• ArchAengelus@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    11
    ·
    2 months ago

    No matter how good the protocol or client encryption, your privacy is only as good as your own physical security for the device in question.

    Given that if you lose your private key, there is no recovery, I would be surprised if there were real back doors in the clients. Maybe unintentional ways to leak data, but you can go look for yourself: https://github.com/signalapp/Signal-Android

    They have one for each client.

    • heavyboots@lemmy.ml
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 months ago

      As an example of this, I believe SexyCyborg got in trouble for reporting on leaks via people’s 3rd party Chinese language keyboards. So her theory is that the keyboard apps people had installed leaked data when Hong Kong protesters were communicating with the press, rather than the actual Signal app. But… as stated above, people have to take responsibility for their device and in this case, they had chosen to install apps with leak issues into the communication process.

      • socsa@piefed.social
        link
        fedilink
        arrow-up
        7
        ·
        2 months ago

        This is precisely why opsec is more than just an app.

        Leaky keyboards are a possibility, but what is actually far more likely is just that someone on the signal group chat was a mole who was archiving the traffic for the party. Signal has since made efforts to bring anonymous accounts to the platform, which will help thwart such attacks. Though against a state actor it is still not enough unless you take additional measures to obfuscate traffic. And then that still doesn’t protect you against some CCP brownshirt from tailing you and then snatching your phone out of your hand when you unlock it.

        • milicent_bystandr
          link
          fedilink
          arrow-up
          4
          ·
          2 months ago

          Leaky keyboards are more than a possibility. Sogou, the biggest one for Chinese typing, got found out a year or so ago for having terrible client-server encryption. They fixed it in an update, but many people didn’t get the update - not to mention it’s still sending every keystroke to Tencent (are the owners I think?) so they could also be saving and analysing private typing anyway.

    • TCB13@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 months ago

      Maybe unintentional ways to leak data,

      Yeah, that’s what I think it may be. Just like Apple reporting on all apps you open on un-encrypted HTTP calls and a few other things.

      • sunzu2@thebrainbin.org
        link
        fedilink
        arrow-up
        3
        arrow-down
        1
        ·
        2 months ago

        are you talking about phone notification bullshit and google got caught reporting to government with no warrants.

        • ArchAengelus@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          3
          ·
          2 months ago

          Signal’s defaults are pretty good about that. Push notifications are both opt-in and the information they send can be selected by the user. You can have it say “new message” and that’s it. Or the senders name. Or the whole message.

          I agree that it’s not intuitive that that’s a leak to most people, but push notifications are kind of wonky how they work.

          • sunzu2@thebrainbin.org
            link
            fedilink
            arrow-up
            1
            ·
            2 months ago

            signal is all around very strong… my main criticism is the “trust signal bro” cult pretending like Signal would not log chats if ordered by the spooks. which is naive AF and feels like they are trying to make normeis comfortable so they don’t demand better.