Hacker News new | ask | show | jobs
by BlueTemplar 2053 days ago
Signal is probably safe for the data[†], but as we know, the NSA cares even more about metadata – and since Signal's centralized servers are (all?) located in California…

[†] - then, considering stuff like this, even vetted open source code might be at risk (remember that the NSA can afford the best programmers in the world !) :

http://underhanded-c.org/

http://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-thom...

2 comments

If you're worried about metadata, then you're probably best off publishing encrypted gists. Yes you have to poll to get the update, but it's better than getting hit by timing analysis.
They don't care more about metadata, it easier for them to collect.