I don’t know if I’m opening a can of worms here, and I’m still trying to backtrack a lot of history where I was tuning everything out. I keep seeing random swipes at Signal (or the representatives (?)), and I was wondering whether they are founded or just lies.Is it another situation like Lemmy where we just “take the technology and move on”? Thanks!

    • jetA
      link
      fedilink
      English
      arrow-up
      18
      arrow-down
      1
      ·
      1 month ago

      Both on device and in the cloud.

      https://signal.org/blog/secure-value-recovery/

      That is why when you switch phones and register again with signal using your “pin”, you can send messages to your contacts without your verification number changing.

      • kitnaht@lemmy.world
        link
        fedilink
        arrow-up
        20
        ·
        1 month ago

        https://github.com/signalapp/SecureValueRecovery2

        The method has changed since that blog post.

        So you are correct about it being stored in the cloud - they also seem to take much better care of it there, but when it’s on someone elses server, your point stands - they can SAY they do anything. There’s no way to actually test that. So thanks for the correction.

        • jetA
          link
          fedilink
          English
          arrow-up
          12
          ·
          edit-2
          1 month ago

          Anytime, I love it when lemmy is a collaborative space!

        • jetA
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          1 month ago

          Yup, it was really big news and everyone was up in arms when they introduced SVR.

          You can “opt out” in the settings, your key is still stored in the cloud but with a random BIP32 encoding or somesuch, still not a great practice, and whoever you talk to probably didn’t opt out.

          Signal is better then non e2e messengers, but its not the best architecture we could have. If your ok with Intel, and the Signal foundation being in a position to handover your keys to a TLA who then would have the capability to decrypt your messages - then its fine. So sexting is fine, probably prevents business intelligence, but if I was negotiating a MX US trade deal, I wouldn’t use signal to talk about my strategy.

          If your running a government communication system, 1,2,3 (But especially point 2) - mean you can’t use signal.