Conversation

This Tweet is from a suspended account. Learn more
This Tweet is from a suspended account. Learn more
There is no black box involved in the process. The Signal app is open source. The whole point of the app is providing end-to-end encryption from client to client. You seem to be confusing end-to-end encryption with transport encryption. It doesn't mean what you seem to think.
2
10
It uses authenticated encryption with forward secrecy between instances of the app. It doesn't trust the server. Encrypting connections to the server is not end-to-end encryption. End-to-end means encrypting from one end (Signal app) to the other (Signal app), not to the server.
2
12
If you verify the safety number, it starts considering it a secure session and marks it as secure. It will prominently notify you if the encryption has to be renegotiated. If you don't ever verify a session, it still informs you if it renegotiates (safety number changed).
1
Show replies