Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> FYI, Signal has access to all metadata about messages and calls

source for this?



The messages and calls are routed through their servers, so they could (but do not) store whatever metadata is required to route messages and calls. This would at least be the recipient's account and IP address, the sender's IP address (but not necessarily their account), and the current time.

I believe the GP is echoing zeverb's sentiment, that it would be preferable if OWS (Signal) could not even be ordered to collect such data.

The thing I don't understand about the GP's post is "but someone else could be storing it". I would expect the entire message (including headers / metadata) to be encrypted in transit, with a pinned key, so that only OWS has access to the routing metadata. Please correct me if I'm wrong.


Someone exploiting a security vulnerability in Signal's servers could be storing the metadata.


It's the way the protocol works and its centralized infrastructure. They for sure have access


https://en.wikipedia.org/wiki/Signal_(software)

Check the metadata portion. One thing to note, this isn't surprising at all. All of the centralized IM servers can do this and, usually more. The alternatives that try to minimize or obfuscate metadata are far from market-ready.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: