IE like Crypto AG:

In 2020, it was revealed that the Swiss company, Crypto AG, which provided secure communications services to ~120 governments throughout the 20th century, was secretly ran by the CIA and West German Intelligence. The CIA and later NSA were able to read encrypted communications for many countries such as Saudi Arabia, Iran, Italy, Indonesia, Iraq, Libya, Jordan and South Korea.

  • SteleTrovilo@beehaw.org
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    It’s funny how every poster who criticizes Signal inevitably makes a technical error. In your case, the claim that “Basically if you are an organizer, criminal, government, part of a hunted opposition, you will leak the whole core group structure of your org with attached phone numbers” entirely lacks basis. The Signal client - the OSS part we can and do control - does not divulge phone numbers.

    You have this theory that Signal’s servers are storing communication records. (While there is no evidence to support this, it’s valuable to consider what they could do.) So the data that would be captured here is a network of hashed phone numbers and literally undecryptable messages. It’s impossible for the adversary to determine any phone numbers they don’t already know this way.

    And since you can make a Signal account with a burner phone and create a “username”, even a known phone number becomes useless against targets who don’t want to be identified.

    • Dessalines@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      2 months ago

      All speculation. You gave them your phone number (which also means your real identity), so you should assume they have it. And because its a US-based company, it must adhere to US laws including key disclosure laws, which make it illegal for any signal employee to tell you that any US government agency has asked for this information.

      https://en.wikipedia.org/wiki/National_security_letter

      So the data that would be captured here is a network of hashed phone numbers and literally undecryptable messages

      With this data you can build social networking graphs: who is talking to who, and when.

      Also this is all the more suspect when you consider that US military / government agencies like OTF fund signal, and constantly try to push signal in privacy spaces.

      • Moovau@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        2 months ago

        They could pull a Lavabit if presented with gag order, but of course, no way to know for sure how they would react.