Recently a bureaucrat who wanted to make a mass protest out of his criticism of Indian Election Commission's drive to remove voters, was picked up by Indian Police and his Signal metadata was accessible to the Police. What is the solution to this thing?
His interview does not tell us if it was metadata or actual calls that were surveilled which could point to device compromise too.
"What caught him by surprise, he told ThePrint, was the Special Cell officers' access to his calls made via Signal"
https://theprint.in/india/ex-civil-servant-ashish-joshi-reca...
I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.
Requiring all three auditor signatures keeps independence meaningful; the seven-day freshness window also makes the remaining split-view risk concrete.
Bit of a positive piece amid a negative headline this week: https://cybernews.com/privacy/police-telegram-whatsapp-signa...