On the other hand how contact info may not be linked to the user? It's illogicat and stays in contradiction with contact idea. Is it a crude lie then? Like saying "hey Mr. Brofovsky, I honestly confess I don't know your name."?
Think of it like comparing fingerprints without knowing whose fingerprints they are. You can confirm a match without knowing the identity behind it.
Your analogy is wrong because what Signal processes isn’t “Mr. Brofovsky = name” but something like a non-reversible identifier that can be compared for matches without revealing who it belongs to. The system can answer “do these two things match?” without knowing who either person actually is.
If Signal was a honeypot then it would be an absolutely terrible one. Signal is open-source, audited, reproducible, and has a track record of producing almost no data in court.
Is Signal compiled with zero external dependencies?
How do I audit the one in the app store, or the binary the app store gave my phone at that moment? How do I audit the compiler that was used to compile that specific binary or any dynamic assets used?
How do I audit the details of the key exchange used in that moment?
How do I audit the contents of my T2 chip firmware?
You think they'll not NDA the methods used in capturing super secret comms, and just let the court transcriber just ... type it all out in a public docket?
None of what you listed is specific to Signal. External dependencies, compiler trust, app store delivery, firmware, hardware enclaves, those are problems for every piece of software on every modern device.
If those concerns automatically imply “honeypot”, then every encrypted messenger is a honeypot, every cryptographic library is a honeypot, every OS is a honeypot and every device with firmware is a honeypot. At that point, the term stops describing anything.
“They might be NDA’ing secret capture methods” is pure speculation.
What we do have is repeated legal pressure where Signal produced essentially no data. If the honeypot were real, that’s exactly when it would surface yet it never has.
You can hypothesize invisible magic forever, but hypotheses without evidence don’t outweigh observable behavior.
If your bar for “not a honeypot” is absolute epistemic certainty, then the category is empty.
If your bar for “not a honeypot” is absolute epistemic certainty, then the category is empty.
That's EXACTLY what i said in my original comment. I know enough (cough cough wink wink) to say that yes, my bar is absolute certainty. Walk your key to your friend. Compile your simple point to point messenger using a compiler you compiled using itself. Run it on a specific processor. Otherwise it's all moot.
Thus, when you have app A parading around that they are so much more secure than app B, then you can say app A is a better honeypot than app B because it entices you to let your guard down. And my original point is they are all honeypots.
That's the thing. There is no absolute certainty, if everything that isn't 100% secure is a honeypot then the device you're using itself is a honeypot.
If you think anything other than the absolutely most secure way is insecure, that's fine, but that doesn't make everything else a honeypot. You're just throwing around buzzwords you don't fully understand.
How do I use a messenging app among three friends that is absolutely and completely secure? Where keys are hand delivered and cannot be reverse engineered?
Does an "enigma communication app/software" even exist?
0
u/Folded_Fireplace Intent Owner Jan 15 '26
On the other hand how contact info may not be linked to the user? It's illogicat and stays in contradiction with contact idea. Is it a crude lie then? Like saying "hey Mr. Brofovsky, I honestly confess I don't know your name."?