@thegibson

There is still a phone number involved last I checked.

Which means SS7 under the hood at some point.

But SS7 is not secure.

https://blog.cryptographyengineering.com/2020/07/10/a-few-thoughts-about-signals-secure-value-recovery/

Why is Signal asking users to set a PIN, or “A few thoughts on Secure Value Recovery”

Over the past several months, Signal has been rolling out a raft of new features to make its app more usable. One of those features has recently been raising a bit of controversy with users. This i…

A Few Thoughts on Cryptographic Engineering

"Signal has historically chosen the more cautious and safer approach — as compared to more commercial alternatives like WhatsApp"

#MatthewGreen, 2020

https://blog.cryptographyengineering.com/2020/07/10/a-few-thoughts-about-signals-secure-value-recovery/

Except when it's integrating third-party search engines so people can search for reaction GIFs in-app;

https://signal.org/blog/giphy-experiment/

... adding a new and totally avoidable attack surface.

@SpaceLifeForm
@thegibson

Why is Signal asking users to set a PIN, or “A few thoughts on Secure Value Recovery”

Over the past several months, Signal has been rolling out a raft of new features to make its app more usable. One of those features has recently been raising a bit of controversy with users. This i…

A Few Thoughts on Cryptographic Engineering