Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Now we just need to drop the phone number requirements and signal would be "done" for all practical purposes


Phone numbers aren't required now. But there are flaws in Signal. Your phone usage can be tracked in high resolution through constant pinging of malformed status messages. I can't find the paper right now but researchers found that they could track their own data about when the phone was on, unlocked, and had Signal on the screen. That can be correlated between users, to see who is talking to who. It can be used to try to ambush you while the phone is unlocked. You don't even have to have a connection to the spies, if I remember right. Signal devs have done nothing about this issue since being notified like a year ago.

Edit: Found it! "Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers" https://arxiv.org/abs/2411.11194


> Phone numbers aren't required now.

Signal still requires a phone number for registration.


They also require running the app on a "real phone" for registration. Most emulators put you in captcha hell


Damn, what a shame... Another vote for Session, I guess. Idk what flaws that one has but it seems to be the leading alternative to Signal.


And you can use your Session ID to post or reply to posts at https://www.LokiList.com (best viewed with javascript disabled) for anonymous casual encounters.


Unfortunately...


For very limited practical purposes. Others would include proper multi device support




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: