this post was submitted on 19 Jul 2025
262 points (93.7% liked)

Technology

73209 readers
3981 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] jet@hackertalks.com 1 points 2 days ago* (last edited 2 days ago)

Consider that your the french intelligence services and you need to setup secure communication for the french government.

  • Would you use signal out of the box? Clearly not.
  • Would you copy signal and setup your own servers and clients, same source, different end-points? Probably not.

If you said yes to either of the above, what if you were not a ally of the US, maybe Russia, China, DPRK.... Does that change your answer?

What capabilities does the runner of a centralized service have?

  • See all traffic
  • Can block traffic
  • Can slow traffic
  • Can record all traffic
  • Timing analysis of metadata

Does this mean Signal is a bad product? No not at all. But it does mean its very well positioned for intelligence harvesting. Add in storing private encryption keys in the cloud SVR relying on intel SGX security... and well... you get everything even decrypted messages.

The US controls Signal, the US controls Intel - Thus the US can get any code they want signed into SGX enclaves, thus the enclaves are pointless if your threat model includes the US as a adversary

Does this mean the protocol should be thrown away? No. Does this mean Signal shouldn't be used (depends on use case)? No. Signal has value, but its not the ultimate form of privacy and security.

I support projects like Briar because there is till much improvement needed in this space.

Notice: I'm not telling others to "educate yourself", if I didn't want to talk to people I wouldn't be here, or I'd link to the proper discussion. I dislike people who come to social places and act antisocially