Elektrine lite

← Feed

@apftwb@lemmy.world

Post #1285751

2026-04-09 17:52 UTC

I am no Android developer, but can’t the push notification payload be encrypted? firebase.google.com/docs/…/encryption A better question is if Signal does this already.

Replies (3)

  • @bearboiblake@pawb.social 2026-04-09 19:09

    So it’ll use TLS encryption, meaning that others on your network won’t be able to snoop it, but not end-to-end encryption, so Google/Apple servers will see the plaintext of the push notification content. This is a limitation of the specific implementation of how push notifications work. End-to-end encrypted push notifications would be technically possible but it would require Apple/Google to make it possible. Developers can’t implement it without getting you to run some services yourself, either self-hosted or a long-running background process on your phone, which would be a battery drain. The link you shared isn’t really relevant to push notifications specifically. The best happy medium we can get is to send empty/blank push notifications, which some apps including Signal offer as an option, but you often need to set it that way in the settings. I think Signal does that by default, but very few apps do.

    Open ##1285747

  • @bjoern_tantau@swg-empire.de 2026-04-09 18:45

    Signal doesn't send anything in the payload. They just use it to wake the phone up and then download all messages that are waiting to be delivered through the usual encrypted means. All Google knows is that something happened at that time. They don't know anything else.

    Open ##2489460

  • @lemonuri@infosec.pub 2026-04-09 18:32

    No, push always leaks metadata to Google. Use molly (signal fork on fdroid) and unified push instead.

    Open ##2489461