logoalt Hacker News

How Trail of Bits helps verify the integrity of Signal chats

62 pointsby dgroshevyesterday at 11:27 AM38 commentsview on HN

Comments

pizzaioloyesterday at 10:19 PM

Bit of a positive piece amid a negative headline this week: https://cybernews.com/privacy/police-telegram-whatsapp-signa...

show 1 reply
iamshstoday at 3:01 AM

Recently a bureaucrat who wanted to make a mass protest out of his criticism of Indian Election Commission's drive to remove voters, was picked up by Indian Police and his Signal metadata was accessible to the Police. What is the solution to this thing?

His interview does not tell us if it was metadata or actual calls that were surveilled which could point to device compromise too.

"What caught him by surprise, he told ThePrint, was the Special Cell officers' access to his calls made via Signal"

https://theprint.in/india/ex-civil-servant-ashish-joshi-reca...

chewsyesterday at 6:24 PM

I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.

show 3 replies
johnnyApplePRNGyesterday at 6:53 PM

[flagged]

show 1 reply
sage981today at 2:19 AM

Requiring all three auditor signatures keeps independence meaningful; the seven-day freshness window also makes the remaining split-view risk concrete.