this post was submitted on 10 Nov 2023
110 points (93.0% liked)

Technology

59428 readers
3132 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

It seems useless to me, at least regarding the cybersecurity aspect. Of course, it's helpful when people ask for my contact information, and I don't want to share my phone number or email address.

But they still require information that could be used to prove or be linked to my identity for registration, right? This means a hacker could still reveal your IP address, phone number, email, and your passcode. Likewise, the development team can access these as well.

I know I'm overly cautious about my privacy, but that's just how I am.

you are viewing a single comment's thread
view the rest of the comments
[–] MondayToFriday@lemmy.ca 14 points 1 year ago (1 children)

All the personal information you mentioned should be hashed or encrypted. For any given phone number, see how little information they have: just an account creation timestamp and a last access timestamp.

[–] online@lemmy.ml 4 points 1 year ago (1 children)

There's so much FUD about Signal it's ridiculous. I'm starting to believe those glowie memes are true it's just the "lol like I'd ever trust Signal!!!" folks who I think might be the glowies. 🫣🫣🫣

spoiler(No I don't actually believe they're glowies lol).

[–] bamboo@lemm.ee 2 points 1 year ago (1 children)

My main complaint is that they officially prohibit 3rd party clients including 3rd party builds of their official ones. They also don’t have reproducible builds for their clients. It leaves the door wide open for inserting some telemetry via an update to completely bypass their otherwise good encryption and (lack of) data retention.

[–] ForgotAboutDre@lemmy.world 1 points 1 year ago (1 children)

Would allowing third parties access to their server API just cause spammers to flood signal users.

[–] bamboo@lemm.ee 4 points 1 year ago

They can already do that. You can make custom clients that pretend to be the real one, it’s just against their terms of service. Spammers generally don’t care about the ToS though, so it’s just legitimate users that are affected.