Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://labyrinth.zone/users/halva" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>halva</span></a></span> <span class="h-card" translate="no"><a href="https://a.bloodyno.se/users/lynn" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>lynn</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>signalapp</span></a></span> <span class="h-card" translate="no"><a href="https://tech.lgbt/@deilann" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>deilann</span></a></span> </p><p>The problem is one needs to literally acquire a phone number and have access to it, and the demand of a phone number itself is bad. This makes it unnecessarily complex and expensive compared to using <span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>monocles</span></a></span> / <a href="https://infosec.space/tags/monoclesChat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>monoclesChat</span></a>. <br>(Cuz if I've to pay to communicate, I might just choose a provider that isn't a <a href="https://infosec.space/tags/VC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VC</span></a> <a href="https://infosec.space/tags/MoneyBurningParty" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MoneyBurningParty</span></a> but a long-term sustainable solution based off <a href="https://infosec.space/tags/OpenStandards" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenStandards</span></a>!)</p><ul><li>I'm sorry for your location. My sincere condolences!</li></ul><p>Still, <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> doesn't allow <a href="https://infosec.space/tags/SelfCustody" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SelfCustody</span></a> of all the keys & <a href="https://infosec.space/tags/SelfHosting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SelfHosting</span></a>, which makes it vulnerable as a <a href="https://infosec.space/tags/proprietary" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>proprietary</span></a> <a href="https://infosec.space/tags/centralized" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>centralized</span></a>, <a href="https://infosec.space/tags/SingleVendor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleVendor</span></a> & <a href="https://infosec.space/tags/SingleProvider" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleProvider</span></a> solution.</p><ul><li>Just because <span class="h-card" translate="no"><a href="https://mastodon.world/@Mer__edith" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Mer__edith</span></a></span> isn't having <a href="https://infosec.space/tags/Roskonmadnozr" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Roskonmadnozr</span></a> pointing a gun at her head doesn't mean <a href="https://web.archive.org/web/20220112020000/https://twitter.com/thegrugq/status/1085614812581715968" rel="nofollow noopener noreferrer" target="_blank">she'd risk jail for a user</a> when push comes to shove.</li></ul><p>And with <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CloudAct</span></a> on one hand and <a href="https://infosec.space/tags/Trump" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trump</span></a> wanting to <em>"Speedrun Hitler"</em>, I'd not rely on Signal.</p><ul><li>The <em>"Metadata"</em> <a href="https://infosec.space/tags/FUD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FUD</span></a> is just a marketing bs because Signal <em>will comply</em> with warrants, whereas nothing prevents me from buying a Thin client, setting up an <a href="https://infosec.space/tags/OnionService" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionService</span></a> to tunnel everything over <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> and rig it to disconnect power if tampered with or upon command.</li></ul><p>I have setup comms for critical operations (incl. helping people flee Russia!) and I'd rather choose <a href="https://infosec.space/tags/OnionShare" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionShare</span></a> over <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> if <a href="https://infosec.space/tags/Metadata" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Metadata</span></a> is a real concern.</p><ul><li>Internet Access, even in <em>"P.R."</em> <a href="https://infosec.space/tags/China" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>China</span></a>, is something feasible to workout given the massive prevalence of public <a href="https://infosec.space/tags/WiFi" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WiFi</span></a>. Also it's easier to spoof/anonymize a MAC than an <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IMEI</span></a> or even <a href="https://infosec.space/tags/IMSI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IMSI</span></a>, so making one dependent on <a href="https://infosec.space/tags/PhoneNumbers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumbers</span></a> to even sign up is inherently bad!</li></ul>