A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
- Don’t promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
- 0 users online
- 108 users / day
- 435 users / week
- 1.32K users / month
- 4.54K users / 6 months
- 1 subscriber
- 4.77K Posts
- 119K Comments
- Modlog
I assume they mean compromised by apps that are installed on one or more devices that can access the keys to the conversations or even cracked versions of Signal itself planted during mostly illegal searches.
That’s not Signal being compromised, that’s the phone and is true of all apps running on compromisable phones. If not, I’d love to see the problem and they can point to the place in the app code where it exists since it would have to be the app and it’s open source. The server doesn’t have the keys for the messages. Unless they’re saying a standard encryption algorithm has a backdoor. Governments have been attempting that for decades, and I wouldn’t be surprised, but also not just affecting Signal since these are standards. And this should be especially shown as it could affect everything from banking to corporate VPNs and any backdoor is available to black hat hackers as well as government. Anything else is scaremongering from sources that are well known for doing just that and not afraid of outright lying, or “alternative facts”, not just manipulating actual facts for their purposes, which they also do on a regular basis.
Signal is not private since metadata is required for routing and reducing spam and falsifying identity. It’s a compromise of all e2ee messaging apps. And unavoidable without significant inconvenience in routing and no control over spammers/scammers, or 100% trust in the middleman servers.
But it is secure unless evidence is given and it would be super easy to provide evidence since all encryption and decryption happens on devices and no keys are shared to the server by the apps themselves as shown by said code.