Don’t buy into this, this is just marketing. I’m not saying that Signal is acting in bad faith, only that they chose to design a communication silo with themselves at the helm instead of a federation of servers/providers united by the same protocol. Because of that, they own all accounts, and have the monopoly of messages being routing on the network. Of course there is no difficulty for them knowing who’s addressing whom, how often, with what kind of payload, by topology. “Sealed senders” and “secure enclave contacts discovery” is just techno babble meaning “trust us, bro. Especially because you have no choice, anyway”.
Is your source for “what privacy experts say” a sad jpeg meme, really?
Also, no matter what some distracted expert might say, the only fact that matters is that none of Signal’s marketing claims are verifiable: the feature you are referring to happens server-side. Nobody but Signal knows what runs server-side. The guarantee of “not knowing who’s talking to whom” isn’t built into the protocol itself. This is where trust enters the picture.
The dominant paradigm in cybersecurity is that trust is not proof of anything. Math is. And “sealed senders” isn’t that.
Don’t buy into this, this is just marketing. I’m not saying that Signal is acting in bad faith, only that they chose to design a communication silo with themselves at the helm instead of a federation of servers/providers united by the same protocol. Because of that, they own all accounts, and have the monopoly of messages being routing on the network. Of course there is no difficulty for them knowing who’s addressing whom, how often, with what kind of payload, by topology. “Sealed senders” and “secure enclave contacts discovery” is just techno babble meaning “trust us, bro. Especially because you have no choice, anyway”.
No, I don’t think I will
I’ll trust what the cyber security and privacy experts say.
Is your source for “what privacy experts say” a sad jpeg meme, really?
Also, no matter what some distracted expert might say, the only fact that matters is that none of Signal’s marketing claims are verifiable: the feature you are referring to happens server-side. Nobody but Signal knows what runs server-side. The guarantee of “not knowing who’s talking to whom” isn’t built into the protocol itself. This is where trust enters the picture.
The dominant paradigm in cybersecurity is that trust is not proof of anything. Math is. And “sealed senders” isn’t that.