logoalt Hacker News

tptacektoday at 2:44 PM4 repliesview on HN

If you have real operational security concerns, your provider shouldn't know anything about you; should in fact have bilateral shielding between themselves and you to prevent either counterparty from learning stuff. That's how Signal works.


Replies

AnonCtoday at 5:06 PM

But Signal requires a working phone number for registration and it knows the phone number. The backend could be modified at any time to store this somewhere else while maintaining end to end encryption between the two parties communicating on it. How can Signal prove continuously that it doesn’t store or disseminate the phone number? I know in past precedent it has told courts that it only has very limited information (date of account creation and the last time of account access).

show 1 reply
inigyoutoday at 4:44 PM

Impossible for a public thing though, noblogs.org will always be traceable to where noblogs.org is hosted because that's how the packets get there.

You can maintain much better opsec in a two way communication than a broadcast.

show 1 reply
jijijijijtoday at 5:29 PM

This is about finances. If the US declares you a terrorist organization, you cannot do any banking anymore, even outside the US, since most banks do not want to gamble on SWIFT access.

Since the US considers anything "antifa" as terrorism now, it already had most concerning distant effects last year. See GLS bank cancelling Rote Hilfe in Germany. 1933 was the last time Rote Hilfe was cancelled, btw. It's an antifa OG. Pretty good indicator about the status quo..

Anyway, look at e.g. GrapheneOS, which is already treated as probable cause by law enforcement. Encrypted messaging also super sus. Thing is, funding can't escape jurisdictions. Signal servers are not running on love and fellowship, but donations and public money. Opsec won't protect your software stack's foundation against US finance attacks.

show 1 reply
redsocksfan45today at 6:05 PM

[dead]