70
submitted 3 days ago* (last edited 3 days ago) by signaljam@lemmy.ml to c/privacy@lemmy.ml

Hey, everyone. If you're looking for a fresh privacy podcast, we recently started a new one called Signal Jam.

Here's a bit about why we made Signal Jam and what we're hoping to do differently.

We even have preliminary ways for you to participate in the project, which you can read about here.

Feel free to connect with us on Proton, Tuta, Signal, or here on Lemmy. Looking forward to your feedback and thoughts!

you are viewing a single comment's thread
view the rest of the comments
[-] cypherpunks@lemmy.ml -1 points 2 days ago

imo you should not promote signal, proton, or tuta for various reasons including the ones i mention in those three links.

[-] signaljam@lemmy.ml 1 points 16 hours ago

Hey, Arthur— thanks for dropping these links. Jay and I will look at these and consider your thought process, and might reach out to follow up, if that's okay! If I may ask, what do you prefer for email and RTC?

-M

[-] stupid_asshole69@hexbear.net 2 points 1 day ago

I only read the signal link you posted, but the first link inside it complains that the signal server needs to know a users ip and that could be used to connect people and users. Ip addresses are required to send data. Ip obfuscation is insanely out of scope for a messenger.

The second link complains about sealed sender not failing closed which is true (or was true at the time) but also a reasonable compromise to prevent abuse and avoid it constantly failing and requiring new expirable tokens.

These are not reasons to not use or even not recommend signal. A person who is taking recommendations to increase their privacy should not be worried about those concerns.

Removing oneself from public records (or taking greater control over what surfaces in public records about oneself) is infinitely more important than expecting ip obfuscation or sealed sender from signal.

I am not making this reply to start an argument and will not engage in one. The point is to help readers understand that your concerns about signal are esoteric.

[-] cypherpunks@lemmy.ml 1 points 6 hours ago

more important than expecting ip obfuscation or sealed sender from signal

People are only expecting metadata protection (which is what "sealed sender", a term Signal themselves created, purports to do) because Signal dishonestly says they are providing it. The fact that they implemented this feature in their protocol is one of the reasons they should be distrusted.

[-] stupid_asshole69@hexbear.net 1 points 6 hours ago

For anyone reading along, that means people you send signal messages to can see your user account name maybe even if you click the button that’s supposed to make it not possible to do that.

Change your behavior accordingly.

[-] cypherpunks@lemmy.ml 1 points 6 hours ago* (last edited 5 hours ago)

No, it isn't about hiding your identity from the people you send messages to - it's about the server (and anyone with access to it) knowing who communicates with who, and when.

Michael Hayden (former director of both the NSA and CIA) famously acknowledged that they literally "kill people based on metadata"; from Snowden disclosures we know that they share this type of data with even 3rd-tier partner countries when it is politically beneficial.

Signal has long claimed that they don't record such metadata, but, since they outsource the keeping of their promises to Amazon, they decided they needed to make a stronger claim so they now claim that they can't record it because the sender is encrypted (so only the recipient knows who sent it). But, since they must know your IP anyway, from which you need to authenticate to receive messages, this is clearly security theater: Amazon (and any intelligence agency who can compel them, or compel an employee of theirs) can still trivially infer this metadata.

This would be less damaging if it was easy to have multiple Signal identities, but due to their insistence on requiring a phone number (which you no longer need to share with your contacts but must still share with the Amazon-hosted Signal server) most people have only one account which is strongly linked to many other facets of their online life.

Though few things make any attempt to protect metadata, anything without the phone number requirement is better than Signal. And Signal's dishonest incoherent-threat-model-having "sealed sender" is a gigantic red flag.

[-] pineapple@lemmy.ml 1 points 1 day ago

I think signal, proton and tuta are totally fine for most peoples threat model unless they feel they need the extra privacy.

If we want everyone to value privacy then we need to onboard them with easy to use and accessible services first and then they can take steps further if they want.

[-] appropriateghost@lemmy.ml 5 points 2 days ago

It's difficult enough for getting people to switch from whatsapp to signal.

I don't know how successful i'd be to get people to switch to simplex.

Is there a particular reason that you don't recommend signal?

[-] geneva_convenience@lemmy.ml 1 points 2 days ago

What alternatives would you recommend?

[-] twikz@sopuli.xyz 2 points 1 day ago

Matrix is open source, should give that a try,

it could be a bit more user friendly tho

[-] geneva_convenience@lemmy.ml 1 points 1 day ago

The fact that Matrix was developed in Israel instantly kills it for me.

[-] twikz@sopuli.xyz 2 points 1 day ago
[-] geneva_convenience@lemmy.ml 2 points 1 day ago

No Matrix was developed by Amdocs, an Israeli company. It has moved to Europe afterwards (I recall UK but might be wrong about that part)

Element is a Matrix client.

this post was submitted on 25 Jul 2025
70 points (96.1% liked)

Privacy

40219 readers
659 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS