Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
evacide
@evacide@hachyderm.io  ·  activity timestamp 4 days ago

The primary advantage of using Signal over WhatsApp is that Signal does not store metadata. Just sayin'.

https://www.forbes.com/sites/the-wiretap/2025/10/21/ice-spies-on-whatsapp/

Forbes

How ICE Spies On WhatsApp

ICE’s HSI division gets contacts from the WhatsApp account of a fake ID dealer and has little trouble identifying them, according to warrant.
  • Copy link
  • Flag this post
  • Block
josh buermann
@buermann@mastodon.social replied  ·  activity timestamp 3 days ago

@evacide

Sharing any data with Zuckerberg's genocide wurlitzer is a danger to your community.

  • Copy link
  • Flag this comment
  • Block
http :verified:
@http@infosec.exchange replied  ·  activity timestamp 3 days ago

@evacide Many people in the reply are criticizing Signal. It's one of the best encrypted messengers available and recommended for everyone. But it's rightfully criticized for requiring a phone number and being US-based. The protocol is the same as WhatsApp, so a malicious government could make it silently behave like WhatsApp and suddenly store metadata like in the article. Nobody can guarantee that this does not happen. I personally like Threema, where you don't require a phone number to register. It also has good e2e encryption, but I'd wish they used the Signal protocol. The biggest risk is probably that the adversary gets a hold of the phone of your communication partner, having access to all decrypted messages. There it doesn't matter what messenger app you use.

  • Copy link
  • Flag this comment
  • Block
Sahil? 🇵🇸
@kq@ieji.de replied  ·  activity timestamp 4 days ago

@evacide @starraven do you guys have alternatives that you'd suggest?

  • Copy link
  • Flag this comment
  • Block
:startrek: Ted
@LGS@friendsofdesoto.social replied  ·  activity timestamp 4 days ago

@evacide I am using signal but thinking of switching to matrix. Does that make sense?

  • Copy link
  • Flag this comment
  • Block
Mikalai
@mikalai@privacysafe.social replied  ·  activity timestamp 4 days ago

@evacide
The next preference is to have a tech that sends no metadata in client-server communication.

  • Copy link
  • Flag this comment
  • Block
Syl ⏚
@kodr@piaille.fr replied  ·  activity timestamp 4 days ago

@evacide it would be nice if Signal would delete messages when you are kicked from a group. How to circumvent cops looking at your phone?

https://community.signalusers.org/t/delete-message-history-from-a-group-members-device-when-a-group-member-is-removed/71647

  • Copy link
  • Flag this comment
  • Block
Thomas Traynor
@thomastraynor@social.linux.pizza replied  ·  activity timestamp 4 days ago

@evacide and I do not use biometrics to unlock my device.

  • Copy link
  • Flag this comment
  • Block
Misuse Case
@MisuseCase@twit.social replied  ·  activity timestamp 4 days ago

@evacide RIP your mentions because you’re talking about Signal and Mastodon is full of some weird, aggro nerds.

  • Copy link
  • Flag this comment
  • Block
Hans-Cees 🌳🌳🤢🦋🐈🐈🍋🍋🐝🐜
@hanscees@ieji.de replied  ·  activity timestamp 4 days ago

@evacide @Herman I was able to possibly identify the majority of the people with whom Ayala was communicating with on WhatsApp during this small time frame,” an HSI agent wrote in the warrant. (Meta hadn't commented at the time of publication.)

  • Copy link
  • Flag this comment
  • Block
Travis F W
@travisfw@fosstodon.org replied  ·  activity timestamp 4 days ago

@hanscees @evacide @Herman this is the kind of thing I don't boost because my followers almost certainly knew it before I did

  • Copy link
  • Flag this comment
  • Block
uebelhacker
@uebelhacker@social.tchncs.de replied  ·  activity timestamp 4 days ago

@evacide and then it's only a tiny step from #signal to #molly

https://molly.im/
@mollyim

  • Copy link
  • Flag this comment
  • Block
MinameH❇️
@Miname@det.social replied  ·  activity timestamp 4 days ago

@evacide as if u would reach anyone here who doesn't already agree with u thinking_pug

  • Copy link
  • Flag this comment
  • Block
KawaiiPunk
@kawaiipunk@sunbeam.city replied  ·  activity timestamp 4 days ago

@evacide https://www.whatsapp.com/records/login https://faq.whatsapp.com/444002211197967/
https://faq.whatsapp.com/808280033839222/?locale=en_US

They actually have good docs on all this data sharing. Interesting that a user's Address Book is on there.

  • Copy link
  • Flag this comment
  • Block
Fazal Majid
@fazalmajid@social.vivaldi.net replied  ·  activity timestamp 4 days ago

@evacide as a US-based corporation, Signal is just as vulnerable to pen register warrants as WhatsApp, the saving grace is Signal’s Sealed Sender feature that WhatsApp doesn’t have. Sealed Sender makes it hard to reverse the identity of the correspondent, but if the pen register also has the IP address and the sender doesn’t use Tor, they can still be identified that way.

  • Copy link
  • Flag this comment
  • Block
Ville 'cos' R
@cos@sauna.social replied  ·  activity timestamp 4 days ago

@evacide nope, Signal is centralized and they do get lot of useful metadata (at least who messaged who and user's identities via phone numbers).
It's trust based if they store or sell this data.

Also it being open source is questionable, as ~100% of users run a binary build with google libraries embedded. You won't find Signal in F-Droid or Debian repositories like proper open source alternatives.

As lot of users already commented, use decentralized or p2p messengers if you need hard privacy.

But don't get me wrong, it's much better alternative than WhatsApp or other fully closed and centralized apps.

  • Copy link
  • Flag this comment
  • Block
Crampi
@crampi@eldritch.cafe replied  ·  activity timestamp 4 days ago

@evacide can we just skip the part where Signal corp gets inevitably controlled by the US government and go straight to using decentralized messengers instead ? Like @delta

  • Copy link
  • Flag this comment
  • Block
billy joe bowers-8647
@billyjoebowers@mastodon.online replied  ·  activity timestamp 4 days ago

@evacide

A bunch of accounts with few followers and not a lot of activity posting anti Signal messages.

Not saying they're absolutely wrong, or ill intentioned, just noticing a pattern.

  • Copy link
  • Flag this comment
  • Block
Multimilliardaire
@multimilliardaire@piaille.fr replied  ·  activity timestamp 4 days ago

@evacide @opiobf

The main disadvantage of using #Signal is that it is provided by a centralized corporation, with all associated risks.

Free Libre & distributed peer-to-peer has always been far better (but most people are amnesiac).

Is it the right time to remind that this is even one of the fundamentals of Internet design?

  • Copy link
  • Flag this comment
  • Block
Magical Cat
@koteisaev@mastodon.online replied  ·  activity timestamp 4 days ago

@evacide Among SimpleX Chat, I am not very aware of other metadata-protecting messengers. But I guess other exist, so who aware, drop links/names please.

  • Copy link
  • Flag this comment
  • Block
Tinkerer
@tinkerer@ieji.de replied  ·  activity timestamp 4 days ago

@evacide Also opensource and has reproducible builds for Android.

  • Copy link
  • Flag this comment
  • Block
endif
@balasubramanium@social.linux.pizza replied  ·  activity timestamp 4 days ago

@evacide signal is literally whatsapp 2.0 given its servers are in the US and accessible by the NSA.

  • Copy link
  • Flag this comment
  • Block
evacide
@evacide@hachyderm.io replied  ·  activity timestamp 4 days ago

@balasubramanium Congratulations. This is the stupidest thing I have read today.

  • Copy link
  • Flag this comment
  • Block
Gabriel ⛺💤
@me@m.geno.is replied  ·  activity timestamp 4 days ago

@evacide @balasubramanium But more seriously; Was it the "Push" system that was exploited for both WhatsApp and Signal ?

https://www.documentcloud.org/documents/24191267-wyden_smartphone_push_notification_surveillance_letter_to_doj_-_signed/

https://unifiedpush.org/news/20250513_push_security_privacy/

UnifiedPush

Push notifications, security and privacy

Published the 14/05/2025 21/05/2025 Edit: Add list of applications without encryption. How secure is UnifiedPush? It’s a legitimate question that comes up from time to time. While the question is fairly short, the answer requires a few details. Behind the question of security, it’s also often about privacy. Security and privacy When we talk about the security of a protocol, software or hardware, we mean the ability to prevent unauthorized access. We generally evaluate security in terms of the ability to preserve the confidentiality, integrity and availability of a system. In other words, we want to be sure that an unauthorized actor cannot read our data, modify it or render our system inaccessible. Other aspects may also be taken into account, such as the ability of an unauthorized actor to increase our bill for a service.
https://www.documentcloud.org

Wyden letter to Department of Justice regarding smartphone push notification surveillance

This is a Dec. 6, 2023 letter from Oregon Senator Ron Wyden asking the Department of Justice to lift any existing restrictions around discussions of push notification surveillance.
  • Copy link
  • Flag this comment
  • Block
D1re_W0lf ⁂
@d1re_w0lf@mstdn.social replied  ·  activity timestamp 4 days ago

@evacide @balasubramanium I don’t know about your timeline but here isn’t even daylight. So give it time. 🙄😑

  • Copy link
  • Flag this comment
  • Block
Starraven
@starraven@mastodon.scot replied  ·  activity timestamp 4 days ago

@evacide @balasubramanium

Your comment is the stupidest thing I've read. He is absolutely right. Signal is rife with security threats, starting with the fact it is US based and requires a phone number.

  • Copy link
  • Flag this comment
  • Block
Eka A.
@Eka_FOOF_A@spacey.space replied  ·  activity timestamp 4 days ago

@evacide
That meta data ties you to others... Maybe enough to get a warrant.

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login