44
submitted 1 year ago by Albin9326@kerala.party to c/privacy@lemmy.ml
you are viewing a single comment's thread
view the rest of the comments
[-] akilou@sh.itjust.works 2 points 1 year ago

Signal doesn't keep metadata at all.

[-] cypherpunks@lemmy.ml 2 points 1 year ago* (last edited 1 year ago)

They say that they don't, and I think it is extremely likely that Signal employees are entirely sincere when they say that.

But, even if they truly don't keep metadata, they can't actually know what their hosting provider (Amazon) is doing. And, their cryptographic "sealed sender" thing doesn't really solve the problem. If someone with the right access at Amazon really wants the Signal metadata, they can get it, and if they can, anybody who can coerce, compel, or otherwise compromise those people (or their computers) can get it too.

One can say they're confident that the kind of adversaries they care to protect against don't have that kind of capability, but it isn't reasonable to say that Signal's no-logging policy protects metadata without adding the caveat that routing all the traffic through Amazon makes the metadata of the protocol's entire userbase available in a single place for the kind of adversaries that do.

[-] akilou@sh.itjust.works 1 points 1 year ago
[-] cypherpunks@lemmy.ml 1 points 1 year ago
[-] akilou@sh.itjust.works 2 points 1 year ago

If someone with the right access at Amazon really wants the Signal metadata, they can get it,

[-] cypherpunks@lemmy.ml 1 points 1 year ago

What stops them from being able to? They could actually infer a lot of the metadata just from the encrypted network traffic, without even looking inside the VMs at their execution state. But, they can also see inside, so they can keep the kind of logs (outside the VM) which Signal [says that they] wouldn't.

this post was submitted on 02 Oct 2023
44 points (75.0% liked)

Privacy

31379 readers
203 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS