Discussion about this post

User's avatar
Michael Ginsburg's avatar

You have a gift Gabriel! Outstanding work!!

Regarding Signal, beyond the (very warranted in my opinion) concerns about the composition of their board and funding by entities affiliated with the US government, the sign-up process and the use of phone numbers is an easily exploitable attack vector, especially due to their reliance on a third party for that (Twilio):

https://thehackernews.com/2022/08/nearly-1900-signal-messenger-accounts.html

This is obviously not an issue unique to Signal but there are other IMs where said attack vector is simply not present (by design!). Session is one such example but there are others.

Does Delta Chat use phone numbers as unique identifiers for user accounts similar to what Telegram itself does?

Expand full comment
Mathew Crawford's avatar

There are some brilliant flawed people. McAfee may have been one of those.

One thing I tell people is that even if Langley has a way to watch every communication, most of it is impersonal and if they encrypt, then at least the neighbor's bored fourteen year old isn't listening. That's not nothing.

Expand full comment
13 more comments...

No posts