|
|
|
|
|
by jmnicolas
1625 days ago
|
|
Thanks for the laugh, you should write news title it would be fun! Anyway the problem of Signal is that you have to use your phone number and a phone number is a much stronger link to you than an ip for example. As the ex boss of NSA said "We Kill People Based on Metadata". |
|
The NSA may "kill people based on metadata" but XMPP produces far more metadata for such decisions than Signal.
XMPP encourages people to build clique servers, which fail a key security requirement "Don't Stand Out". The six other users of "Bob's 100% Preparedness Militia and True Patriots Server" may be quite sure Bob is trustworthy and won't rat on them, and maybe one of them only uses it to post funny GIFs of cats, but the loose metadata association between this group and a plot to kidnap a State Senator means all seven of them are targets anyway.
But if you try not to stand out by using a popular server, that server's operators have far more insight into you than Signal's server operators do. Remember, when my friend Steve sent me a Signal message last week, Signal does not know who sent that. I know, because I decrypted the message, but Signal does not. That's a bunch of heavy cryptographic lifting, but from their point of view it was worth it to improve privacy.