infosec.space is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for info/cyber security-minded people. This instance blocks threads.net

Administered by:

Server stats:

50
active users

@osman, no because @signalapp is a , , & solution that demands like for no valid reason, is subject to and only continues to exist because it's convenient as a means to fo and mark it's users as .

Public
Public

@osman If your , , and/or relies on @signalapp and/or @Mer__edith risking jail or worse [web.archive.org], you fucked up!

Seriously, to me stenches like & .

That's why I get people setup with it!

Twitterthaddeus e. grugq on Twitter“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”
Public

@kkarhan @osman @signalapp @ccc @monocles show me the part of the code where it's compromised to be used to mass surveillance

Public

@licho @osman provide evidence the code @signalapp released is actually being deployed.

Not to mention pushing a - () disqualifies per very design!
youtube.com/watch?v=tJoO2uWrX1M

  • Given the collection of like , the ability to restrict functionality based off those and the fact that is subject to make it inherently not trustworthy.

And don't even get me started on the fact.it's not sustainable to run it as a !

Same as identifying users: They already got a which in many juristictions one can't even obtain without legally, thus making it super easy to i.e. find and locate a user. Even tze cheapest LEAs can force their local M(V)NOs to a specific number...

  • All these are unnecessary risks, that could've been avoided, but explicitly don't even get remediated retroactively!

Again: Signal has a stench, and you better learn proper , and because corporations can't pull the 5th [Amendment] on your behalf! [web.archive.org]

Public

@kkarhan @osman @signalapp @monocles @fdroidorg

I'm totally with you on the mobile coin. I withdrawn my beta testing volunteering when they started it, warned friends who wanted to buy it by making a big analysis of the coin back in on my deleted now twitter - turned out i saved their asses.

However, I do think moxie has a point with the design choices he's made. Like using your real identity is no issue under the full zero knowledge e2e encryption. It supports the spread of encryption itself and normalizes being on signal. 10 years ago it was controversial to be there, I had to explain it to people, now even my grandma uses it.

Using phone numbers decouples your social network from the service. You OWN YOUR SOCIAL GRAPH. They don't capture your network effect this way - you always have a way to reconnect. I think it's a wise tradeoff. Signal works very well for everyday people. The fact you have to KYC your number when buying is irrelevant to the threat model considered.

IIRC Signal has reproducible builds
github.com/signalapp/Signal-An

But I indeed think they can easily take it down. That's no good therefore I advocate having multiple ways of communicating.

GitHubSignal-Android/reproducible-builds/README.md at main · signalapp/Signal-AndroidA private messenger for Android. Contribute to signalapp/Signal-Android development by creating an account on GitHub.