Skip to main content


Increasingly, @signalapp is being criticized by governments and users alike though the only successful compromises have been through bad actors being added to group chats accidentally.

Do NOT follow the narrative that you should move to another chat app if having life-or-death chats. Signal is the ONLY chat app with proper #security for those conversations: #PostQuantumEncryption, #PerfectForwardSecrecy, and a proven track record of privacy in court.

#activism #cybersecurity #InfoSec

reshared this

in reply to Seth G.

Take it from someone who has been in security for more than half his career:

1. Signal is not compromised.
2. Signal has flaws, but they do not affect its technical security.
3. Signal is THE app to use for critical situations.
4. Everyone should have a backup chat app, and we should be working on getting those apps to the same level of security (or better) as Signal.

But for now, USE SIGNAL FOR MISSION CRITICAL CONVERSATIONS. Don't be manipulated into leaving it for bullshit reasons!

This entry was edited (5 days ago)

reshared this

in reply to Seth G.

"proper security" depends on your thread model of course

might be something that you host yourself (XMPP or Matrix, heck… even "Synology Chat") might have "less secure" (on paper) clients, but since you're not relying on other peoples servers, you might be way less traceable on reality.

That alternate system might already be in place.

in reply to Cegorach

@dat @davidgerard For the example I gave, where it's life or death circumstances, and implying that the threat actor is a nation state, I stand by Signal being the only option. Anything that is weaker on paper can have the message transmissions captured and decrypted, whether now or in the future. Who hosts the servers does not matter if the servers (1)are not the target, (2)keep no message records, and (3)have no insight into message traffic even in real time.
in reply to Seth G.

@dat also, Signal is super usable including by abject non techies who just install the app. That bit is of towering importance. People can and will infosec mall ninja to their heart's content, but we're talking about real life danger to real non-techie users here.

reshared this

in reply to David Gerard

@dat my real world use case was the El Salvador bitcoin story, where the danger was sufficient that some of my contact have fled the country

of course El Salvador then used Pegasus on a pile of journalists, which fucks even Signal, and .sv is poor so getting a burner is expensive

nevertheless, Signal was absolutely up to the task of journalism in danger, 100% would recommend to everybody ('cos the bigger the network the better) as just a daily messenger

reshared this

in reply to David Gerard

@davidgerard @dat

Signal was absolutely up to the task of journalism in danger, 100% would recommend to everybody ('cos the bigger the network the better) as just a daily messenger


This is really critical. The privacy of Signal users is significantly enhanced by the fact that tens of millions of people are sending mundane traffic via the same servers. Doing traffic analysis on this is hard.

It's also helped by the fact that this includes the people using it for sensitive things. If you use Signal for talking to journalists and WhatsApp for talking to everyone else, it's easy for a passive adversary to see that you're doing something unusual.

reshared this

in reply to David Gerard

I never claimed "usability" of anything I listed would be good.

Yes, giving people that one piece of advice "use signal!" is way easier than to teach them how to get a decent XMPP-setup or how to run their own server.

I was only claiming: my thread model doesn't put my local government as the most important threat I have to defend against. I.E. defending against US services and companies sounds way more important to me.

Thus "download something from google" kinda sounds a stupid point to start with?

in reply to Cegorach

in practical real world terms, that's infosec mall ninja talk

> I never claimed "usability" of anything I listed would be good.

in context, this is a bizarre statement. Are you advising humans, or who are you advising?

anyone can define a perfectly spherical security system for use in a vacuum at absolute zero

i suggest everyone else Just Use Signal

This entry was edited (4 days ago)
in reply to Seth G.

That’s an extraordinary claim, which means it also requires extraordinary evidence.
in reply to Seth G.

@Seth G. @Signal Since you all went off-topic I want to have a serious talk about my Cat
⇧