Even State Department-funded Human Rights Watch admits that authorities combine legal and illegal methods to obtain convictions: https://text.hrw.org/report/2018/01/09/dark-side/secret-origins-evidence-us-criminal-cases
Combining dragnet surveillance with device hacking is intended in the design of both tools. Hence, State Department-funded Signal dupes you into handing over your identity as part of the population-centric mapping. In custody, your phone will be hacked when it is taken away if it’s important.
https://xcancel.com/hannahcrileyy/status/2034273723667161480#m
Jitsi, Jami, and Simplex are all, I believe, peer-to-peer and don’t require you to trust an intermediary.
Love simplex, also good if you have children and they have a tablet but not a phone
Jitsu requires authentication from big tech companies now, or at least person hosting call.
Wut
Thank you for pointing that out, It’s been awhile since I’ve used Jitsi. I’m currently using Jami and liking it.
Some people are very protective of Signal.
- Reason: Disinformation
- Reason: privacy rule #3: “Try to keep things on topic”
- Reason: Misinfo, alarmism
- Reason: This is harmful disinformation
Oh well if Dessalines says so it must be true
It’s davel
The essay being linked to was posted (authored?) by dessalines from lemmy.ml
You may have missed the sarcasm.
Privacy is proof of terrorism. The state, and it’s corporate allies, need to have access to your innermost thoughts, the things about you even you don’t know, for national security reasons. This is totally normal and not something to resist. Vote republican.
The Prairieland case was an important case for the capitalist state of US Imperialism. It was a litmus test, a threat, to all people who dare criticize and challenge its rule within the belly of the beast. Just like the Iran war, which is about control over the region, and beating back any neo-colonial governments who don’t fall in line with the wishes of US Imperialism….this is the US government waging similar class war at home.
The places tyrants can’t see into is where the threats come from.
worn black to a protest
used Signal
carried a first aid kit
lol

The laws are made up and we’ve always been fucked. We always knew that
Consider prison an organizing opportunity
every goth tech nurse is a terrorist
Everyone should just wear all blue or some other colour
One reason to use Matrix on your own server.
Via a domain which you have to register with even more personal data.
Njalla
TL;DR:
Njalla (Swedish pronunciation: [ˈnjala]) is an anonymous domain name registrar, hosting provider and VPN provider, established by The Pirate Bay co-founder Peter Sunde.
It is not a domain registrar, they literally say it in their FAQ.
You do not own the domain then either.
All of my domains are .eu and are hosted in Europe and are under European GDPR rights.
What evidence do you have that Signal collects anything? Traffic logs from the app or something?
It uses a phone number.
Phone numbers havent been required for at least like a year or so
Hm now I wonder what to do about that, as they have had my number for a while now.
That isn’t true. You still need a phone number to sign up.
Do they let you sign up purely with username and password? Or do they make you use insecure email?
You can check if a number is registered with Signal just by having Signal and starting a chat with that number
Even if the number is set as hidden in settings?
No, idk wth they’re talking abt
They changed that. You can make yourself undiscoverable by just the number now
This is as shady as Telegram to me tbqh
Signal doesn’t need to, you need to trust the whole chain. You’ll need to trust AWS, you need to trust Intel SGX, etc
The phrase “E2E encryption” definitionally means it applies when you don’t trust whole chain.
At that point you can rely on nothing but Tor or I2P
Nothing else hides metadata better than Signal, without involving large networks of independent nodes that participate in Sybil resistant routing. The only thing that gets close is threshold schemes where you still need multiple independent entities running servers.
Helping an old grandma up, is cause enough for execution by ICE on the spot.
In custody, your phone will be hacked when it is taken away if it’s important.
Unless I turned off the USB port…
I wouldn’t bet my life on GrapheneOS in person despite being a fan of the project due to wanting to treat my phone as a computer
*actually forgot to mention they charged the duress password guy with destruction of evidence this isn’t speculative at all lmao
personally, my bet is that they don’t have anyone qualified enough to pull off an exploit like that (on me).
the problem with my bet: what we’ve seen is that they won’t care, and accuse individuals of terrorism based off the color of their clothes.
I just refuse to believe Google doesn’t have some kind of hardware backdoor, or that Motorola won’t once that is up and running.
hardware vulnerabilities undoubtedly exist, whether intentional or not. its simply the nature of designing these complex semiconductors.
that said, if one company intentionally creates a backdoor, won’t they all? what phone do you buy at that point?
any startup or small phone company may not have intentional backdoors, but I can guarantee their hardware security on all other levels pales to what apple and google can accomplish. I think the question then becomes are you more worried about google having a backdoor, or about third party compromises?
im not a fan of our choices, there is no silver bullet.
It’s about knowing that any phone can have a backdoor and being careful on how you use it. Don’t bring your phone to a protest.
Yeah tails does have graphene beat, but a lot of folks see a phone as a necessity. Graphene is best if you’re gonna have a phone. It can turn off the USB port where it can’t even be charged without being off. It can reboot itself if not unlocked frequently enough, putting the phone back into a BFU state.
Now it’s possible that there’s some exploit a state knows that is not public, but the software they generally use does not work on graphene as long as you are not running a pre-2022 version of graphene. Someone else mentioned rubber-hose cryptanalysis, but like if I’m getting beat for my unlock, then what do I care about getting charged with destruction of evidence?
They can turn it back on. Or they can apply some rubber-hose cryptanalysis.
I really don’t get the big “use signal” push at this point in time because even if it’s private and the encryption is solid, it’s a fucking American company. It’s so easy for letter agencies to get information on their users from them, don’t you realize that they can’t refuse to give out your number if they ask for it and that once they have that your identity and location are immediately and thoroughly compromised? If you are subject to US jurisdiction and could be seen in any way as opposing its government, I really don’t think you should be using it.
i’m convinced the big push for signal is a CIA op. not that it’s necessarily signal’s fault, it could be and it could not, but setting signal as the defacto private alternative is weird.
better than whatsapp at least i guess, but that’s a low ass bar to clear.
We know it’s an op, RFA does damage control for signal:
Libby Liu, president of Radio Free Asia stated:
Our primary interest is to make sure the extended OTF network and the Internet Freedom community are not spooked by the [Yasha Levine’s critical] article (no pun intended). Fortunately all the major players in the community are together in Valencia this week - and report out from there indicates they remain comfortable with OTF/RFA.
Because its one of the only popular secure methods of communication thats app based.
All giving out your number provides is that you have ever used Signal.
They’re saying ever using a private chat service is terrorism. That’s not really on Signal.
All your phone number provides is that you have ever used signal? Not what tower you’re connected to and therefore approximate realtime location? Your full identity via your telco? Social graph and history of your calls and texts?
I’m not saying it’s their fault or that they are volunteering any information, but that’s how it is for any US-based corporation (doesn’t matter if it’s a nonprofit, any legal entity that can be subpoenaed)
The government already has access to every phone number in existence. They can already track every phone to figure out who attended a protest or whatever. Filtering down to “all phone numbers who’ve ever connected to Signal” doesn’t exactly narrow anything down. They don’t have any metadata about who you were chatting with.
government already has access to every phone number in existence
that’s precisely why you should not trust services that require it as private. phone number = identification.
plus apparently you government considers you a terrorist if you do.
The government already has access to every phone number in existence
They used to publish them in big books, even
This is fundamentally not how Signal works, but you are generally correct in that a phone number has been shown to provide a lot of context for a person (or a device, at least). But Signal (the app) only uses a phone number for initial verification of an account. You have a lot of options to break that association with you - use a landline and get a call verification code, use a VoIP number (assuming you trust the provider), use a burner SIM, etc.
Once you have an account, you can choose to identify yourself on the network solely via username so the registration number is not presented to other users. The Signal protocol itself is well-audited and generally secure.
If your issue is with Signal the American company, use an open source fork like Molly with your own UnifiedPush instance. Then you’re only trusting them with transport of your encrypted messages, which again have shown to be secure at least in public audits.
it all does not matter when most people register with their primary phone number that is already tied to their name
I still don’t get it. What is bad about signing up with your phone number? All readable Info that governments can force out of Signal is. “Yep this guy uses Signal, signed up last year” so nothing is lost (except if they use that as a sign you are a terrorist, but then they just wanted to monitor you anyway in the first place)
except if they use that as a sign you are a terrorist, but then they just wanted to monitor you anyway in the first place
exactly. what is the question?
also its not “monitor me” and “monitor you”, but “monitor whoever is using the service” more closely, and as it seems, retaliate against them.
The question is: What privacy do I loose by signing up to Signal with a phone number instead of hypothetically a username.
If you are being monitored, they know your phone number. With that they know you are using Signal, but nothing more. Messaging through Signal is safe.
If you are not being monitored, nobody knows you are using Signal. Messaging through Signal is safe
If the only data surfacable from Signal is the phone number, not the crypto conversation, they didn’t source you on signal and get your number, they got your number through other means and used it to prove you use signal.
They can’t see the conversation to contents to supoena the number to id.
It’s not a company it’s a nonprofit foundation. And they’ve been audited many times by independent auditors.
Sorry but both points are irrelevant, nonprofit foundations can still be forced to turn over user information. That is part of following the law so nothing that would need to be hidden to auditors, unless you were talking about encryption audits which is completely besides the point
What data is there for Signal to turn over? Can you prove that they’re keeping messages or logs on their servers that have ‘disappeared’ from all the associated devices?
the irrededeemable fact that you are using it, which matters because the government now just targets all the signal users. they can’t read your messages, so they are applying guilt by association.
Your entire social network graphs, and timestamped message history.
No one can “prove” signal doesn’t store everything. If you give me ssh access to their server, then I can verify. Otherwise it’s “just trust me bro”.
If you give me ssh access to their server, then I can verify. Otherwise it’s “just trust me bro”.
What do you think an independent autit does?
But not the messages, and that’s basically all that matters
LOL no is not.
Its the largest part that matters, because if they don’t have that, they cannot secretly snoop into everyone’s plans (and share that info with ice/dns/etc.)
The audits determined they don’t have any user information to provide. You can see this in previous government requests where the only thing provided was a timestamp of last connection to the network.
and the phone number, which is clearly user information, now being used against the users
Because the other options most people are aware of are by and large even worse? Would you prefer people were sending this shit over Facebook messenger?
A reminder that your phone number is metadata. And people who think metadata is “just” data or that cross-referencing is some kind of sci-fi nonsense, are fundamentally misunderstanding how modern surveillance works.
By requiring phone numbers, Signal, despite its good encryption, inherently builds a social graph. The server operators, or anyone who gets that data, can see a map of who is talking to whom. The content is secure, but the connections are not.
Being able to map out who talks to whom is incredibly valuable. A three-letter agency can take the map of connections and overlay it with all the other data they vacuum up from other sources, such as location data, purchase histories, social media activity. If you become a “person of interest” for any reason, they instantly have your entire social circle mapped out.
Worse, the act of seeking out encrypted communication is itself a red flag. It’s a perfect filter: “Show me everyone paranoid enough to use crypto.” You’re basically raising your hand.
So, in a twisted way, Signal being a tool for private conversations, makes it a perfect machine for mapping associations and identifying targets. The fact that it operates using a centralized server located in the US should worry people far more than it seems to.
The kicker is that thanks to gag orders, companies are legally forbidden from telling you if the feds come knocking for this data. So even if Signal’s intentions are pure, we’d never know how the data it collects is being used. The potential for abuse is baked right into the phone-number requirement.
In theory warrant canaries could have been used, but Marlinspike has an excuse for everything.
yeah that makes the whole thing even more sketch, I love how he never replies to the EFF link too
We’re supposed to take privacy advice from someone posting on X?
Lol this looks like the regular X app to you does it?
The domain of the person’s handle is literally “x.com”
Surprised that they didn’t link straight to Telegram.
- How does it feel to be on my nuts? 2. I get Telegram channels through RSS and let you work out the rest. I will if I want to.
Were you to be so lucky.
More anti-signal propaganda? Who is claiming it can’t be associated to a user. The messages are private, not anonymous.
It does use deniable encryption, but that stops working as a defense the second they take your phone and copy all logs from your device.
And large group chats relies on how well you can vet participants more than it relies on encryption itself, and if they’re too large they may as well not be encrypted.
Orgs in my town have seen this first-hand. People are out here learning secure comm practices the hard way.
That’s what Molly is for, right?
And graphene




















