@tagomago @_elena @marleenstikker also that doesn't help when @signalapp and it's supplier, #Amazon #aws, are all falling.under #CloudAct.

@divVerent The problem is that @signalapp mandates #PII like #PhoneNumbers, which is critical for said #phishing...

#Signal can spout all their "#Metadata" - #FUD all day but in the end they fall under #CloudAct and will snitch on users because if they didn't it would've been a statistical inevitability that @Mer__edith and #Moxie would've been in jail and Signal shutdown like #EncroChat was.

  • Make of that what you will, but demanding a #PhoneNumber [which is either directly ("#KYC!") or indirectly / circumstantially linked to a person should be seen as *THE BIGGEST RED FLAG for any service.
    • It's like asking for an #ID at a store not as means to "verify age" with like a #DOB & Photo on something not trivial to forge but rather demanding someone's address just to buy a beer!

@DekOfTheYautja PRECISELY THAT!

Kevin Karhan :verified: (@[email protected])

@[email protected] @[email protected] yes, it it #Signal's [sole fault!](https://infosec.space/@kkarhan/116200603563502633) - Because this attack vector *doesn't exist* in [any halfway decent messenger App / system!](https://infosec.space/@kkarhan/116200603563502633)

Infosec.Space
Kevin Karhan :verified: (@[email protected])

@[email protected] THERE IS *NO LEGITIMATE REASON* FOR #Signal TO DEMAND A #PhoneNumber (= #PII by circumstances if not mandatory doxxing to the governments aka. *"#KYC"*)… - so yes I [do blame Signal](https://infosec.space/@kkarhan/116200585213177913) because this attack vector is unique to #Signal's shittyness and would not exist with @[email protected] / #monoclesChat or even [`cock.li`](https://cock.li) of all places…

Infosec.Space

@Xtreix well, @GrapheneOS chose their requirements and they can happily design their own platform instead.

  • I just think that their stubbornness makes them look like Stallmanist extremists to the point of being unbearable cringe and completely loosing the plot.

To the point that it's cheaper to go black/red and teach that to people, even at the risk of inconvenience.

  • I mean, in many juristictions one will have to do so anyway, but that's not tue point here…

I think #GrapheneOS prefer to "die on their hill" of "moral superiority" than fave the reality that 99% of people can't and won't blow $500 - $1000+ on a phone when any half-decent Netbook with @tails_live , @torproject and #4G or #5G modem can do the same.

Otherwise we'll see them fail the same way @signalapp did, which is eitger getting shut down (#EncroChat-style) or being uncovered as a controlled opposition / honeypot (like #ANØM aka. #OperationIronside aka. #OperationTrøjanShield)…

Red/black concept - Wikipedia

This is a *lot* of prison (12 years for the lad, he will serve 6-9 of them inside) for just #partydrugs with no violence involved, but there was a lot being sold!

Digging a bit deeper it appears he *tried* to get out of the game after #Encrochat got popped, laundered the money into an events management company but it folded (even ending up with an Employment Tribunal judgment as he didn't pay his staff correctly), then got back into dealing and thus created a second set of data for #MetPol to track and nick him!

#London #Essex #drugs #crime

https://www.essexlive.news/news/local-news/drug-kingpin-nabbed-police-carrying-10788206

Drug kingpin nabbed by police carrying £160k in cash

His girlfriend worked alongside him and the pair handled more than £12 million worth of drugs and criminal cash

Essex Live
@tranquil_cassowary @halotroop2288 This followed the shutdown of #EncroChat after a cop in the #UK leaked that it had been taken over by LEAs and criminals who didn't get busted directly switched from EncroChat to #ANØM
How law enforcement's biggest secret was leaked to gangster elite | EncroChat treachery

YouTube

Calling the #UK a "#democracy" is like calling the #USA "#socialist"...

If a "platform" is #KYC'ing users from the UK or even is able or willing to collect #PII like #PhoneNumbers that would make them know if a customer is from the UK, it has to be regarded as #insecure - period!

The sheer idea of said #tech is irredeemably wrong!

  • Espechally since it's not a replacement for moderation nor parenting!

#ITsec #InfoSec #OpSec #ComSec #privacy #DataProtection #OSA #UKOSA #OnlineSafetyAct

The UK Just Legalized Mass Surveillance (In the Name of Safety)

YouTube

Var det Encrochat-avslöjandet som ledde till våldsvågen? Det är i alla fall en teori som lanseras av SVT i en artikel om att material från Encrochat fortfarande leder till åtal i Sverige. Det är möjligt att knäckandet av Encrochat bidrog till en ökning av gängvåldet i Stockhom men det är totalt osannolikt att det ledde till att gängvåldet ökade i Göteborg och Malmö.

https://blog.zaramis.se/2026/01/13/var-det-encrochat-avslojandet-som-ledde-till-valdsvagen/

@net_gremlin @andnull +9001%

Add to that #CloudAct and then you know how @signalapp that rubs off #AWS not only can but will snitch on users because if they didn't #Trump (and #Biden befire him) would've unplugged them harder than #EncroChat got.

I'll be shouting #ToldYaSo and expect all those #Signal shills to apologize to me personally when the shit inevitably hits the fan!

https://infosec.space/@kkarhan/115871670255534175

Kevin Karhan :verified: (@[email protected])

@[email protected] no, but they want to be ableto #snitch and #dox users. - Only #cops demand #ID or any *"#KYC" with #PII. - #PhoneNumbers are #PII and are at best merely pseudonymous, but trivially to link to a person. Good systems are #decentralized, #federated, #SelfHosting-capable, #OpenSource & #OpenStandard and offer *real #E2EE* (with #SelfCustody of all the keys!)… - See #XMPP+#OMEMO (i.e. @[email protected] / #monoclesChat & @[email protected] ) and #PGP/MIME (see @[email protected] / #deltaChat and @[email protected] )… Anything else is either a #HoneyPot or run by #UsefulIdiots that consider snitching on their customers as valid strategy. - Cuz we all know neither @[email protected] nor anyone else at @[email protected] is gonna [risk jail for their users](https://web.archive.org/web/20220112020000/https://twitter.com/thegrugq/status/1085614812581715968), and by the amount of users they have, it is a statistical inevitability that they would've had to do so already.

Infosec.Space