How Trail of Bits helps verify the integrity of Signal chats

(blog.trailofbits.com)

19 points | by dgroshev 8 hours ago

2 comments

  • chews 1 hour ago
    I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.
    • ortekk 1 hour ago
      They will allow registering without phone number as a paid option soon.
    • mmooss 38 minutes ago
      Signal's mission is to provide maximized privacy in a form the non-technical public can use.

      A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?

      Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.

  • johnnyApplePRNG 1 hour ago
    [flagged]
    • evrimoztamur 1 hour ago
      You commented this twice, what's your backing, besides 'they're non-commercial thus must be fed by nefarious actors'?
      • stavros 1 hour ago
        I'm also worried about that these days. They posted an article a while back that Signal costs $50m per year to run, and that they make that money from "things". Together with how low a profile they keep, I'm not convinced they aren't a honeypot.

        I love Signal and it's still my preferred messenger, but if it came out that they're backed by some government agency, I wouldn't be extremely surprised.