58
submitted 3 days ago* (last edited 2 days ago) by cypherpunks@lemmy.ml to c/privacy@lemmy.ml

This is a year-old paper but now there is an easy-to-use implementation of the attack: https://github.com/gommzystudio/device-activity-tracker

Signal developers' verdict is WONTFIX: https://github.com/signalapp/Signal-Android/pull/14463

top 9 comments
sorted by: hot top controversial new old
[-] juko_kun@sh.itjust.works 4 points 2 days ago

Is there any reason to use Signal over Matrix?

[-] tomenzgg@midwest.social 5 points 2 days ago

https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/

This is the most strongly writeup I know of (whether it's something you, likewise, find worth being wary about is, naturally, up to you, though).

[-] Screen_Shatter@lemmy.world 3 points 2 days ago

I remember trying to sign up for signal and stopped when it wanted my phone number. It's no longer anonymous at that point. When I talk about it theres always people who come at me about it being secure and whats my attack vector? Well, its not secure. My vector is a desire to be anonymous, and clearly the anonymity this presents is a facade.

[-] ryannathans@aussie.zone 0 points 2 days ago

You can literally turn off read receipts in signal

[-] cypherpunks@lemmy.ml 15 points 2 days ago* (last edited 2 days ago)

You can literally turn off read receipts in signal

But you can't turn off delivery receipts, which is what this attack uses.

[-] ryannathans@aussie.zone 0 points 2 days ago

But you can turn off sealed sender messages from anyone, so they'd have to already be a trusted contact

[-] cypherpunks@lemmy.ml 13 points 2 days ago

But you can turn off sealed sender messages from anyone, so they’d have to already be a trusted contact

The setting to mitigate this attack (so that only people who know your username can do it, instead of anybody who knows your number) is called Who Can Find Me By Number. According to the docs, setting it to nobody requires also setting Who Can See My Number to nobody. Those two settings are both entirely unrelated to Signal's "sealed sender" thing, which incidentally is itself cryptography theater, btw.

this post was submitted on 22 Dec 2025
58 points (95.3% liked)

Privacy

43969 readers
791 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS