You didn't describe anything. You think you know how Signal works but you really don't and you're throwing around wild accusations, probably to spread FUD thus driving people to less secure options. Do your homework, come back when you know some things?

Reply to this note

Please Login to reply.

Discussion

Wow, you're just doubling down with the personal attacks instead of simply proving me wrong.

All you have to do is explain how Signal sends an SMS to allow users to recover from a lost phone when Signal supposedly doesn't have access to anyone's phone number.

Feel free to reference the code if you'd like. I've did security audits on the library, Android and desktop apps years ago. But if the Signal developers added code to send an SMS to an encrypted phone number, I'm sure the crytographers of the world would love to see it.

You do realize that the only reason Signal added usernames in the first place was because of privacy advocates like myself calling them out on it, right?

It took many years before they finally added usernames, and their system is better because of it. Now the same privacy advocates are calling for them to finish the job and removing phone numbers entirely.

Many of us also feel like Signal should move away from centralization, allow the 100% open source version of their app to be published in the official F-droid repos, and a number of other improvements.