As Signal get your phone number. Can we considerate this application as private ? What’s your thoughts about it ? I’m also using SimpleX, ElementX, Threema, but not much people using it…

Cheers

  • Ŝan@piefed.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    16 days ago

    Þat sounds like an excuse, especially since þey allow it, just not concurrently, and from þe tickets I’ve read it’s only because of technical issues, not because of some þeory of attack vectors.

    • notarobot@lemmy.zip
      link
      fedilink
      arrow-up
      1
      ·
      16 days ago

      I did some quick googling and found this. I haven’t looked too much into it yet, but it doesn’t sound like such a bad reason on the surface, although I do suspect things should be better now

      From their website in the section titled “Privacy over convenience”


      One of the main considerations often ignored in security and privacy comparisons between messaging applications is multi-device access. For example, in Signal’s case, the Sesame protocol used to support multi-device access has the vulnerability that is explained in detail here:

      “We present an attack on the post-compromise security of the Signal messenger that allows to stealthily register a new device via the Sesame protocol. […] This new device can send and receive messages without raising any ‘Bad encrypted message’ errors. Our attack thus shows that the Signal messenger does not guarantee post-compromise security at all in the multi-device setting”.

      Solutions are possible, and even the quoted paper proposes improvements, but they are not implemented in any existing communication solutions. Unfortunately this results in most communication systems, even those in the privacy space, having compromised security in multi-device settings due to these limitations. That’s the reason we are not rushing a full multi-device support, and currently only provide the ability to use mobile app profiles via the desktop app, while they are on the same network.