• Kairos
        link
        fedilink
        -415 hours ago

        Signal does not know who talks to whom. It’s kind of the main thing about the double ratchet.

        • ☆ Yσɠƚԋσʂ ☆OP
          link
          fedilink
          23 hours ago

          You sign up to use Signal using your phone number which is a personally identifying piece of information. Signal clients send messages to the server that routes the messages to their destination. It is not a p2p system where clients talk directly to each other. Therefore, the server must know both the sending and receiving accounts for the messages it routes, and it has the phone numbers associated with this accounts. All these things together make it trivial for the server to know which phone numbers talk to each other.

        • @[email protected]
          link
          fedilink
          English
          413 hours ago

          Unless you compiled the app yourself from source code that you understand, you don’t really know what the app might be saying to Signal’s servers. Almost everyone just trusts that the pre-compiled app supplied by Apple or Google aren’t compromised. But we know from history that Big Tech and the military-intelligence-industrial complex are in bed with each other.

          • Kairos
            link
            fedilink
            -113 hours ago

            Okay. You tell me what the double ratchet is, since you’re so smart.

              • Kairos
                link
                fedilink
                -213 hours ago

                Compiling the app is irrelevant if I don’t read the source.

                • ☆ Yσɠƚԋσʂ ☆OP
                  link
                  fedilink
                  212 hours ago

                  That’s nonsense, because many different people read the source and audit open source software. While it’s certainly possible to sneak malicious code in, the trust doesn’t depend on each single individual auditing it. It’s a collective effort.