Privacy and anonymity have some overlap, but are ultimately two different things. Signal focuses on privacy.
Privacy
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
Chat rooms
-
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
I don't undestand this comment, could you please elaborate?
The way I way I see it, privacy without anonymity only works if you can trust a service provider. Since there are no trustworthy providers, especially since legislation can cancel any assurances anyone could give you, anonymity becomes the only way to ensure privacy, making it virtually synonymous.
Privacy means that you can talk/act safely in your own closed-off space while no-one knows what you do.
Anonymity means that you can safely talk/act in public space while no-one knows who does it.
If you want your talk be private while doing it in public or via an untrusted service, you can use obfuscation/encryption of the content/payload data of your talk (still anyone could receive it and know it's from you and if they have the key they can decipher it).
If you want to be anonymous in public space, you have to obfuscate the metadata of your talk (so that no-one knows who said it but anyone can still receive it).
*And here is a bit of an overlap depending on where we want to draw the boundary of our privacy realm. In some cases, the knowledge about metadata like location and time of a message can be breach privacy while in other cases this is irrelevant.
You could also do both, meaning you'd have an anonymous appearance in a public/untrusted space, having a conversation with only those people who have the key to your messages. That's a stunt which is not easily accomplished, as obviously you'll need a way to let others know how to reach you, and exchange keys (in other words, you'll have to first make an appointment in private and in a trusted space).
[wanted to write two sentences, no so much text :-D]
Privacy isn't anonymity. Signal promises privacy, not anonymity.
This is a well known issue for a lot of people and signal has been promising to fix this for years. Using a phone # for verification reduces spam and bot accounts, but like you said it drastically reduces anonymity.
That said, anonymity != privacy. You could anonymously place a note on a car telling the owner to learn to park, but it's not private since anyone walking by could read it. Likewise you can send an encrypted signal message to another user who knows who you are, so it's private, but not anonymous.
They've repeatedly stated that they're working on removing the need to share your phone number with your contacts, but that's taking some time, because they want to implement it in a way that does not involve storing your entire social graph on their servers.
You'll still have to sign up with your phone number, but the only thing that can be traced back is that your phone number is registered on Signal - and only by subpoenaing Signal, I believe.
Btw, the main thing to realise, is that Signal is trying to tread the delicate balance of being accessible and private. If you have the perfect private messenger but nobody uses it, that doesn't help democracy one bit. So starting out with an easier-to-implement mechanism that also helps adoption (because people can get notified when people they already have in their contact list join), that still protects against indiscriminate mass surveillance, makes sense to me, even if it means your contacts can still know who you are.
They made a mistake in removing SMS support - that was a good way to become useful to people with the current paradigm and encourage them over to the new. Sometimes Signals decisions are self destructive.
I still have signal but I use it much less since it stopped SMS support; I just open it less and so when starting conversations default to WhatsApp. For a while signal was growing amongst my friends and colleagues but it appears to have stalled.
Google are now doing the same pushing their RCS in the default SMS app in Android.
I wouldn't call it a mistake, more like being caught between a rock and a hard place, where Android basically forced them to give up on SMS support even though they'd have liked to keep it: https://community.signalusers.org/t/signal-blog-removing-sms-support-from-signal-android-very-soon/47954/57
But yes, it was really nice when I could use it as my SMS app. Then again, very few people in my country use SMS in the first place - it's all WhatsApp, and it was never able to have support for that. Luckily, most of my friends have adopted Signal by now.
Would I be able to switch seamlessly to another SIM/number in that case, do you think?
I have no idea, unfortunately :/
Remember, privacy and anonymity are not the same thing. Signal is an app for private communications, not anonymous communications.
You can have privacy without anonymity, and you can have anonymity without privacy, and either/both of those can be secure or insecure.
With focus on anonymity matrix is better than signal, with focus on privacy signal is probably better, just because you are forced to use encryption.
Almost all Matrix servers seem to require at least an email address. A better option would be XMPP, as most servers only require a username and a password to register. It's also the IETF internet standard and a lot less bloated than Matrix.
I agree with you, but I dont. The bloat is optional and important. Because the bloat is features and people want features.
The thing with the email is a fair point and I wont suggest just hosting your own email or matrix server cuz thats a silly argument.
Signal is great for private communication with people you already know and trust. I was in a situation where I was organizing with new friends, and we had a big group chat on Signal. I cloned Signal to a work profile, and registered it with a cheap VOIP number, so that I could keep my real phone number separate from my political organizing activities.
Signal is a privacy first app. Do I wish it would not use a telephone number? Absolutely! But they never claim to be anonymous. This said with something like https://juicysms.com you can register signal and many other services with a number in the USA, the Netherlands or the UK (the Netherlands is the best option here)
If you look for an app what don’t need a telephone number check simplex or session. Perhaps something like the matrix protocol and element would be a great option too.
A messenger can at best be pseudonymous, since you want your friends to be able to find you.
And in practice, a mobile messenger that actually works (i.e. makes your phone go "ping" when someone sends you a message, not hours later) will always be traceable to you, as it needs to be able to deliver the message.
Also, regardless whether Signal is perfect or not, it's the one privacy friendly messenger that people actually use. A messenger where you can reach only your privacy-extremist friends is useless. Signal is already on the extreme end for most people, trying to push anything "more perfect" (but more niche) will just make people use WhatsApp.
Well I don’t get spam from signal. However if you want anonymity find something else. Or don’t talk to anyone. Most of our cellphones leak all kinds of data you won’t get privacy in most phones and you shouldn’t expect it either.
Jami?
Because its the best right now in terms of usability and popularity. I don't like it but it does work