How Trail of Bits helps verify the integrity of Signal chats

15 hours ago (blog.trailofbits.com)

Bit of a positive piece amid a negative headline this week: https://cybernews.com/privacy/police-telegram-whatsapp-signa...

  • That requires access to the actual phone and the unlock code in the case of WhatsApp (you need to identify to add a WhatsApp web client).

    For telegram it's a bit easier yes, but the user can set up an additional password. I have done so of course. Note that telegram is not E2EE so they can give your stuff to the police at any time unlike WhatsApp and signal.

    For signal I don't know as I don't really use it but i understand it works the same way as WhatsApp, scan a QR code and authenticate to the phone.

    Also, with all 3 systems it's clearly visible when you look at the linked systems.

    • It is possible to intercept text messages and phone calls in such a way that the recipient never even knows a text message or phone call was sent to them in the first place. SMS is an extremely insecure channel for handling authentication codes.

      https://youtu.be/wVyu7NB7W6Y

I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.

  • Signal's mission is to provide maximized privacy in a form the non-technical public can use.

    A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?

    Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.

    • True they can make their choices but it also means I won't support them in any way. Or recommend them.

      I'd use something that's truly decentralised but signal is just another walled garden like WhatsApp. Just one that promises to behave better. But what's a promise worth these days?

      A decentralised network would mean a guarantee that they can't do anything bad. I'll take that over promises and good intentions any day.

      I don't care about the masses. If signing up for a matrix account is too annoying for them they don't really care about privacy anyway. After all it's the same they have to do for any online shop. Just create a username and password. Somehow it's not a problem for the masses if they wanna order a phone charger but for matrix it's suddenly 'too complicated'?

      2 replies →

    • > What is a more private, usable solution for filtering them out than using a phone number?

      Since when is giving out your phone number a "more private" option ?

      7 replies →

[flagged]

  • You commented this twice, what's your backing, besides 'they're non-commercial thus must be fed by nefarious actors'?

    • I'm also worried about that these days. They posted an article a while back that Signal costs $50m per year to run, and that they make that money from "things". Together with how low a profile they keep, I'm not convinced they aren't a honeypot.

      I love Signal and it's still my preferred messenger, but if it came out that they're backed by some government agency, I wouldn't be extremely surprised.

      5 replies →