Tbf, can’t the other party mess it up with signal too?
Yes, but this is where threat modeling comes into play. Grossly simplified, developing a threat model means to assess what sort of attackers you reasonably expect to make an attempt on you. For some people, their greatest concern is their conservative parents finding out that they’re on birth control. For others, they might be a journalist trying to maintain confidentiality of an informant from a rogue sheriff’s department in rural America. Yet others face the risk of a nation-state’s intelligence service trying to find their location while in exile.
For each of these users, they have different potential attackers. And Signal is well suited for the first two, and only alright against the third. After all, if the CIA or Mossad is following someone around IRL, there are other ways to crack their communications.
What Signal specifically offers is confidentiality in transit, meaning that all ISPs, WiFi networks, CDNs, VPNs, script skiddies with Wireshark, and network admins in the path of a Signal convo cannot see the contents of those messages.
Can the messages be captured at the endpoints? Yes! Someone could be standing right behind you, taking photos of your screen. Can the size or metadata of each message reveal the type of message (eg text, photo, video)? Yes, but that’s akin to feeling the shape of an envelope. Only through additional context can the contents be known (eg a parcel in the shape of a guitar case).
Signal also benefits from the network effect, because someone trying to get away from an abusive SO has plausible deniability if they download Signal on their phone (“all my friends are on Signal” or “the doctor said it’s more secure than email”). Or a whistleblower can send a message to a journalist that included their Signal username in a printed newspaper. The best place to hide a tree is in a forest. We protect us.
My main issue for signal is (mostly iPhone users) download it “just for protests” (ffs) and then delete it, but don’t relinquish their acct, so when I text them using signal it dies in limbo as they either deleted the app or never check it and don’t allow notifs
Alas, this is an issue with all messaging apps, if people delete the app without closing their account. I’m not sure if there’s anything Signal can do about this, but the base guarantees still hold: either the message is securely delivered to their app, or it never gets seen. But the confidentiality should always be maintained.
I’m glossing over a lot of cryptographic guarantees, but for one-to-one or small-group private messaging, Signal is the best mainstream app at the moment. For secure group messaging, like organizing hundreds of people for a protest, that is still up for grabs, because even if an app was 100% secure, any one of those persons can leak the message to an attacker. More participants means more potential for leaks.
Concrete example of threat modeling: if someone found out I was using Signal, for any reason at all, would that cause problems for me?
If yes, then Signal is not a good option. If no, then Signal may be appropriate. Why? Because in their documentation, they explicitly state that while messages are confidential, the fact that you’re using Signal cannot be hidden, and so they don’t make that guarantee.
Yes, but this is where threat modeling comes into play.
Right,:
If you need nation-state level secrecy, rule #1 is don’t associate with idiots who can’t be bothered with at least the most basic opsec. I shouldn’t talk to this motherfucker at all were that my case, or at least not digitally. Thankfully at worst we talk about me middlemanning him some weed, and even local PD dgaf.
Though btw speaking of:
Can the size or metadata
Plenty of people have been drone striked (struck?) simply because the metadata said they were talking to the wrong guy. Frankly if you need that high of a level of secrecy, you’d be better served using tails/tor, or hell even snail mail with false return addr and a book cipher. But for:
all ISPs, WiFi networks, CDNs, VPNs, script skiddies with Wireshark, and network admins in the path
Then frankly either signal or jabber+encryption (or for that matter, simplex, briar, yadda yadda) should be fine.
Signal also benefits from the network effect, because someone trying to get away from an abusive SO has plausible deniability if they download Signal on their phone (“all my friends are on Signal” or “the doctor said it’s more secure than email”)
But then again, it’s more likely to be known as an encrypted chat which may be a problem for them, while the abusive SO might just think XMPP is some outdated IM they know what signal is, and “my friends” can use jabber just the same as signal.
Alas, this is an issue with all messaging apps, if people delete the app without closing their account
Except not. XMPP not being tied to a phone number, if my buddy Steve deletes Conversations, while I may not be able to message him on jabber I can fall back on text. However (and again maybe now this is fixed), on signal if he deletes the app, I can no longer signal message him, nor can I SMS him because they get lost in limbo as signal messages, I’d have to email or use XMPP to get him to redownload signal, delete it properly, and THEN I can SMS him again. (Maybe no longer now that “no sms,” but also “no sms now but still give us your phone number” don’t sit right with me.)
I do, but idk how that effects that problem since I stopped using it due to that problem. Also, ironically, removing sms support killed a big selling point, and the fact that phone numbers are still required is pretty lame.
Yes, but this is where threat modeling comes into play. Grossly simplified, developing a threat model means to assess what sort of attackers you reasonably expect to make an attempt on you. For some people, their greatest concern is their conservative parents finding out that they’re on birth control. For others, they might be a journalist trying to maintain confidentiality of an informant from a rogue sheriff’s department in rural America. Yet others face the risk of a nation-state’s intelligence service trying to find their location while in exile.
For each of these users, they have different potential attackers. And Signal is well suited for the first two, and only alright against the third. After all, if the CIA or Mossad is following someone around IRL, there are other ways to crack their communications.
What Signal specifically offers is confidentiality in transit, meaning that all ISPs, WiFi networks, CDNs, VPNs, script skiddies with Wireshark, and network admins in the path of a Signal convo cannot see the contents of those messages.
Can the messages be captured at the endpoints? Yes! Someone could be standing right behind you, taking photos of your screen. Can the size or metadata of each message reveal the type of message (eg text, photo, video)? Yes, but that’s akin to feeling the shape of an envelope. Only through additional context can the contents be known (eg a parcel in the shape of a guitar case).
Signal also benefits from the network effect, because someone trying to get away from an abusive SO has plausible deniability if they download Signal on their phone (“all my friends are on Signal” or “the doctor said it’s more secure than email”). Or a whistleblower can send a message to a journalist that included their Signal username in a printed newspaper. The best place to hide a tree is in a forest. We protect us.
Alas, this is an issue with all messaging apps, if people delete the app without closing their account. I’m not sure if there’s anything Signal can do about this, but the base guarantees still hold: either the message is securely delivered to their app, or it never gets seen. But the confidentiality should always be maintained.
I’m glossing over a lot of cryptographic guarantees, but for one-to-one or small-group private messaging, Signal is the best mainstream app at the moment. For secure group messaging, like organizing hundreds of people for a protest, that is still up for grabs, because even if an app was 100% secure, any one of those persons can leak the message to an attacker. More participants means more potential for leaks.
Concrete example of threat modeling: if someone found out I was using Signal, for any reason at all, would that cause problems for me?
If yes, then Signal is not a good option. If no, then Signal may be appropriate. Why? Because in their documentation, they explicitly state that while messages are confidential, the fact that you’re using Signal cannot be hidden, and so they don’t make that guarantee.
Right,:
Though btw speaking of:
Plenty of people have been drone striked (struck?) simply because the metadata said they were talking to the wrong guy. Frankly if you need that high of a level of secrecy, you’d be better served using tails/tor, or hell even snail mail with false return addr and a book cipher. But for:
Then frankly either signal or jabber+encryption (or for that matter, simplex, briar, yadda yadda) should be fine.
But then again, it’s more likely to be known as an encrypted chat which may be a problem for them, while the abusive SO might just think XMPP is some outdated IM they know what signal is, and “my friends” can use jabber just the same as signal.
Except not. XMPP not being tied to a phone number, if my buddy Steve deletes Conversations, while I may not be able to message him on jabber I can fall back on text. However (and again maybe now this is fixed), on signal if he deletes the app, I can no longer signal message him, nor can I SMS him because they get lost in limbo as signal messages, I’d have to email or use XMPP to get him to redownload signal, delete it properly, and THEN I can SMS him again. (Maybe no longer now that “no sms,” but also “no sms now but still give us your phone number” don’t sit right with me.)
I dunno if you know this but SMS support got removed from Signal a few years ago
I do, but idk how that effects that problem since I stopped using it due to that problem. Also, ironically, removing sms support killed a big selling point, and the fact that phone numbers are still required is pretty lame.