Post #4493779
2026-08-11 07:52 UTC
Replies (1)
-
@david_chisnall@infosec.exchange 2026-08-11 08:17
@arcanechat@fosstodon.org From the web site: Fast, reliable, decentralized, anonymous, secure messenger. It's magic! Yes, that does indeed sound like magic because getting all of those is an open research problem. Given that you're spreading misleading FUD about Signal, my guess is that it's the 'private' that you're giving up and your approach is trivially vulnerable to passive traffic analysis for reconstructing the entire communications graph. I can't tell though because there's absolutely nothing on the web site about how the protocol does... anything. So perhaps you can answer: How do you ensure that a passive adversary who can see all messages going to and from a server in the network (a 100% realistic threat model post-Snowden, and one Signal was explicitly designed to address) cannot correlate senders and receivers and build a communication graph?