

They made the prices so insane that most 3rd party apps couldn’t justify the higher subscription price
Cryptography nerd
Fediverse accounts;
@Natanael@slrpnk.net (main)
@Natanael@infosec.pub
@Natanael@lemmy.zip
Bluesky: natanael.bsky.social


They made the prices so insane that most 3rd party apps couldn’t justify the higher subscription price


It does use deniable encryption, but that stops working as a defense the second they take your phone and copy all logs from your device.
And large group chats relies on how well you can vet participants more than it relies on encryption itself, and if they’re too large they may as well not be encrypted.


They changed that. You can make yourself undiscoverable by just the number now


At that point you can rely on nothing but Tor or I2P
Nothing else hides metadata better than Signal, without involving large networks of independent nodes that participate in Sybil resistant routing. The only thing that gets close is threshold schemes where you still need multiple independent entities running servers.


What evidence do you have that Signal collects anything? Traffic logs from the app or something?
Not a fan of the marketing speak on that page, as a cryptography nerd there’s a lot of questionable stuff.
SAS authentication is stone cold dead in the LLM age. P2P with friends is trivially trackable by the ISP and can easily map who knows who. ECDSA isn’t “industry leading”, that would be EdDSA or something based on Risetto, or a pq algorithm like ML-DSA
Depends on how repressive.
Often your main method of staying safe is appearing harmless.
You can find dedicated Mastodon and lemmy hosts more receptive to VPN users.
Anonymous use is hard due to stuff like timing attacks and writing style recognition, etc, especially if you post publicly. You want to mimic another style, for example. And create plausible deniability around timings (like say scheduled posts)
Some people can only see linear grey scales