Does signal have a back door?

Reply to this note

Please Login to reply.

Discussion

👀

Not that I'm aware of, and I follow that topic pretty closely. The Signal protocol is the gold standard of messaging encryption, and the whole point is that the encrypted content can only be viewed by the conversation participants. Aside from Signal, the Signal protocol (double-ratchet) is used in many other secure messengers, including SimpleX, and the Nostr-based Keychat. It's fully open source, and has gone through multiple independent security audits. If there was a backdoor, it would have been exposed by now given all the independent eyes that have poured over the code, and the seperate cryptographic audits it has gone through.

i would assume that anyone who's gotten their signal "hacked" actually had their device compromised (pegasus, etc.), rather than the signal app itself

That's a good assumption. If Signal was hacked, it would be on the front page of every tech journal and news outlet because journalists use Signal extensively to have private conversations with sources, and receive anonymous tips.

Even if it isn't backdoored right now, that doesn't mean MFers won't push an OTA update that is. If the US gov presses them hard enough, they'll implement it or risk legal action.

Use Molly. Meta data is Signal's backdoor.

Never heard of it

Molly is a client that's based on the Signal client, but has some additional security features. It uses the Signal servers and is fully interoperable with Signal. So, you can talk to Signal users.

Metadata isn't a backdoor. You can't just redefine words when it's convenient. That said, I definitely agree about using Molly as it has some significant security upgrades, including full-time database encryption. Molly is a superior client.

Single client + single relay = single point of failure at any point now or in the future

This is why I like #SimpleX

nostr:nevent1qqsrce04vzyc22cpdy93y4effx9al70cvxenucnrlfqs4c7tdv99kpqpz9mhxue69uhkummnw3ezuamfdejj7q3qr0rs5q2gk0e3dk3nlc7gnu378ec6cnlenqp8a3cjhyzu6f8k5sgsxpqqqqqqz9cfkqn

Not that I have heard, but it’s a centralized, closed-source system. It can be hard to tell. Have you heard anything?

No way to know for sure. But ATT no indications that there is.