cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 hours ago

          Signal supports Tor.

          They have features like Sealed Sender, which is at least on par with the multiple server behavior of Simplex as it behaves the same (message passing multiple servers, carrying no sender origin data in plaintext)

          Simplex knows the same thing. The pairwise identifiers is a sham - all your different identifiers point to the same Android/iOS notification server API key so they know the recipient is the same person, they can tell which exact phone receives a notification when somebody sends you a message (unless the devs use anonymized fetch on a polling schedule, which they don’t).

          And because they don’t hide those sender stamps, Simplex leak more info than Signal with Sealed sender

          Why is Simplex asking for investors?

          Are Simplex even considering notification content security?