Conversation

Replying to and
This is a academical discussion. Storing signal contacts encrypted with a password + sgx has no practical security impact. Users are reading this discussion and switching to wire or telegram. Where this data and all your messages on telegram is stored in PLAINTEXT on serverss
2
Replying to and
Also this discussion ignores reality. If you ever used an other big messenger all your contacts have been uploaded in plaintext. If a person who has your phone number used e.g WhatsApp your contact was uploaded in plaintext. If you sync your contacts: also uploaded in plaintext
1
Replying to and
Signal is the ONLY Messenger / App that uses contact information where the information is encrypted + you have control over the password used for encryption, so this data can be stored for it to be uncrackable by bruteforce.
1
They also encourage a weak PIN due to using SGX and they exaggerate the security it provides. Providing an opt-out doesn't resolve the problems. Under the hood, the opt-out just generates a high entropy random PIN which you could already do. They treated this as only a PR issue.
1
1
Show replies