9 ms·
How Trail of Bits helps verify the integrity of Signal chats
- chews 5d agoI have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.
- ortekk 5d agoThey will allow registering without phone number as a paid option soon.
- johnnyApplePRNG 5d ago[flagged]
- Cider9986 4d ago> Lol how is that any better at all? They are [1] implementing unlinkable payments so all that is known by credit card is that you purchased Signal and Signal doesn't know which credit card goes with which account. >Signal is an obvious honeypot. Claims without evidence can be dismissed without evidence. You might say they don't do enough to protect metadata privacy but it was never made to be an anonymous messenger, it was made to be a private messenger. You can easily check the end-to-end encryption in the code (reproducible builds on all platforms except iOS BTW!). This person audited Signal recently [2]. >They make no money and have no plans to. They make money from donations and paid backups and they might make money from paid accounts. [1] https://github.com/signalapp/Signal-Android/commit/7da3357b564b1d8b522710b30afbce184137f65d https://github.com/signalapp/Signal-Android/commit/7da3357b5... [2] https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/#trademark https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...
- traceroute66 4d ago> registering without phone number as a paid option soon Replacing the need to register with a phone number with a requirement to pay is a better option how, exactly ?
- some_furry 4d agoIf your concern is "muh phone number", then you can pay and not have to give the phone number to sign up. It's already the case today (and has been for years) that you don't need to give strangers your phone number to chat on Signal. My username is soatok.45; try to get my phone number if you can. If you want absolutely no info to be collected, ever, and there to be zero cost on the end user too, be prepared to welcome your new spam overlords. Because the people who will benefit the most from a zero cost signup that only requires a username are spammers.
- my-huge-pony 4d agoI'm a bit surprised by this dismissal. Of course some info must be collected, or there must be some cost to enter (probably both I mean phone number is also a cost, but one most people already sunk). But we can still debate the best way, right? For example: * Are you absolutely positive signal will never have a bug that let attackers reveal contact phone numbers? I really trust in their secure coding skills, but this class of vulnerabilities (like 2fa leaj) happened to even the biggest players. * One of the reasons signal collects phone numbers (and asks for a contacts permission) is to check which contracts are already on signal. For some people or in some governments even having a signal account is an opsec problem (to be fair, they have a secure privacy-preserving protocol for this - as you know - and it's possible to avoid this footgun if necessary)
- thecrash 4d agoDecreases what info Signal needs to collect and retain about a user. When using an SMS verification as a proof, Signal needs to log the phone number, because if they didn't, one spammer could use one phone number to create 10^99 accounts. When using payment as proof, they can verify that payment occurred, validate the account and then immediately forget about the transaction. One spammer would still have to pay 10^99 times to create that many accounts.
- anigbrowl 4d agotwo weeks
- mmooss 5d agoSignal's mission is to provide maximized privacy in a form the non-technical public can use. A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number? Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.
- traceroute66 4d ago> What is a more private, usable solution for filtering them out than using a phone number? Since when is giving out your phone number a "more private" option ?
- tialaramex 4d agoYou don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people.
- traceroute66 4d ago> You don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people. You are deliberately missing the point. Signal are gatekeeping these new advanced security features behind a phone number wall (soon to become paywall if some posts here are to be believed).
- mmooss 4d agoIf it's not, let us know a solution (to Signal's actual problem as stated in the GP) that is more private.
- snackbroken 4d agoOne possible solution is to only be able to contact someone if you have received an invitation code from them out of band. E.g. "scan this QR code to add me on signal". Such an invitation code should default to single-use but users should be allowed to generate standing invitations so that businesses and the like can print and post one in their store or whatever. Start getting spam from one of your standing invitations? Just revoke it and make a new one. Presumably the Signal folks can come up with more alternative solutions than the half baked one I came up with after thinking about it for a minute, they're clever cookies.
- crossroadsguy 4d agoAnd apparently, just like Telegram, just like WhatsApp, they readily merge the username with your number if numbers are already saved.
- pseudohadamard 4d agoDitto for Trail of Bits, worked with them recently and they do some really impressive quality work, and have some very sharp guys working for them.
- johnnyApplePRNG 5d ago[flagged]
- evrimoztamur 5d agoYou commented this twice, what's your backing, besides 'they're non-commercial thus must be fed by nefarious actors'?
- stavros 5d agoI'm also worried about that these days. They posted an article a while back that Signal costs $50m per year to run, and that they make that money from "things". Together with how low a profile they keep, I'm not convinced they aren't a honeypot. I love Signal and it's still my preferred messenger, but if it came out that they're backed by some government agency, I wouldn't be extremely surprised.
- some_furry 4d ago> Together with how low a profile they keep, I'm not convinced they aren't a honeypot. You don't need to be convinced of such things. In fact, it's better if technical people remain skeptical and check. I did in 2025. https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/ https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...
- stavros 4d agoThis helps put my mind at ease, thanks.
- msdz 4d agoI and not necessarily many, but at least some people I know donate (and, somewhat irregularly, will continue to do so) small-ish amounts to the foundation. [1] You’d imagine that ought to be sufficient to cover running costs. However, it might actually not be enough with hardware prices these days? Not sure. They’ve also recently (edit: “recently-ish”, it’s actually been a year!) introduced paid storage for backups, which I’d imagine comes with some amount of profit margin, too. [2] [1] https://signal.org/donate/ https://signal.org/donate/ [2] https://signal.org/blog/introducing-secure-backups/ https://signal.org/blog/introducing-secure-backups/
- pizzaiolo 4d agoBit of a positive piece amid a negative headline this week: https://cybernews.com/privacy/police-telegram-whatsapp-signal-surveillance-linked-devices/ https://cybernews.com/privacy/police-telegram-whatsapp-signa...
- wolvoleo 4d agoThat requires access to the actual phone and the unlock code in the case of WhatsApp (you need to identify to add a WhatsApp web client). For telegram it's a bit easier yes, but the user can set up an additional password. I have done so of course. Note that telegram is not E2EE so they can give your stuff to the police at any time unlike WhatsApp and signal. For signal I don't know as I don't really use it but i understand it works the same way as WhatsApp, scan a QR code and authenticate to the phone. Also, with all 3 systems it's clearly visible when you look at the linked systems.
- xingped 4d agoIt is possible to intercept text messages and phone calls in such a way that the recipient never even knows a text message or phone call was sent to them in the first place. SMS is an extremely insecure channel for handling authentication codes. https://youtu.be/wVyu7NB7W6Y https://youtu.be/wVyu7NB7W6Y
- wolvoleo 4d agoYes I know but when you want to link a WhatsApp Web client to a phone with WhatsApp, SMS is not used. You need to scan a QR with the phone in question and sign in to the phone. SMS is used to register WhatsApp to a new phone, but that signs the original phone out. Also, you need the pin code that WhatsApp forces you to set. If you don't have it you have to wait a week if you got a recycled number. Also the original account holder is notified you tried it. So this method cannot be used by the police to snoop unnoticed. I believe signal works the same as WhatsApp here, it also forces you to set a pin now. For telegram this can be used yes but you can set an optional extra password. And also like I said telegram is not E2EE anyway so it's open to warrants.
- sage981 4d ago[flagged]
- csande17 4d agoYou're absolutely right! Let's delve deeper...
- iamshs 4d agoRecently a bureaucrat who wanted to make a mass protest out of his criticism of Indian Election Commission's drive to remove voters, was picked up by Indian Police and his Signal metadata was accessible to the Police. What is the solution to this thing? His interview does not tell us if it was metadata or actual calls that were surveilled which could point to device compromise too. "What caught him by surprise, he told ThePrint, was the Special Cell officers' access to his calls made via Signal" https://theprint.in/india/ex-civil-servant-ashish-joshi-recalls-delhi-police-interrogation-signal-calls-contacts-hm-hs-x-post/3034029/ https://theprint.in/india/ex-civil-servant-ashish-joshi-reca...