We believe that the key encapsulation mechanism we have selected, CRYSTALS-Kyber, is built on solid foundations, but to be safe we do not want to simply replace our existing elliptic curve cryptography foundations with a post-quantum public key cryptosystem. Instead, we are augmenting our existing cryptosystems such that an attacker must break both systems in order to compute the keys protecting people’s communications.

Our new protocol is already supported in the latest versions of Signal’s client applications and is in use for chats initiated after both sides of the chat are using the latest Signal software. In the coming months (after sufficient time has passed for everyone using Signal to update), we will disable X3DH for new chats and require PQXDH for all new chats. In parallel, we will roll out software updates to upgrade existing chats to this new protocol.

    • @sudneo
      link
      198 months ago

      Many people also fail to make a proper distinction between private and anonymous, which is why some people get mad at the phone number thing.

    • Obinice
      link
      28 months ago

      Ah, yes, I’m not giving an instant messenger application my phone number, it doesn’t need it, especially if I’m not even using it on a phone.

      That’s private information that I only give out to close friends and family members.

    • @[email protected]
      link
      fedilink
      -18 months ago

      The phone number thing is a major problem but Signal just has the momentum imo. Ultimately, they’re gonna need to fix it or we’re all going to have to stop using it.

        • @[email protected]
          link
          fedilink
          18 months ago

          Anonymity is good but that’s not the biggest problem with Signal’s reliance on phone numbers. Phone numbers are just not secure and not designed to be authentication credentials. Phone services are vulnerable to a large number of exploits and that’s never going to change. Signal has a number of mitigations to try preventing those exploits from hitting people but that’s a bandage at best. Reliance on phone numbers is a gigantic weak point in Signal’s privacy and security.