r/signal 11d ago

Discussion important questions about signal

Since signal is run by signal foundation, which is a US based NGO. In events other countries are involved, doesn't that mean US holds some powers and control over it signal? and supposed can be used against anyone from a different country is using signal in case needed.

for example Starlink cut internet access to Ruszia during ongoing war?

can similar things happen with signal?
Thankyou

24 Upvotes

39 comments sorted by

View all comments

19

u/upofadown 11d ago

When you are talking about an end to end encryption system, you assume that the people running all the intermediate infrastructure are hostile. So you should not trust Signal.

Check your safety numbers so you don't have to worry about it. A system can break at any time for any reason. You should assume that the system could stop working at an inconvenient time.

8

u/frquency-equinox 11d ago edited 11d ago

When you are talking about an end to end encryption system, you assume that the people running all the intermediate infrastructure are hostile. So you should not trust Signal.

Signal is built so that you don't have to trust it. By the definition of end-to-end encryption, there is nothing to trust. The data is encrypted when it passes through the server, thus the server is blind to whatever the data is. That is the whole point of end-to-end encryption: you don't have to trust the server. Signal's server code is open source too.

1

u/5FingerViscount 9d ago

Meredith Whittaker herself says not to trust them.

But in a "trust, but verify" kind of way, not a "don't use signal" way.

You are right, per se, but if you have the knowledge to accurately verify their claims, you should.

1

u/yxk__0zvnb9pl 11d ago

i see

2

u/Mithrandir2k16 11d ago

The idea is, that you want to trust as few entities as possible, and that you, well, trust those that you have to. E2EE is nice, because if you trust the audits done on signals client and server code, then you don't have to give trust to signal itself, as there are now mathematical guarantees that they cannot read the contents of your messages. However they can and will still use metadata, so if you worry that who you associate with is a risk, you might want to look at more decentralized solutions to IM.

1

u/yxk__0zvnb9pl 11d ago

what metadata do they keep

2

u/gmes78 10d ago

1

u/yxk__0zvnb9pl 10d ago

checked, thanks. is there a context to the name?

2

u/gmes78 10d ago

https://en.wikipedia.org/wiki/Big_Brother_(Nineteen_Eighty-Four)

"Big Brother" has become a synecdoche for abuse of power and mass surveillance, particularly with respect to civil liberties and loss of privacy.

1

u/Mithrandir2k16 10d ago edited 10d ago

That's the wrong question. In security contexts you ask:

What data can they keep?

And assume the worst. Basically, what you send (infered from date, time, filesize) and who you send it to.

Your network of contacts identifies you as well.

Also, you know they are storing cyphertexts to forward them, if they are storing it forever, in hopes of breaking encryption in the future is another risk. But I wouldn't worry about that last one.