Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Privacy
  3. Signal is not the place for top secret communications, but it might be the right choice for you – a cybersecurity expert on what to look for in a secure messaging app

Signal is not the place for top secret communications, but it might be the right choice for you – a cybersecurity expert on what to look for in a secure messaging app

Scheduled Pinned Locked Moved Privacy
privacy
103 Posts 56 Posters 494 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • thorned_rose@sh.itjust.worksT [email protected]

    If you want to get really technical, each Signal account actually has a 'secret' account number that the phone number is linked to. The phone number requirement is actually a means to reduce spam and scam accounts.

    G This user is from outside of this forum
    G This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #94

    So they could have replaced it with, like, email verification or something, but they instead stuck to the design that lets governments identify all users?

    <Insert rampant and unfounded speculation about FBI compromise here>

    1 Reply Last reply
    0
    • ikidd@lemmy.worldI [email protected]

      No, but it's easy enough to be both. There's a pile of IM packages out there that manage it.

      Metadata is valuable info, look at what a pen order nets law enforcement and why it's the first step in an investigation. The idea that a messaging app that's supposed to be used for political action but the chain of association is visible and verified is absolutely suspect.

      pathief@lemmy.worldP This user is from outside of this forum
      pathief@lemmy.worldP This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #95

      You say "easy enough" but there are some serious tradeoffs when removing phone numbers from the equation. My mom can use Signal without my help but she wouldn't be able to use SimpleX.

      Signal is a fantastic middle ground messaging app that is secure enough for me to use and easy enough for my mom to use.

      I also have SimpleX but I have exactly 1 contact there...

      1 Reply Last reply
      0
      • swelter_spark@reddthat.comS [email protected]

        SimpleX is what I use. I tried Signal in the past, but there was a noticeable delay in receiving messages and it caused problems when using it to communicate with family.

        I have no problems with SimpleX so far. It works well and looks modern. A feature I like is that you can create a different user identity for each contact/ chat thread.

        ? Offline
        ? Offline
        Guest
        wrote on last edited by
        #96

        You might've had background battery optimization enabled

        swelter_spark@reddthat.comS 1 Reply Last reply
        0
        • florencia@lemmy.blahaj.zoneF [email protected]
          This post did not contain any content.
          S This user is from outside of this forum
          S This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #97

          All I'll say is Threema. You pay once for a licence, so there's less bullshit people on it and they are based in Switzerland with it's privacy laws.

          Z 1 Reply Last reply
          0
          • ? Guest

            So use no messenger? Any decentralized options?

            T This user is from outside of this forum
            T This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #98

            So use no messenger? Any decentralized options?

            Alternatives to Signal that prioritize decentralized communication.

            • Briar Project (https://briarproject.org/ 😞 A compelling choice for censorship resistance. Briar employs peer-to-peer messaging, connecting via Bluetooth, Wi-Fi, or Tor, and incorporates privacy features by design. It’s a robust solution for those concerned about surveillance.
            • Delta Chat (https://delta.chat/ 😞 A decentralized and secure messenger application. It's often praised for its ease of use and integration with existing email accounts.
            • XMPP (https://en.wikipedia.org/wiki/XMPP 😞 Less of an application and more of a foundational protocol. XMPP is an open standard for instant messaging, allowing for decentralized implementations – though setting up and maintaining such a system requires a degree of technical expertise.
            1 Reply Last reply
            0
            • S [email protected]

              All I'll say is Threema. You pay once for a licence, so there's less bullshit people on it and they are based in Switzerland with it's privacy laws.

              Z This user is from outside of this forum
              Z This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #99

              Proprietary?

              S 1 Reply Last reply
              0
              • K [email protected]

                I personally use carrier pigeons with caesar cipher. I know I can't out tech google, so I will go medieval.

                ? Offline
                ? Offline
                Guest
                wrote on last edited by
                #100

                Consider upgrading to IPoA?

                1 Reply Last reply
                0
                • ? Guest

                  You might've had background battery optimization enabled

                  swelter_spark@reddthat.comS This user is from outside of this forum
                  swelter_spark@reddthat.comS This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #101

                  Maybe, but I normally only leave battery optimization on for apps that shouldn't be running in the background at all. This was several years ago, though. If Signal isn't like that anymore, that's a good thing.

                  1 Reply Last reply
                  0
                  • H [email protected]

                    Fair point, it always feels dirty to send invite-link through WhatsApp, the dominant messenger in EU.

                    How would one go to solve the invite problem? How does Signal handle this?

                    J This user is from outside of this forum
                    J This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #102

                    Phone number and trust-on-first-use for most people, with out-of-band fingerprint verification for the paranoid. It really depends on the threat model and the security practices/awareness of your colleagues, but a link shared on some social media or lower-security chat network is more vulnerable to a man-in-the-middle attack than a phone number for your average Joe. There are a lot of ways a person could get a manipulated invite link.

                    1 Reply Last reply
                    0
                    • Z [email protected]

                      Proprietary?

                      S This user is from outside of this forum
                      S This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #103

                      Not sure, but probably. But looking at their history I think they have a good track record and it's used by the government as well in certain cases.

                      1 Reply Last reply
                      0
                      • System shared this topic on
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups