- cross-posted to:
- privacy@lemmy.ml
- cross-posted to:
- privacy@lemmy.ml
Can LEO tie a username to a phone number?
From Signal’s blog footnotes:
Usernames in Signal are protected using a custom Ristretto 25519 hashing algorithm and zero-knowledge proofs. Signal can’t easily see or produce the username if given the phone number of a Signal account. Note that if provided with the plaintext of a username known to be in use, Signal can connect that username to the Signal account that the username is currently associated with. However, once a username has been changed or deleted, it can no longer be associated with a Signal account.
Depends. How smart is Leo?
Finally!
Signal blog post on the topic, with instructions and links to join the beta: https://signal.org/blog/phone-number-privacy-usernames/
Awesome! I love Signal and the lack of usernames has always been one of it’s bigger downsides, especially when comparing against other messaging apps.
I see this as both a win and a problem:
As soon as you take away a hard link to a real-life identifier, the sketchy people come out of the woodwork and spread images of child exploitation.
Signal has not had this problem like some platforms (e.g. Kik), and I suspect two reasons:
- Lack of searchable chat rooms
- Concrete link to a phone number that anyone who contacts you must know (and make it easy to identify you to authorities)
Up until now signal has been an excellent secure replacement for text messaging between parties that know each other. I hope they don’t go the “chat groups” route, though I doubt they will. But I suspect this change will make it a preferred way for abusers to exchange images and videos nearly anonymously.
it’s called “phone number privacy.”
Really rather important feature in places like here in Finland, where your phone number (and car license plate) is directly linked and publicly searchable to your full name and address :)
The implication is that a phone number is still required, you just no longer have to share that with the people you communicate with.
Their blog post says explicitly that phone number is still required for sign-up and that usernames are purely meant as an avenue to message new people without sharing your phone number. Your username isn’t even visible to anyone but you and you can change it whenever you want.
That does help. While It adds an extra step to the reporting process (having the authorities identify the human behind the tag), it does at least nearly guarantee someone can figure out who is behind it.
Careful though. Maybe not as “private” as you may think… a thread from @sc00bz@infosec.exchange - https://infosec.exchange/@sc00bz/111966928032512918
So do I still need to provide a phone number when I sign up?
you will still need a phone number to sign up for Signal
From signals official blog, yes you do
Well, then this changes nothing as it applies to political organizing.