Post #3145171
2025-01-21 22:40 UTC
Replies (5)
-
@rysiek@mstdn.social 2025-01-21 22:43
I'd like to hear what @signalapp@mastodon.world has to say about all this. There is a claimed response from Signal in that gist file, but I'd like to see it come directly from Signal before I form an opinion.
-
@nblr@chaos.social 2025-01-21 22:48
@rysiek@mstdn.social Which is why my expectation until now was that they just simply don't outsource that. And if they did, that they made sure that it passes a basic laugh-test. But to use clownflare? And declare it to be out of scope because it is "up to users to hide their identity" (from a company that hard-verifies your phone number no less!) wtaf. But eh... one trust-us-pinkie-promise-company hand in hand with another pinkie-promise-company. Very entertaining, from an outside perspective 🍿
-
@tyil@fedi.tyil.nl 2025-01-22 08:51
@rysiek@mstdn.social CDNs confirmed once more to be a liability if anything. Stop using garbage like Cloudflare, stuff like this keeps happening. Its a shame that Signal uses it and doesn't see an issue.
-
@SoniEx2@chaos.social 2025-01-22 12:06
@rysiek@mstdn.social this would work even without the cache status in the response. you can infer the status from latency observations.
-
@jrconlin@mindof.jrconlin.com 2025-01-22 17:30
@rysiek@mstdn.social I'll also note that apps don't have to use CDNs for images and thus could get REALLY, REALLY specific information about your location. The fact that CDNs are prevalent is a privacy feature. Of course, any app on your device of choice could report all sorts of information about your device and you. Use a web version when you can. They're not perfect, by any stretch, but it requires more effort and devs are lazy.