cross-posted from : https://lemmy.zip/post/71321898
Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance


There are all of these stories about signal because it is notable when someone gets around it
That there’s anything approaching secure communication on a cell-phone dominated Internet whose.operating systems are either “snobbish walled garden” or “ad agency living in the corpse of a search engine” is astonishing. In the same way that a gun safety that keeps a toddler from shooting themselves with an otherwise loaded gun is astonishing.
can’t get around simplex encryption unless you have physical access to the device or have been physically invited by a member.
You… didn’t read the article did you… that’s literally what happened here lol
lol
it’s literally a quote in the post. physical access was only one way they accessed messages.
That’s not the point I was trying to make. You are acting like simplex is better than signal because it requires physical access… that’s how it works for signal as well…that was the point…
breaking the encryption is hard , but getting around the encryption is entirely doable without physical access if you allow SMS or on-device sharing.
Ok so no better than Signal?
You can do all the same things and use Tor, allow Sealed sender, and rotate username with phone number hidden.
Why does Simplex want investors?
what company doesn’t want to grow or maintain services? they host the primary servers that everyone uses, that costs money.
you could host your own though. can you do that with signal?
If I only want to talk to my own group of people registered on my server yes
https://github.com/signalapp/Signal-Server
as I pointed out in your other comment. signal uses a database, fails to explain why a database is required, and doesn’t even make a mention of it in their technical information.
why use a database at all? that just introduces more attack surface area and complexity for attackers to leverage.
Yeah precisely you didn’t check what it’s for. It doesn’t hold conversation data or even metadata.
what 👏 is 👏 it 👏 used 👏 for
Not to quote myself but:
You should trust signal tree the same way you trust a front door lock that has never been broken or picked despite repeated attempts to do both.
.Just remember that police only go through the door when it’s easier than breaking a window or tearing through a wall.
The US government has openly stated they killed people because of metadata and ur comfortable just giving that all away? U also didn’t address any of my precise exact points you simply made a vague deflection.
Signal doesn’t reveal that kind of metadata.
All ur messages have a recipient address. All ur messages go though signal servers. You have an IP address that u communicate to said servers with. They know when and who you are messaging.
Signal supports Tor.
They have features like Sealed Sender, which is at least on par with the multiple server behavior of Simplex as it behaves the same (message passing multiple servers, carrying no sender origin data in plaintext)
Simplex knows the same thing. The pairwise identifiers is a sham - all your different identifiers point to the same Android/iOS notification server API key so they know the recipient is the same person, they can tell which exact phone receives a notification when somebody sends you a message (unless the devs use anonymized fetch on a polling schedule, which they don’t).
And because they don’t hide those sender stamps, Simplex leak more info than Signal with Sealed sender
Why is Simplex asking for investors?
Are Simplex even considering notification content security?