Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Privacy
  3. Signal has no known/published real security audit?

Signal has no known/published real security audit?

Scheduled Pinned Locked Moved Privacy
privacy
22 Posts 13 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • adbenitez@lemmy.mlA [email protected]

    Someone made a compilation of academic reviews and blogposts here: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243
    but none of them seem to be real security audit reports, ex. compare with real security audits to Delta Chat: https://delta.chat/en/help#security-audits

    F This user is from outside of this forum
    F This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #6

    As I seen in other comment I think that the protocol is audited not really the app and servers
    In comparison SimpleX is audited pretty regularly

    adbenitez@lemmy.mlA 1 Reply Last reply
    0
    • lattrommi@lemmy.mlL [email protected]

      This was first published in 2021. There are some interesting points made.

      https://dessalines.github.io/essays/why_not_signal.html

      It has had a few updates since, then but I cannot vouch for its accuracy.

      It doesn't cover audits per sé, but I feel there is important information that is tangentially related, since security audits become kind of moot if some of the items mentioned are true (i.e. CIA funding and US govt. tactics).

      Full disclosure, I still use Signal for a family group chat. I have very little economic value, thus my threat model is minimal. It mentions cats several times. I neither have cats, nor interact with them frequently enough to warrant their inclusion in a threat model.

      Y This user is from outside of this forum
      Y This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #7

      Right, always this link to show that signal isn’t trustworthy and then lists “good alternatives” that are either less secure or less usable

      1 Reply Last reply
      0
      • adbenitez@lemmy.mlA [email protected]

        Someone made a compilation of academic reviews and blogposts here: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243
        but none of them seem to be real security audit reports, ex. compare with real security audits to Delta Chat: https://delta.chat/en/help#security-audits

        melody@lemmy.oneM This user is from outside of this forum
        melody@lemmy.oneM This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #8

        Lack of detailed audits...only in this case specifically...does not imply lack of security and/or privacy.

        The protocol that Signal uses, which is in fact firmly audited with no major problematic findings, plus the fact the client is OSS is generally enough to lower any concerns.

        The server side software in production for Signal.org is not OSS. It will not be. You are required to trust the server to use Signal; because the protocol and the client renders it factually impossible for the server to spy on your messages. The server cannot read messages; or even connect who is messaging who if the correct client settings are used. (Sealed Sender).

        Non-OS stats software in general is not automatically lacking in privacy or security, particularly not in this case where the affected software does interact only with software that is verifiably open-source and trustworthy in general due to the protocols and how they are implemented correctly in a verifiable manner.

        M 1 Reply Last reply
        0
        • melody@lemmy.oneM [email protected]

          Lack of detailed audits...only in this case specifically...does not imply lack of security and/or privacy.

          The protocol that Signal uses, which is in fact firmly audited with no major problematic findings, plus the fact the client is OSS is generally enough to lower any concerns.

          The server side software in production for Signal.org is not OSS. It will not be. You are required to trust the server to use Signal; because the protocol and the client renders it factually impossible for the server to spy on your messages. The server cannot read messages; or even connect who is messaging who if the correct client settings are used. (Sealed Sender).

          Non-OS stats software in general is not automatically lacking in privacy or security, particularly not in this case where the affected software does interact only with software that is verifiably open-source and trustworthy in general due to the protocols and how they are implemented correctly in a verifiable manner.

          M This user is from outside of this forum
          M This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #9

          Non-OS stats software in general is not automatically lacking in privacy or security

          Sure is. It's only that in this case you are sure that your messages are sufficiently protected, so you can send them over a untrusted service.

          1 Reply Last reply
          0
          • adbenitez@lemmy.mlA [email protected]

            Someone made a compilation of academic reviews and blogposts here: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243
            but none of them seem to be real security audit reports, ex. compare with real security audits to Delta Chat: https://delta.chat/en/help#security-audits

            H This user is from outside of this forum
            H This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #10

            There's a hardened "version" of signal called molly

            adbenitez@lemmy.mlA 1 Reply Last reply
            0
            • H [email protected]

              There's a hardened "version" of signal called molly

              adbenitez@lemmy.mlA This user is from outside of this forum
              adbenitez@lemmy.mlA This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #11

              does that one has security audits? thanks in advance

              H 1 Reply Last reply
              0
              • I [email protected]

                If you use Android, Briar is end to end encrypted and doesn't have a central server and its recommended by privacyguides.org

                adbenitez@lemmy.mlA This user is from outside of this forum
                adbenitez@lemmy.mlA This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #12

                does Briar has security audits you could point to? thanks in advance

                I 1 Reply Last reply
                0
                • F [email protected]

                  As I seen in other comment I think that the protocol is audited not really the app and servers
                  In comparison SimpleX is audited pretty regularly

                  adbenitez@lemmy.mlA This user is from outside of this forum
                  adbenitez@lemmy.mlA This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #13

                  could you provide some source/link to the SimpleX security audits? I would like to look into it, thanks in advance!

                  T 1 Reply Last reply
                  0
                  • adbenitez@lemmy.mlA [email protected]

                    does Briar has security audits you could point to? thanks in advance

                    I This user is from outside of this forum
                    I This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #14

                    https://briarproject.org/news/2017-beta-released-security-audit/

                    1 Reply Last reply
                    0
                    • adbenitez@lemmy.mlA [email protected]

                      does that one has security audits? thanks in advance

                      H This user is from outside of this forum
                      H This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #15

                      Both signal and molly are considered safe, a lot of apps use the same protocol as signal, most risk come from messages leaks before the encryprion happens.

                      Unfortunately, I'm not aware if they did external audits, but both codes are available in github.

                      S 1 Reply Last reply
                      0
                      • adbenitez@lemmy.mlA [email protected]

                        could you provide some source/link to the SimpleX security audits? I would like to look into it, thanks in advance!

                        T This user is from outside of this forum
                        T This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #16

                        This seems to be the latest one. https://simplex.chat/blog/20241014-simplex-network-v6-1-security-review-better-calls-user-experience.html

                        F 1 Reply Last reply
                        0
                        • adbenitez@lemmy.mlA [email protected]

                          Someone made a compilation of academic reviews and blogposts here: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243
                          but none of them seem to be real security audit reports, ex. compare with real security audits to Delta Chat: https://delta.chat/en/help#security-audits

                          F This user is from outside of this forum
                          F This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #17

                          Not a formal audit, but a more recent review of the protocol: https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/

                          adbenitez@lemmy.mlA 1 Reply Last reply
                          0
                          • F [email protected]

                            Not a formal audit, but a more recent review of the protocol: https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/

                            adbenitez@lemmy.mlA This user is from outside of this forum
                            adbenitez@lemmy.mlA This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #18

                            thanks, I think I know that one, but yeah as you said it is not a real security audit and the person itself said so

                            1 Reply Last reply
                            0
                            • H [email protected]

                              Both signal and molly are considered safe, a lot of apps use the same protocol as signal, most risk come from messages leaks before the encryprion happens.

                              Unfortunately, I'm not aware if they did external audits, but both codes are available in github.

                              S This user is from outside of this forum
                              S This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #19

                              At a user level, the biggest security compromise with signal is enabling notifications

                              H 1 Reply Last reply
                              0
                              • S [email protected]

                                At a user level, the biggest security compromise with signal is enabling notifications

                                H This user is from outside of this forum
                                H This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #20

                                That's a big one, you can disable it, but if the other person has it enabled it can leak it after decryption also.

                                S 1 Reply Last reply
                                0
                                • T [email protected]

                                  This seems to be the latest one. https://simplex.chat/blog/20241014-simplex-network-v6-1-security-review-better-calls-user-experience.html

                                  F This user is from outside of this forum
                                  F This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #21

                                  Right thank you

                                  1 Reply Last reply
                                  0
                                  • H [email protected]

                                    That's a big one, you can disable it, but if the other person has it enabled it can leak it after decryption also.

                                    S This user is from outside of this forum
                                    S This user is from outside of this forum
                                    [email protected]
                                    wrote on last edited by
                                    #22

                                    Exactly the issue, same as always. Signal got rid of sms because it was insecure but enable reply in notifications by default.

                                    1 Reply Last reply
                                    0
                                    • System shared this topic on
                                    Reply
                                    • Reply as topic
                                    Log in to reply
                                    • Oldest to Newest
                                    • Newest to Oldest
                                    • Most Votes


                                    • Login

                                    • Login or register to search.
                                    • First post
                                      Last post
                                    0
                                    • Categories
                                    • Recent
                                    • Tags
                                    • Popular
                                    • World
                                    • Users
                                    • Groups