this post was submitted on 12 Sep 2026
199 points (95.9% liked)

Technology

87980 readers
2620 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

cross-posted from : https://lemmy.zip/post/71321898

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance

you are viewing a single comment's thread
view the rest of the comments
[–] muntedcrocodile@hilariouschaos.com 0 points 2 hours ago (1 children)

The US government has openly stated they killed people because of metadata and ur comfortable just giving that all away? U also didn't address any of my precise exact points you simply made a vague deflection.

[–] Natanael@infosec.pub 1 points 57 minutes ago (1 children)

Signal doesn't reveal that kind of metadata.

[–] muntedcrocodile@hilariouschaos.com 1 points 51 minutes ago (1 children)

All ur messages have a recipient address. All ur messages go though signal servers. You have an IP address that u communicate to said servers with. They know when and who you are messaging.

[–] Natanael@infosec.pub 1 points 47 minutes ago* (last edited 45 minutes ago)

Signal supports Tor.

They have features like Sealed Sender, which is at least on par with the multiple server behavior of Simplex as it behaves the same (message passing multiple servers, carrying no sender origin data in plaintext)

Simplex knows the same thing. The pairwise identifiers is a sham - all your different identifiers point to the same Android/iOS notification server API key so they know the recipient is the same person, they can tell which exact phone receives a notification when somebody sends you a message (unless the devs use anonymized fetch on a polling schedule, which they don't).

And because they don't hide those sender stamps, Simplex leak more info than Signal with Sealed sender

Why is Simplex asking for investors?

Are Simplex even considering notification content security?