Amethyst Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
adbenitez@lemmy.ml to Privacy@lemmy.dbzer0.comEnglish · 4 months ago

Signal has no known/published real security audit?

message-square
message-square
9
link
fedilink
17
message-square

Signal has no known/published real security audit?

adbenitez@lemmy.ml to Privacy@lemmy.dbzer0.comEnglish · 4 months ago
message-square
9
link
fedilink

Someone made a compilation of academic reviews and blogposts here: https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243 but none of them seem to be real security audit reports, ex. compare with real security audits to Delta Chat: https://delta.chat/en/help#security-audits

alert-triangle
You must log in or # to comment.
  • Telorand@reddthat.com
    link
    fedilink
    arrow-up
    23
    ·
    4 months ago

    You can always look at their history “complying” to government orders to hand over user data.

    https://signal.org/bigbrother/

    No company is going to break the law for you, so live tests seem about as good as a security audit.

    • adbenitez@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      4 months ago

      You can always look at their history “complying” to government orders to hand over user data.

      IIRC by US law they are not allowed to disclose requests from US gov itself

      so live tests seem about as good as a security audit.

      I would rather prefer real security audits

      • Telorand@reddthat.com
        link
        fedilink
        arrow-up
        4
        ·
        4 months ago

        A security audit would be great, but their most recent request was from Santa Clara county, and several previous ones are also from US jurisdictions. You can read about the content of what they were able to provide to the courts.

        They’re obviously private. And if you’re concerned about the app, use the fork Molly.

        I guess I don’t see what more a security audit would reveal that we couldn’t deduce by examining the code or real-life examples.

      • EngineerGaming@feddit.nl
        link
        fedilink
        arrow-up
        4
        ·
        edit-2
        1 month ago

        deleted by creator

        • ERROR: Earth.exe has crashed@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 months ago

          If you and your contacts are all Android, you can Use Briar. It has no central servers and all traffic go through Tor. Open Source and on Fdroid and recommended by privacyguides.org

          • EngineerGaming@feddit.nl
            link
            fedilink
            arrow-up
            5
            ·
            edit-2
            1 month ago

            deleted by creator

      • Telorand@reddthat.com
        link
        fedilink
        arrow-up
        2
        ·
        4 months ago

        deleted by creator

      • Coldmoon@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 months ago

        I only talk quietly in loud rooms, can’t trust Signal.

        • ERROR: Earth.exe has crashed@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 months ago

          I only talk a mixture of Cantonese Mandarin and English in the Style of Shakespeare

  • 🇦🇺𝕄𝕦𝕟𝕥𝕖𝕕𝕔𝕣𝕠𝕔𝕠𝕕𝕚𝕝𝕖@lemm.eeBanned from community
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    3
    ·
    4 months ago

    Signal is a little sus. We should be applying pressure for them to allow federation. They don’t wanna remove the phone number requirement cos spam sure let everyone else we handle that u keep doing your thing with phone numbers and allow us to do ours and still communicate.

    • MTK@lemmy.world
      link
      fedilink
      arrow-up
      12
      arrow-down
      1
      ·
      4 months ago

      That is kind of naive.

      “Allow federation” it’s not a simpke switch, it’s probably a full project of it’s own, and if they only hace X resources for development, taking on a big project like federation might just not be a priority.

      • adbenitez@lemmy.mlOP
        link
        fedilink
        English
        arrow-up
        7
        arrow-down
        1
        ·
        edit-2
        4 months ago

        yet the reason that “Signal is expensive” https://signal.org/blog/signal-is-expensive/ is because they didn’t go for a federated approach, they spend more money just to keep the servers running than resources spent on development

        • EngineerGaming@feddit.nl
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          1 month ago

          deleted by creator

        • quickenparalysespunk@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          1
          ·
          4 months ago

          deleted by creator

Privacy@lemmy.dbzer0.com

privacy@lemmy.dbzer0.com

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !privacy@lemmy.dbzer0.com

Welcome! This is a community for all those who are interested in protecting their privacy.

Rules

PS: Don’t be a smartass and try to game the system, we’ll know if you’re breaking the rules when we see it!

  1. Be civil and no prejudice
  2. Don’t promote big-tech software
  3. No apathy and defeatism for privacy (i.e. “They already have my data, why bother?”)
  4. No reposting of news that was already posted
  5. No crypto, blockchain, NFTs
  6. No Xitter links (if absolutely necessary, use xcancel)

Related communities:

Some of these are only vaguely related, but great communities.

  • !opensource@programming.dev
  • !selfhosting@slrpnk.net / !selfhosted@lemmy.world
  • !piracy@lemmy.dbzer0.com
  • !drm@lemmy.dbzer0.com
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 197 users / day
  • 2.24K users / week
  • 4.24K users / month
  • 7.55K users / 6 months
  • 1 local subscriber
  • 2.97K subscribers
  • 486 Posts
  • 3.71K Comments
  • Modlog
  • mods:
  • fxomt@lemmy.dbzer0.com
  • Otter@lemmy.ca
  • shaytan@lemmy.dbzer0.com
  • fxomt@piefed.social
  • BE: 0.19.12
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org