• Jul@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    14
    ·
    4 days ago

    I assume they mean compromised by apps that are installed on one or more devices that can access the keys to the conversations or even cracked versions of Signal itself planted during mostly illegal searches.

    That’s not Signal being compromised, that’s the phone and is true of all apps running on compromisable phones. If not, I’d love to see the problem and they can point to the place in the app code where it exists since it would have to be the app and it’s open source. The server doesn’t have the keys for the messages. Unless they’re saying a standard encryption algorithm has a backdoor. Governments have been attempting that for decades, and I wouldn’t be surprised, but also not just affecting Signal since these are standards. And this should be especially shown as it could affect everything from banking to corporate VPNs and any backdoor is available to black hat hackers as well as government. Anything else is scaremongering from sources that are well known for doing just that and not afraid of outright lying, or “alternative facts”, not just manipulating actual facts for their purposes, which they also do on a regular basis.

    Signal is not private since metadata is required for routing and reducing spam and falsifying identity. It’s a compromise of all e2ee messaging apps. And unavoidable without significant inconvenience in routing and no control over spammers/scammers, or 100% trust in the middleman servers.

    But it is secure unless evidence is given and it would be super easy to provide evidence since all encryption and decryption happens on devices and no keys are shared to the server by the apps themselves as shown by said code.