@david_chisnall@infosec.exchange
2026-08-11 08:56 UTC
Replies (4)
-
@Kukmetz@social.vivaldi.net 2026-08-11 11:31
@david_chisnall@infosec.exchange @arcanechat@fosstodon.org "...there are serious concerns that organizers should discuss and further study. These include: (1) Signal’s extensive ties to the state and major corporations, (2) Signal’s extractive and anti-democratic corporate model, and (3) Signal’s technical dependence on companies like Google, Microsoft, and Amazon, which could open it up to surveillance or censorship. https://www.counterpunch.org/2025/03/07/the-revolution-will-not-be-signaled/ "New tracking tool exploits WhatsApp/Signal delivery receipts to monitor users silently, and reveal daily routines using just phone number." https://www.cyberkendra.com/2025/12/free-tool-can-spy-whatsapp-and-signal.html #Signal collects #Metadaten the same as #WhatsApp https://primal.net/e/note154hta9dt8k4mhleu4z20rwlqd85dxap20xtvcy4fq89uzcrwshpsdelk2t Meet Paragon: An American-Funded, Super-Secretive Israeli Surveillance Startup That ‘Hacks WhatsApp And Signal’ https://www.forbes.com/sites/thomasbrewster/2021/07/29/paragon-is-an-nso-competitor-and-an-american-funded-israeli-surveillance-startup-that-hacks-encrypted-apps-like-whatsapp-and-signal/ Secure Messenger 86 #Threema = the most secure messenger 82 #SimpleX 80 #Session 78 #Signal 64 #Wire 63 #Element X #Matrix 45 #Viber 42 #Apple #iMessage 32 #Whatsapp 31 #Google #Messages 30 #Telegram 30 #Facebook Messenger 15 #XChat Source: https://www.securemessagingapps.com and rate 🟩=3 🟨=1 🟥=0
-
@arcanechat@fosstodon.org 2026-08-11 12:06
@david_chisnall@infosec.exchange > This is misleading. The phone number in Signal is not used for message routing at all it is not, any government can block Signal's servers and SMS codes for login in, in places like Iran while Signal is not working during shutdown, ArcaneChat and similar do > Your only rationale in the comic is that they are hosted on AWS. the thing is, besides any technical matter, it is just plain bad to support Signal when millions of dollars donated go to Amazon and other big tech
-
@arcanechat@fosstodon.org 2026-08-11 12:02
@david_chisnall@infosec.exchange > what can leak from Signal: the timestamp at which you joined the network and the timestamp at which the client last connected to the network you seem to be on a higher protocol level ignoring that Amazon servers know users' IPs (often this means location/city) out of the control of Signal, the adversary can go directly to Amazon for this info without needing collaboration of Signal, and can know then what IP/user is sending message/traffic/data to whom
-
@LukefromDC@kolektiva.social 2026-08-13 08:32
@david_chisnall@infosec.exchange @arcanechat@fosstodon.org The whole point to end to end encryption is that neither the network nor the server has to be trusted to protect message content. The point to Signal being open source is that the insertion of a backdoor to "escrow" keys or scan decrypted plaintext would be instantly caught due to it likely being under a microscope by mutually opposing parties. It is reasonable to treat AWS and the Big Telcos providing every link between the phones of users as malicious, so Signal is designed to resist such attacks. Whatsapp by comparison is closed source and controlled by a proven adversary, Meta. Although it supposedly uses the same comms protocol as Signal, it could be doing anything in the background: snarfing keys, scanning and forwarding data, anything. A really stupid backdoor might be detected using Wireshark but a smart one could be tough to find without access to the source code,