58
submitted 3 days ago* (last edited 2 days ago) by cypherpunks@lemmy.ml to c/privacy@lemmy.ml

This is a year-old paper but now there is an easy-to-use implementation of the attack: https://github.com/gommzystudio/device-activity-tracker

Signal developers' verdict is WONTFIX: https://github.com/signalapp/Signal-Android/pull/14463

you are viewing a single comment's thread
view the rest of the comments
[-] cypherpunks@lemmy.ml 13 points 2 days ago

But you can turn off sealed sender messages from anyone, so they’d have to already be a trusted contact

The setting to mitigate this attack (so that only people who know your username can do it, instead of anybody who knows your number) is called Who Can Find Me By Number. According to the docs, setting it to nobody requires also setting Who Can See My Number to nobody. Those two settings are both entirely unrelated to Signal's "sealed sender" thing, which incidentally is itself cryptography theater, btw.

this post was submitted on 22 Dec 2025
58 points (95.3% liked)

Privacy

43969 readers
791 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS