first-class adjunct devices without using wierd tricks or alternate clients. It may permit them to be the initiation/sign-on device, which would invoke the ZKP, but the point for me as an existing phone number denominated user, the point is I can be on my tablet with true signal now. Nothing against molly, wanted it in the base.
kroken 2 hours ago [-]
Thanks for pointing this out. I've been waiting for this for years and was not aware!
opengrass 7 hours ago [-]
You can already do that without being a trusted device.
ggm 6 hours ago [-]
For the longest time, you couldn't. It wasn't until this release I realised that had changed. If it changed before, it wasn't well communicated to me as an Android signal user. I was on beeper and then molly precisely because there was so little traction on changing this. You could install signal fine, but you couldn't QR code or secret phrase mesh it with your android handset. Oddly, iPad meshed fine with iPhone or Android, and OSX desktop likewise. Just Android tablet which didn't.
Do you think this changed in over 18 months? I think it changed in under 18 months.
Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.
ezst 28 minutes ago [-]
Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims about being privacy conscious.
fredski42 11 minutes ago [-]
Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
zx8080 2 minutes ago [-]
XMPP. Run your own (federated) server, chat with anyone outside it, with e2e encryption.
crossroadsguy 3 minutes ago [-]
[delayed]
s0ss 6 hours ago [-]
I’m not sure their tax status is the justification your argument needs.
6 hours ago [-]
what 4 hours ago [-]
OpenAI is 501c3, should they also be required to release everything?
vlovich123 2 hours ago [-]
OpenAI is a 501c4 not a 501c3. Also the structure is much more complicated for OpenAI.
Nevertheless the point stands - I don’t see what relationship company organizational mission has with their technical responsibilities. Indeed, if the open sourced everything, standing up a clone would be easier which creates funding risk due to a race to the bottom of people who didn’t invest into the R&D investing very little additional to compete.
gbriel 3 hours ago [-]
Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.
purpleidea 8 minutes ago [-]
> Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.
Actually you're mistaken. Under the 501(c)(3) tax code rules, they are required to act in the public good. Nobody has sued them to enforce this though, but I'd at least like them to acknowledge the game they're playing by ghosting us all on this.
akoboldfrying 3 hours ago [-]
Perhaps it shouldn't necessitate it, but I can't think of a good reason why not.
If it were expensive to release it, that would be a reason. But it costs roughly zero dollars to create a public repo on GitHub and a cron job to push to it once a day.
Making the system public potentially increases the likelihood of a hack, which would be bad for Signal users. But relying on this argument to keep the source secret is, I think, a confession that your security is below par. Or to put it the other way round: A secure software system remains secure even if its source code is public, so making your source public is a strong signal that you are confident in your security measures. Security isn't something I expect all non-profits to focus on, but I think it would be telling for Signal to hide behind this reason.
What other reasons are there?
Jolter 48 minutes ago [-]
How about they:
1. Don’t want hack competitors launching products using their code
2. Don’t want the resulting fracture in the community
If I were Signal I wouldn’t want either of those.
alightsoul 4 hours ago [-]
Yes
NooneAtAll3 3 hours ago [-]
"open" is literally in the name, so yes
Grombobulous 3 hours ago [-]
Apple should make their products edible as well.
monocasa 2 hours ago [-]
'Apple' was a metaphor to Newton. 'Open'AI was meant as a promise; one that they've since broke both to some of their founders as well to the general populace. Reminding people of that broken promise doesn't seem that wild.
mertenvg 3 hours ago [-]
Pretty sure that was Blackberry's downfall
opengrass 7 hours ago [-]
Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.
Cider9986 6 hours ago [-]
It says something about Play Billing being used specifically to mitigate spam?
I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.
Wouldn't that be related to data storage? Which they offer now? Or is that different?
Cider9986 6 hours ago [-]
Ah, I thought you meant using google play to do the payments to prevent spam unrelated to the cost. I know they are costing something.
6 hours ago [-]
wolvoleo 6 hours ago [-]
Ugh wtf so I need a Google account on Android? That's not going to happen.
For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet.
Just allow monero payments or something. Alongside Google play for the sheep that want to use that.
drnick1 39 minutes ago [-]
> Just allow monero payments or something.
This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.
shim__ 28 minutes ago [-]
> If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.
How do they perform address book matching without an phone number? It just being accessible by SGX does not really count as not storing it.
Problem with phone numbers is they are to short to store as a hash, since you can brute force the sha256 of an phone number in a trivial amount of time on a single consumer device
HWR_14 4 hours ago [-]
Are you being hyperbolic, or do you really consider Google the worst with regards to privacy.
wolvoleo 3 hours ago [-]
The most ubiquitous, absolutely. Their data collection is unparalleled. They're on almost every website, app, they have fingers into payment and browsers and mobile OSes.
In terms of what they do with big data there's more evil parties like Palantir but data abuse starts with collecting it, and I would object to it even if Google promised to only use it for good. For me my privacy is already violated when my data is collected, not just when it's abused. And I do consider Google's use of that data abusive, just not in the worst ways.
shim__ 27 minutes ago [-]
Google is a bad as a phone number since it also has strong ties to your real identity
Cider9986 6 hours ago [-]
Hopefully they eventually make a way to pay without it.
genrader 6 hours ago [-]
You wouldn't believe the spam if they did that
Cider9986 5 hours ago [-]
Why? Just raise the prices if they get more spam on non-google payments.
I've literally registered a Signal account on one of the free SMS sites floating around. Why would spammers choose the payment route over phone numbers? They would just choose the one that's cheaper.
thin_carapace 6 hours ago [-]
googles obligation to hand out all account linked info notwithstanding, one may still create google accounts without associating a phone number, by doing so on old android versions. signal does however explicitly force credit card info here, thus providing direct individual traceability ..
wolvoleo 4 hours ago [-]
Plus they are mandating you give your details to Google. So much for privacy
mmooss 7 hours ago [-]
What about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.
Cider9986 6 hours ago [-]
Nobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal.
They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.
wolvoleo 6 hours ago [-]
I always thought they didn't want monero because they were pushing their own crypto thingy. Which indeed nobody uses.
dakolli 4 hours ago [-]
They avoid Monero because Signal and the EFF are actually the feds and this is all theater.
Cider9986 4 hours ago [-]
Claims without evidence can be dismissed without evidence.
Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX.
If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?
They are the largest messenger that has E2EE backups by default.
monocasa 2 hours ago [-]
If I was the NSA, I would be using the fact that signal uses AWS for their backend combined with the cudgel that .us.gov has with the AWS govcloud contract to mandate that all traffic to and from signal's backend also gets routed to NSA traffic analysis servers, which could then be correlated with other sources like ISP data to get a pretty complete record of all Signal message metadata.
To be clear, I use signal pretty heavily, but that's because my threat model doesn't really include competent .us.gov actors. I don't think that they'd either prove they're doing this or go through the trouble of parallel construction over anything in my messages or who I'm talking to.
dakolli 1 hours ago [-]
Nobody is arguing the e2ee isn't valid, its useful as a metadata collection platform, which is all they care about. Former NSA and CIA Director Michael Hayden famously stated: “We kill people based on metadata." and then he tried to hold back a smile and said "but not with this metadata". It's usefulness as a metadata collection platform becomes much less useful if people don't trust it, so of course it's secure.
If you can convince as many of your enemies (the american people who politically organize against them) to use the same platform, your job becomes easier than having to ETL from 20 different privacy platforms..
To be honest, I use signal, I have nothing to hide but it is useful in that nobody can spoof me (easily). I even talk to my 60 year old mother on signal. It has it's uses. But the EFF is definitely a federal psyop to get people using tools and techniques they control.
Just look at the people who created TOR, they're all feds. All these projects are funded by feds. These tools are advertised in CIA recruitment campaigns, they are literal weapons to circumvent nation state firewalls and deliver psychological weapons, overthrow governments or allow covert recruitment of foreign traitors.
Jhater 4 hours ago [-]
[dead]
wolvoleo 4 hours ago [-]
True, if they're not even going to allow that for payment then they might as well remove it from the app altogether. Because what's the point if they don't even believe in it themselves.
drum55 6 hours ago [-]
I've literally never seen anybody mention it, much less use it since it was announced.
6 hours ago [-]
rkagerer 7 hours ago [-]
Lots of discussion at that link, but what's the bottom line? Can you register without a phone number yet?
Cider9986 6 hours ago [-]
Likely soon.
ynniv 7 hours ago [-]
you can't wave your hands, say "zero knowledge", and be private. this is too little information to be useful
teravor 6 hours ago [-]
usually, the implication of ZKP is that you buy coupons and claim them without attribution. in this coupon scenario the ZKP can just be a blind signature scheme.
however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.
tornado134 2 hours ago [-]
[dead]
sysguest 3 hours ago [-]
any link to presentations/papers on this?
I'm interested on learning ZKPs -- they seem so much like "fairy-tale come true" because I don't know much
Main caveat is that ZKPs are probabilistic. The protocol (number of rounds etc) determines how sure, e.g. 99.9%. But never 100%.
Second caveat: tech- and crypto-bros play fast and loose with the term "ZKP", either because they don't know any better (marketing) or they straight up lie. Whether any application you run actually uses ZKP (or any other cryptography scheme) is unknown unless you have the source code.
Cider9986 6 hours ago [-]
I'm curious about the cost because you can buy a phone number for Signal for ~10 cents (spammers likely get them cheaper). I would still buy it because you don't have to worry about losing your number or something.
smalltorch 6 hours ago [-]
The commit history is kinda wild
2Gkashmiri 5 hours ago [-]
I know for a fact If you use "signal" matrix or whatever "security" app, you will get branded a terrorist in India, your life will be upended and you will face a long list of problems.
Yes that's bad but that's an Indian government problem, not a signal or other messenger app problem. And really, it sounds like there was a lot more going on with these people than just using a particular app. Discord and WhatsApp are mentioned too.
India also bans most satellite phones by the way. I have one so I looked into that as to not get caught out travelling.
Cider9986 4 hours ago [-]
And WhatsApp is E2EE with the same protocol so I don't see the big deal.
2Gkashmiri 4 hours ago [-]
The big deal is, having talked to security people, they are "fine" with WhatsApp because the theory is, they get data from whatsapp so they have some sort of backdoor access.
They are pretty chill with WhatsApp which id unexplainable
Cider9986 3 hours ago [-]
Maybe WhatsApp gives them a ton of metadata like all their contacts, when they chat and with who, IPs, etc. Signal only gives out either time registered or last used last time I checked.
mitxela 1 hours ago [-]
WhatsApp uploads decrypted chats to the cloud once a week.
shim__ 25 minutes ago [-]
No need to enable the google backup
Novosell 50 minutes ago [-]
Source?
qmmmur 25 minutes ago [-]
Have a look in the settings lol
s5300 3 hours ago [-]
[dead]
Synthetic7346 4 hours ago [-]
[flagged]
wolvoleo 4 hours ago [-]
[flagged]
mitxela 1 hours ago [-]
Rape jokes are not okay, and that wasn't even remotely funny anyway.
locitra 23 minutes ago [-]
[flagged]
victorbvieira 5 hours ago [-]
[flagged]
user3939382 7 hours ago [-]
I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".
bawolff 7 hours ago [-]
Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there.
I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.
mitxela 1 hours ago [-]
WhatsApp is also sufficient for the average person. So is SMS. But they're not even slightly secure.
420official 7 hours ago [-]
Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?
I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?
mmooss 6 hours ago [-]
> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?
While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data.
I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.
420official 4 hours ago [-]
It's true someone snooping at either end of a conversation could over time correlate timing and sizes to show that two users are communicating, but that's the most they can do. Signal is not peer to peer so you're not connecting to your recipient, and signal itself has enough raw volume that simply correlating sizes and timing of a small number of messages wouldn't really be sufficient to know who is communicating with who.
I think they could make that significantly more difficult by adding csprng delays and padding to the messages. That way you can't really effectively correlate timing and sizes without direct access to signals inner workings. I'm not sure what signal's actual throughput is, but if think as a paid feature it could be economical.
Another crazier way would be to send every message to a large number random latched recipients. Good way to 1000x your bandwidth.
> The metadata is as valuable as the data.
This can be true if you are able to get ahold of a user's device and access their signal messages. It's not true in most other cases. I don't particularly care if you know that I am talking to someone specific as much as I care that you don't know what I'm saying.
monocasa 1 hours ago [-]
> Ex-NSA Chief: 'We Kill People Based on Metadata'
> Hayden made the remark after saying he agreed with the idea that metadata - the information collected by the NSA about phone calls and other communications that does not include content - can tell the government "everything" about anyone it's targeting for surveillance, often making the actual content of the communication unnecessary.
Isn't it? I think it has a setting, disabled by default, to proxy connections via a Signal server. If you're not doing that ... it must be P2P? Probably with the IP address of the person you're communicating with in the header of every packet?
ranger_danger 4 hours ago [-]
> the surveillance networks can capture metadata - who talks to who and when
If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.
mitxela 1 hours ago [-]
Session uses onion routing. SimpleX does not.
bawolff 3 hours ago [-]
I'm not familiar with SimpleX, but keep in mind only some types of onion routing is secure against a global passive adversary. Famously Tor is not.
Cider9986 3 hours ago [-]
Nym is apparently good against a global adversary.
atiq-ca 8 hours ago [-]
Signal still uses proprietary blob and uses google/apple service for notifications. Use molly.im instead which has solved these problems.
Cider9986 7 hours ago [-]
Molly is a security-hardened Signal client only on Android for people unfamiliar. They went through a period of not updating (there were no security updates during that time afaict), but now releases should happen faster on top of Signal.
In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.
I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..
Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.
rkagerer 7 hours ago [-]
If you're using WebSocket, how do Google and Apple see metadata? Can someone explain why it's so difficult to make a decent chat app divorced from their ecosystems?
Cider9986 7 hours ago [-]
I'm talking about using play services or Apple's version. Signal falls back to a WebSocket if you don't have play services installed.
john01dav 7 hours ago [-]
The native Signal android app delivers notifications just fine without Google play services on my degoogled android.
twothreeone 4 hours ago [-]
Same!
opan 7 hours ago [-]
I was using Silence from F-Droid for a while back in the day because of these issues, but the lack of interop and needing to make everyone move again soured me on the whole thing. I would rather just get people on XMPP or Matrix and not use some sketchy phone-first app at all. For SMS I use Fossify Messages, which I think was a fork of QKSMS. I don't use SMS as primary or sensitive comms, only as needed. Same as email, basically, but less useful.
nosioptar 7 hours ago [-]
I really liked silence. I stopped using it when f-droid said the source code was no longer available. Fossify messages is the best replacement I've found.
(I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)
Cider9986 6 hours ago [-]
GrapheneOS is more well-roundedly private than any desktop OS.
Competition is Qubes but that has usability issues and does not have good hardware security.
wolvoleo 4 hours ago [-]
The problem for me is writing on a mobile device is a terrible user experience.
When I'm at home I don't wanna use a virtual keyboard on a 6.3" (or 7.9 unfolded). I just want to use my triple monitor PC setup with a real keyboard and a wealth of display space.
Mobile is cool for on the go but a productivity killer.
nosioptar 5 hours ago [-]
I'm not about to trust a google branded device. Even if the Graphene folks are on the up and up, google sure as hell isn't.
Cider9986 5 hours ago [-]
That's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want.
Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation.
It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration).
You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services.
But GrapheneOS relies on a proprietary, black-box security chip from Google... who pinky-promised to open-source it but never did, and that just doesn't sit well with me.
I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/method where the OS is not really aware of what's going on.
mitxela 1 hours ago [-]
The government only gets to use this once, and they probably won't use it on you.
ranger_danger 7 hours ago [-]
I tried it and it was fine while it worked, but eventually I had to go back to regular Signal because Molly's updates did not follow Signal's closely enough, and at some point the server code changed enough to where I was unable to use it for an unacceptable amount of time (after checking, it took them weeks to update). Something to keep in mind if you're not using a custom server.
blfr 7 hours ago [-]
Maybe it's because I use Molly as a secondary device (my tablet) but I never had an issue where it didn't work for weeks.
Do you think this changed in over 18 months? I think it changed in under 18 months.
Nevertheless the point stands - I don’t see what relationship company organizational mission has with their technical responsibilities. Indeed, if the open sourced everything, standing up a clone would be easier which creates funding risk due to a race to the bottom of people who didn’t invest into the R&D investing very little additional to compete.
Actually you're mistaken. Under the 501(c)(3) tax code rules, they are required to act in the public good. Nobody has sued them to enforce this though, but I'd at least like them to acknowledge the game they're playing by ghosting us all on this.
If it were expensive to release it, that would be a reason. But it costs roughly zero dollars to create a public repo on GitHub and a cron job to push to it once a day.
Making the system public potentially increases the likelihood of a hack, which would be bad for Signal users. But relying on this argument to keep the source secret is, I think, a confession that your security is below par. Or to put it the other way round: A secure software system remains secure even if its source code is public, so making your source public is a strong signal that you are confident in your security measures. Security isn't something I expect all non-profits to focus on, but I think it would be telling for Signal to hide behind this reason.
What other reasons are there?
If I were Signal I wouldn’t want either of those.
I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.
https://github.com/signalapp/Signal-Android/commit/7da3357b5...
For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet.
Just allow monero payments or something. Alongside Google play for the sheep that want to use that.
This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.
How do they perform address book matching without an phone number? It just being accessible by SGX does not really count as not storing it.
Problem with phone numbers is they are to short to store as a hash, since you can brute force the sha256 of an phone number in a trivial amount of time on a single consumer device
In terms of what they do with big data there's more evil parties like Palantir but data abuse starts with collecting it, and I would object to it even if Google promised to only use it for good. For me my privacy is already violated when my data is collected, not just when it's abused. And I do consider Google's use of that data abusive, just not in the worst ways.
I've literally registered a Signal account on one of the free SMS sites floating around. Why would spammers choose the payment route over phone numbers? They would just choose the one that's cheaper.
They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.
Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX.
If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?
They are the largest messenger that has E2EE backups by default.
To be clear, I use signal pretty heavily, but that's because my threat model doesn't really include competent .us.gov actors. I don't think that they'd either prove they're doing this or go through the trouble of parallel construction over anything in my messages or who I'm talking to.
If you can convince as many of your enemies (the american people who politically organize against them) to use the same platform, your job becomes easier than having to ETL from 20 different privacy platforms..
To be honest, I use signal, I have nothing to hide but it is useful in that nobody can spoof me (easily). I even talk to my 60 year old mother on signal. It has it's uses. But the EFF is definitely a federal psyop to get people using tools and techniques they control.
Just look at the people who created TOR, they're all feds. All these projects are funded by feds. These tools are advertised in CIA recruitment campaigns, they are literal weapons to circumvent nation state firewalls and deliver psychological weapons, overthrow governments or allow covert recruitment of foreign traitors.
however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.
I'm interested on learning ZKPs -- they seem so much like "fairy-tale come true" because I don't know much
Also ZCash.
https://en.wikipedia.org/wiki/Zero-knowledge_proof
Main caveat is that ZKPs are probabilistic. The protocol (number of rounds etc) determines how sure, e.g. 99.9%. But never 100%.
Second caveat: tech- and crypto-bros play fast and loose with the term "ZKP", either because they don't know any better (marketing) or they straight up lie. Whether any application you run actually uses ZKP (or any other cryptography scheme) is unknown unless you have the source code.
https://timesofindia.indiatimes.com/india/ats-probes-use-of-...
https://www.aninews.in/news/national/general-news/accused-da...
https://www.deccanherald.com/india/secure-messaging-apps-lik...
https://india-employmentnews.com/tech-category/delhi-blast-n...
https://timesofindia.indiatimes.com/tech-news/Dangerous-Sign...
And it doesn't matter you use a connected phone or not, they just get data from ISPs.
And yes, using a VPN will get you knocked up as well.
https://www.aljazeera.com/news/2026/1/12/indias-vpn-ban-in-k...
India also bans most satellite phones by the way. I have one so I looked into that as to not get caught out travelling.
I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.
I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?
While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data.
I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.
I think they could make that significantly more difficult by adding csprng delays and padding to the messages. That way you can't really effectively correlate timing and sizes without direct access to signals inner workings. I'm not sure what signal's actual throughput is, but if think as a paid feature it could be economical.
Another crazier way would be to send every message to a large number random latched recipients. Good way to 1000x your bandwidth.
> The metadata is as valuable as the data.
This can be true if you are able to get ahold of a user's device and access their signal messages. It's not true in most other cases. I don't particularly care if you know that I am talking to someone specific as much as I care that you don't know what I'm saying.
> Hayden made the remark after saying he agreed with the idea that metadata - the information collected by the NSA about phone calls and other communications that does not include content - can tell the government "everything" about anyone it's targeting for surveillance, often making the actual content of the communication unnecessary.
https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-...
Isn't it? I think it has a setting, disabled by default, to proxy connections via a Signal server. If you're not doing that ... it must be P2P? Probably with the IP address of the person you're communicating with in the header of every packet?
If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.
In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.
I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..
Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.
(I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)
Competition is Qubes but that has usability issues and does not have good hardware security.
When I'm at home I don't wanna use a virtual keyboard on a 6.3" (or 7.9 unfolded). I just want to use my triple monitor PC setup with a real keyboard and a wealth of display space.
Mobile is cool for on the go but a productivity killer.
Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation.
It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration).
You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services.
Here's a team member's thoughts: https://discuss.grapheneos.org/d/10150-not-your-average-why-...
I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/method where the OS is not really aware of what's going on.