• @[email protected]
    link
    fedilink
    1
    edit-2
    3 months ago

    I agree with you but I think that signal was built as to not trust the server either way.

    • poVoqM
      link
      fedilink
      33 months ago

      That’s what they like you to think yes. But it is only the message content and not the various forms of metadata that is protected by their encryption scheme.

      • @doodledup
        link
        1
        edit-2
        3 months ago

        It’s also the metadata. Profile and contact discovery is also private. I don’t think they have anything except your IP.

        • poVoqM
          link
          fedilink
          13 months ago

          Seal sender is a nice idea, but since you can easily run timing attacks on centralised infrastructure it is pointless for Signal, or rather you have to trust them that their infrastructure is not compromised.

          They also store device ids for push notifications via Google/Apple.