Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

FWIW here is the only data that Signal had available to turn over when requested by the government: https://twitter.com/whispersystems/status/783325788883955713


There is actually more than that stored in the server's database. Push messaging IDs are there, for example. But ignoring that, let's say the attacker is watching all the Signal server's connections. Who is talking to who can be determined based on size, direction and timing of traffic between clients and the server. The server could also be modified to log it.

The idea with projects such as Vuvuzela is to make metadata less usable.


I wonder, why even store those two pieces of information? I mean, they're not exactly essential.


Pure speculation, but backend tidying?

if ( days between acct creation and last check-in > N Days ): archive record; rm prod record;

There may be less identifiable means for these boring operations though. Just the first thing that popped into my head.


How is that connected to vuvuzela? It is not even subtle at this point.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: