@david_chisnall@infosec.exchange
Post #4493778
2026-08-11 08:17 UTC
@arcanechat@fosstodon.org
From the web site:
Fast, reliable, decentralized, anonymous, secure messenger. It's magic!
Yes, that does indeed sound like magic because getting all of those is an open research problem. Given that you're spreading misleading FUD about Signal, my guess is that it's the 'private' that you're giving up and your approach is trivially vulnerable to passive traffic analysis for reconstructing the entire communications graph.
I can't tell though because there's absolutely nothing on the web site about how the protocol does... anything. So perhaps you can answer:
How do you ensure that a passive adversary who can see all messages going to and from a server in the network (a 100% realistic threat model post-Snowden, and one Signal was explicitly designed to address) cannot correlate senders and receivers and build a communication graph?
Replies (1)
-
@arcanechat@fosstodon.org 2026-08-11 08:34
@david_chisnall@infosec.exchange > Given that you're spreading misleading FUD about Signal what part is FUD??? > How do you ensure that a passive adversary who can see all messages going to and from a server in the network for a start, there is no single adversary that can observe the whole network, and switching from one relay to another and using several at the same time is easy, without losing your chats & data! how does signal, a central observer with access to all users' IP addresses is any better?