• 8 Posts
  • 439 Comments
Joined 2 years ago
cake
Cake day: April 27th, 2024

help-circle



















  • I think the text is somewhat dubious in its arguments, but this (and the arguments built on this assertion) is just plain wrong:

    [Signals servers have] a few important pieces of data;

    Message dates and times Message senders and recipients (via phone number identifiers)

    Signal clients implement the Pond protocol. As a result, Signals servers know who a message is for (obviously, how else do you get the message) but cannot know who it is FROM.

    I’ve been playing around with implementing a secure/private messenger demo for myself, and have been consistently impressed with how privacy preserving Signal is when reading their papers and code. I wish it was selfhostable, but apart from that, it’s great.

    The server would be NICE to be OSS, but ultimately, privacy breaches are prevented client/protocol side.