内阁为什么要用 Signal 没有自己的专用软件吗?

TG 的政策原来只是给 LE 分享涉恐信息,还说从未发生过。CEO 被捕之后,改成这个了。

8.3. Law Enforcement Authorities

If Telegram receives a valid order from the relevant judicial authorities that confirms you’re a suspect in a case involving criminal activities that violate the Telegram Terms of Service, we will perform a legal analysis of the request and may disclose your IP address and phone number to the relevant authorities. If any data is shared, we will include such occurrences in a quarterly transparency report published at: Telegram: Contact @transparency.

Signal就是美国政府的蜜罐,每次看到一群人在那儿吹美国各种软件对隐私保护多好我就想笑,不知道是不懂技术还是不懂美国,还是明明都懂但是出于精神或物质需要不得不这么吹

1 个赞

任何形式的im软件,一旦依赖于一个中心化的服务infra,都有被当地政府上门索要数据的可能性。

在强大的公权力面前什么加密手段都是扯淡,公权力要你解密数据有一万种办法,以为单纯是storage上加个密就完事了?还且不说不开源的加密本身就有可能有美国政府植入的后门之类的问题。

特别是signal这种几乎就明牌告诉你是美国政府控制的im,还在那吹什么没有交给政府数据,简直令人发笑。

这个人就是明显的既蠢且坏。

1 个赞

自己去看

Signal >> Government Communication

Search warrants for Signal user data, Santa Clara County

08 Aug 2024

Because everything in Signal is end-to-end encrypted by default, the broad set of personal information that is typically easy to retrieve in other apps simply doesn’t exist on Signal’s servers.

Once again, Signal doesn’t have access to your messages; your calls; your chat list; your files and attachments; your stories; your groups; your contacts; your stickers; your profile name or avatar; your reactions; or even the animated GIFs you search for – and it’s impossible to turn over any data that we never had access to in the first place.

MLAT order from Luxembourg for Signal user data

02 Nov 2021

Signal still knows nothing about you, but the government still continues to ask us if we do.

Because everything in Signal is end-to-end encrypted by default, the broad set of personal information that is typically easy to retrieve in other apps simply doesn’t exist on Signal’s servers. This order requested a wide variety of information we don’t have, including the target’s correspondence, contacts, groups, calls, address.

你说的有道理但是我相信 edward snowden 亲自带货

julian assange 警告过 signal 的风险,只是说终端会被 hack,没有提 protocol 会泄密

这样取得的证据不合法,不能用在法庭上 convict 犯罪嫌疑人

hack 终端违法,那不小心被拉进群呢? :troll:

我是不相信任何依赖于centralized infra的im的私密性和抵抗政府的能力。

我记得signal的android app好像是reproducible的,但是其他客户端不知道有没有试过。

非要说signal安全,至少也应该自己host matrix server吧。signal不说别的,收集手机号这一点已经把警报拉满了。

终端当然也是个问题,这个里面有多少blob,blob里面埋了啥只有天知道…

多少年前苹果和谷歌就是这样的文案了,多少年都过去了,不能花点钱找人好好重新策划下文案吗?

1 个赞

官方白纸黑字都给你了,你还不信,包括上面 FBI 图片也给你了。

犯罪基本原则是不能超过 2 个人,不能群聊。

县公安局法院政府去找腾讯阿里要数据你看腾讯阿里会不会理

腾讯和阿里重视用户隐私,拒绝政府访问用户数据的请求

你能看懂英文吗?上面 FBI 图片给你了。


:troll:

你只懂技术,不懂法律。我只管在法律上,能合法获得哪些证据。

责任全在 (Republican) deep state

No paper trail

这句话暴露了你的不专业,不懂技术。

把 blob 当成不可审查的黑箱看,是开源软件魔怔人的想法,不是安全从业者的想法。逆向工程能力是任何严肃一点的安全从业者最基本的能力。

1 个赞

你懂技术,你专业。
o mighty security analyst, please tell me why there is no reverse engineering results to clarify security and privacy concerns of blobs being used in those devices, then?