Signal has so many red flags. You are required to have a phone number which is essentially ur real identity. They now have payments linked to real identities so much better. They used to federate with 3rd party servers but they killed that and all but wiped it from the internet. They try to shut down 3rd party clients. They don’t provide reproducible builds so we can’t trust the source. They received their initial funding from In-Q-Tel the CIA venture capital firm.
Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.
At minimum they have a full social graph of real identities with time-stamped message events. Sealed sender doesn’t negate this as signal knows ur ip address when u give them a message. They also know the destination of that message as that isn’t sealed. This is sufficient information to link sender and recipient and timestamp. That’s assuming the unreproducible builds don’t have backdoors.
It’s all got a slightly fishy smell to it.
Tldr: If u want actual secure messaging u should consider SimpleX
I’ve said it before and I’ll say it again:
Signal has so many red flags. You are required to have a phone number which is essentially ur real identity. They now have payments linked to real identities so much better. They used to federate with 3rd party servers but they killed that and all but wiped it from the internet. They try to shut down 3rd party clients. They don’t provide reproducible builds so we can’t trust the source. They received their initial funding from In-Q-Tel the CIA venture capital firm.
Every time someone tries to raise any of these issues they are immediately shut down and told that its all for a good reason and that we should trust it.
At minimum they have a full social graph of real identities with time-stamped message events. Sealed sender doesn’t negate this as signal knows ur ip address when u give them a message. They also know the destination of that message as that isn’t sealed. This is sufficient information to link sender and recipient and timestamp. That’s assuming the unreproducible builds don’t have backdoors.
It’s all got a slightly fishy smell to it.
Tldr: If u want actual secure messaging u should consider SimpleX