Egregoros

Signal feed

Timeline

Post

Remote status

Context

14
@ug Was almost entirely based on social graphs; person A is a known Taliban leader, people B, C, and D regularly interact with him so let's kill them. "Interact" here could mean anything from frequent text messages picked up by local cell infrastructure or sniffed by predator drones to a drone footage of them in physical proximity

Contents of messages didn't matter at all

@ug Ironically Signal is one of the only protocols that is even a little bit resistant to social graph attacks

It's definitely possibly for Signal to work around sealed-sender by analyzing the timing of traffic between various IP addresses over time to build a rough social graph but that's a lot more difficult to build and there's a lot less information available than, say centralized OMEMO XMPP like what WhatsApp is based on

(It should go without saying that Signal is doing exactly that and that their insistence on requiring phone numbers is in a large part an attempt at linking real-world data to those rough social graphs)

@ug @mia P2P protocols are more resistant to social graph and timing analysis in the practical sense that the data is usually scattered across loads of servers with different owners but on a protocol level (assuming a hostile actor can slurp data down from the entire network) they're equally vulnerable

@mia @scathach

beyond the kind of wide net that the NSA etc. are able to cast and the definite reality that Signal traffick is highly scrutinized by them… a thing about signal evangelists that drives me up the wall is in the end we have to just trust that signal does what they say, and assume that there isn’t some kind of deep level infiltration by feds.

and you bring this up and they’re elike ‘that’s crazy, why would the federal government do such a thing?” like of course they would do that, were you born yesterday?

Replies

0
No replies yet.