| Post AuslJJ1YvfWtaabZ8i by [email protected] | |
| More posts by [email protected] | |
| Post #AuoItQJTdEpzJk0xmq by [email protected] | |
| 0 likes, 4 repeats | |
| Signal (and many other messengers) stores push tokens in their database in plai… | |
| Post #AuoItQRHAF4lhvfBwW by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp Arian, thanks for your toot, super informative. Can I ask a dumb quest… | |
| Post #AuoItQXemWBE1ieHtA by [email protected] | |
| 0 likes, 1 repeats | |
| @onekind Signal sends an empty notification. It wouldn't even be possible f… | |
| Post #AuoItR2quX8LaTFCVs by [email protected] | |
| 0 likes, 0 repeats | |
| More technical details herehttps://blog.phnx.im/privacy-of-push-notifications/A… | |
| Post #AuoItRXL5BWJ71VY24 by [email protected] | |
| 0 likes, 0 repeats | |
| @andre_meister originally broke this story in 2023. Thanks for bringing it to l… | |
| Post #AuoWQPIHk0TX7IW0CO by [email protected] | |
| 0 likes, 1 repeats | |
| @arianvp I'm not super inclined to go full-on "Signal is compromised a… | |
| Post #AuowKaHmYfY6HJAEV6 by [email protected] | |
| 0 likes, 1 repeats | |
| @arianvp I'll be talking about it in my talk on metadata protection in mess… | |
| Post #AuozJ8hFwqYuHj58kq by [email protected] | |
| 0 likes, 1 repeats | |
| @arianvp @letoams Does signal claim users are anonymous? | |
| Post #Auq5VsjHQ48ZPWRotU by [email protected] | |
| 0 likes, 1 repeats | |
| @arianvp Signal gets routine requests from feds for data.They say they only sto… | |
| Post #AusksfUrGjNFT3bdRo by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp are you really, *really* sure that this represents an actual deanonymi… | |
| Post #AusksfbwqN2rp2vIUy by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat Yes. 100%Apple will give all your personal details in exchange for a push… | |
| Post #AusksfjOOh04C8PF6O by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat The issue has been thoroughly reported on by journalists in 2023. Apple … | |
| Post #AusksfqTyKfgY7iu9Y by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp Do you have some reason to believe that? Seems equally likely to me th… | |
| Post #Auskslg4HxuEdYtfkm by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp @andre_meister On the Android side of things, the culprit is Google Pl… | |
| Post #AuskstoA3l8JqykFTk by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp I highly recommend https://simplex.chat/ since it has no identifiers a… | |
| Post #AuskstvFdOnwCy3uWu by [email protected] | |
| 0 likes, 0 repeats | |
| @ParetoOptimalDev @arianvp what security issues does simplex have? | |
| Post #Ausksu0vIJLEUYiRN2 by [email protected] | |
| 0 likes, 0 repeats | |
| @hipsterelectron I see possible availability issues at least; doing their own p… | |
| Post #AusksuGANdXDFpqc88 by [email protected] | |
| 0 likes, 0 repeats | |
| @wonka @hipsterelectron @ParetoOptimalDev @arianvp I bought into that lie, too.… | |
| Post #AusktH9vF1CqH86S5g by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat Apps that aren't end to end encrypted and don't go out of their w… | |
| Post #AusktHFatvk8Yikyvo by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp okay; so you’re guessing, but you think you’re guessing correctly.… | |
| Post #AusktHLcXWZ0rPZnKC by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat Yes this is a great point. Indeed signal does a good job at not linking… | |
| Post #AusktHS09nfTBCYtGq by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp if they can get into the phone and open signal they know a lot more th… | |
| Post #AusktHYNm4lvUzXzDU by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat e2ee and Anonymity are two separate things and we shouldn't conflate … | |
| Post #AusktI63kri7BRIsi0 by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat To give a contrived example: "Arian was part of the Anti-Putin-Rall… | |
| Post #AusktKxf6XmA4GOiXI by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp Ah, okay. Your theory is that push ids link users to devices, and ther… | |
| Post #AusktL3KlSJSLr3FNQ by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat @gnat In the signal protocol every participant of a chat knows the accoun… | |
| Post #AusktLlI81TUYBcLtQ by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat Law enforcement then makes a request for a database record for a specifi… | |
| Post #AusktMOHn2fOV7rUfo by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat Same for Wire. Given an account id, you can get the list of push tokens:… | |
| Post #AusktN33LTHCXYw3DU by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat the push id and the device id *have* to be linkable. That's how you a… | |
| Post #AusktNl0i2REjtV9jU by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp "signal has never admitted this happening" implies that they… | |
| Post #AusktNqgMwyX1U9gZc by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp apple does not appear to specifically identify signal as the target of… | |
| Post #AusktNwi0XnPKAyUy0 by [email protected] | |
| 0 likes, 0 repeats | |
| @hipsterelectron I'm literally linking to the source code where you can see… | |
| Post #AusktO3RbVBRf47sSu by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp where is the link??????? | |
| Post #AusktOSc5vJgv7tyhE by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp if this issue has been raised to signal i would like to see their resp… | |
| Post #AusktOdxPkOHUJD2NU by [email protected] | |
| 0 likes, 0 repeats | |
| @hipsterelectron yes Apple has blame too. They could've built a more privac… | |
| Post #AusktP8RaOmF0rTNtg by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp you have the link to reuters which does not mention signal and the lin… | |
| Post #AusktPMcjg7Tiq6i00 by [email protected] | |
| 0 likes, 0 repeats | |
| @hipsterelectron the fact that signal has actively been banning forks that disa… | |
| Post #AusktQ2oCprbpfqOki by [email protected] | |
| 0 likes, 0 repeats | |
| @hipsterelectron where there is smoke there is fire. And apple just published A… | |
| Post #AusktRD7rxi7Rxg9TM by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp @hipsterelectron wdym banning forks? Like banning accounts that login … | |
| Post #AusktSxbMeTssOQmYK by [email protected] | |
| 0 likes, 0 repeats | |
| @hipsterelectron @ParetoOptimalDev @arianvp Lots. And it's run by nazis.The… | |
| Post #Ausktc51SQlTA0yKrw by [email protected] | |
| 0 likes, 0 repeats | |
| @ParetoOptimalDev @arianvp @delta I like https://delta.chat/en/ a lot. Seems se… | |
| Post #AusktcC724R5W0Hzv6 by [email protected] | |
| 0 likes, 0 repeats | |
| @pekka @ParetoOptimalDev @arianvp Delta uses the described method for push noti… | |
| Post #AusktcI8ffFxoh6oJU by [email protected] | |
| 0 likes, 0 repeats | |
| @feld @arianvp @ParetoOptimalDev Push notifications in Delta seem ok to me, tho… | |
| Post #AusktcPEFIvaAgQTMe by [email protected] | |
| 0 likes, 0 repeats | |
| @pekka @arianvp @ParetoOptimalDev wake the app, then it syncs is all it does AI… | |
| Post #AusktebM5Boeys7BXk by [email protected] | |
| 0 likes, 0 repeats | |
| @ParetoOptimalDev @arianvp SimpleX Chat uses APNS too:https://github.com/simple… | |
| Post #AusktrJknwSeQ2yoPg by [email protected] | |
| 0 likes, 0 repeats | |
| @astro I'm not exactly sure what eats all my battery, but with two Matrix c… | |
| Post #AusktrQ8QDZ6jpxuMK by [email protected] | |
| 0 likes, 0 repeats | |
| @wonka Check server info in Conversations, and maybe one Matrix client is enoug… | |
| Post #Ausku1K7bQhHS5EFNI by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp 2nd time I talk about this blog post today: https://unifiedpush.org/ne… | |
| Post #Ausku1RDB4Mto4XuQS by [email protected] | |
| 0 likes, 0 repeats | |
| @S1m Google publishes the amount of government requests for user data they rece… | |
| Post #Ausku1Xwm1kw8xhHvM by [email protected] | |
| 0 likes, 0 repeats | |
| @S1m I think it's a first that Apple is coming forward specifically with in… | |
| Post #AuskuD5JsHzFveOay8 by [email protected] | |
| 0 likes, 0 repeats | |
| @feld @arianvp @ParetoOptimalDev @feld Sorry, didn't quite catch what you m… | |
| Post #AuskuVp0DBDy2XuKfo by [email protected] | |
| 0 likes, 0 repeats | |
| @pekka @feld @arianvp @ParetoOptimalDev Feld was right even if a bit brief: Th… | |
| Post #AuskuVx9irkKRpiqNk by [email protected] | |
| 0 likes, 0 repeats | |
| @delta @pekka @feld @arianvp @ParetoOptimalDev Note that signal notifications a… | |
| Post #Auskuq0j9IUEehXyj2 by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp @hipsterelectron Signal with sealed sender enabled is set up such that… | |
| Post #AuskvPQTTYsWUgrXDU by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp and this is why you don't use #PushNotifications and espechally no… | |
| Post #AuskvRpiWgG5xYgiq8 by [email protected] | |
| 0 likes, 0 repeats | |
| @delta @pekka @feld @ParetoOptimalDev you're missing the point. I'm not… | |
| Post #AuskvSU86QaJytazpY by [email protected] | |
| 0 likes, 0 repeats | |
| @delta @pekka @feld @ParetoOptimalDev if delta doesn't integrate with these… | |
| Post #AuskvSoKtIkQzZ38KG by [email protected] | |
| 0 likes, 0 repeats | |
| @hipsterelectron https://functional.cafe/@arianvp/114626609850588449 | |
| Post #AuskvrCGE096ciQZwu by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp @delta @pekka @ParetoOptimalDev nobody else to my knowledge is doing t… | |
| Post #AuskvvKCsOsXQWAytE by [email protected] | |
| 0 likes, 0 repeats | |
| @astro I'd love to have only one Matrix client, but I'd need one that s… | |
| Post #Auskw5Wcx4kv3w42dc by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp @delta @pekka @feld @ParetoOptimalDevThe good thing for delta here is … | |
| Post #AuskwfNJfAhMFTz77g by [email protected] | |
| 0 likes, 0 repeats | |
| @ParetoOptimalDev @arianvp haskell bootstrap... | |
| Post #Auskx4vCgJexTp21ui by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp that's on me mastodon failed to load those replies. i'm sorry … | |
| Post #Auskx51aIalPnc17rM by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp linking to source code without an analysis is not actually proof of an… | |
| Post #AuskxkO0W83s51p70C by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp That's a good thing. This surveillance tool is known for years but… | |
| Post #AuskyVbmwi0mXNdHVY by [email protected] | |
| 0 likes, 0 repeats | |
| @ParetoOptimalDev Signal can also be used without APN or FCM. | |
| Post #AuskyccOspf0HIyMvw by [email protected] | |
| 0 likes, 0 repeats | |
| @walnut @feld @arianvp @ParetoOptimalDev @pekka @JustinDerrick the need for cen… | |
| Post #AuskyrGyOmQvjC3y7M by [email protected] | |
| 0 likes, 0 repeats | |
| @hipsterelectron @arianvp well, being owned by openly transphobic people, for o… | |
| Post #Auskz1DRQlYAZ8UI08 by [email protected] | |
| 0 likes, 0 repeats | |
| @Natanael_L @arianvp @hipsterelectron dude. it's a centralized service. the… | |
| Post #AuslIujfEYx6G82vuS by [email protected] | |
| 0 likes, 0 repeats | |
| @[email protected] But how could a server push notification to device if … | |
| Post #AuslIupgs9lyYorkIq by [email protected] | |
| 0 likes, 0 repeats | |
| @Orca you can't. I'm not saying their implementation is wrong. I'm … | |
| Post #AuslJ2ezlnyGpxvJk8 by [email protected] | |
| 0 likes, 0 repeats | |
| @[email protected] Yeah I remember there's an instant messaging proje… | |
| Post #AuslJ5lqCoEIU49KKW by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp I've been involved in numerous criminal cases where the Police sta… | |
| Post #AuslJ5rrqP3Amky8iu by [email protected] | |
| 0 likes, 0 repeats | |
| @dgold that is a different thing altogether. That's talking about the notif… | |
| Post #AuslJB32aHxUqrEdKi by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp I have to say that I am impressed at your patience because I would hav… | |
| Post #AuslJB94DsmN9Y3Rj6 by [email protected] | |
| 0 likes, 0 repeats | |
| @aroacemagicalnerd Thanks. I don't mind the questions. And I'm happy to… | |
| Post #AuslJEp0YP6uYUhU12 by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp @aroacemagicalnerd is molly with a known good unified push provider a … | |
| Post #AuslJJ1YvfWtaabZ8i by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp no google play services, no push notifications, no problem?Or is it no… | |
| Post #AuslJJ7wXwdLuNaf5M by [email protected] | |
| 0 likes, 0 repeats | |
| @dantalionyes, problem. because communication and security is a team sport. wil… | |
| Post #AuslJJDcCrAeByFBvU by [email protected] | |
| 0 likes, 0 repeats | |
| @zeh @dantalion so I think on Android the story is better as you can use your o… | |
| Post #AuslJun0WESwiS5TjE by [email protected] | |
| 0 likes, 0 repeats | |
| @Andromxda @onekind it's an identifier number that both you and apple store… | |
| Post #AuslJzYIoKfrUIFJ0C by [email protected] | |
| 0 likes, 0 repeats | |
| @dantalion correct. | |
| Post #AuslK1rAFAwydN5OgC by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp Hello, I have a question I hope you will not find offensive."Sign… | |
| Post #AuslK1xBsllqw3uD4a by [email protected] | |
| 0 likes, 0 repeats | |
| @mcc the server code is open source. I've linked to the code in the thread. | |
| Post #AuslK508YGuUO4J6a8 by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp thanks | |
| Post #AuslKVPYMOgoIQOlo8 by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp you’re explaining and documenting the part that I already believe; w… | |
| Post #AuslKVVvyfnGcDNrkm by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp specifically, I’m not seeing that all participants know the device i… | |
| Post #AuslKVcfZdBIx6XFFg by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp if this code meant what you say it means, then the list of devices is … | |
| Post #AuslKVk77x8VKC1Br6 by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat Correct signal stores your phone number. That's how they can verify y… | |
| Post #AuslKbO0950spLicDo by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp I don’t think I buy that - in https://signal.org/bigbrother/eastern-… | |
| Post #AuslKgG228bpw51ozg by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat @arianvp Signal was suspiciously silent on the topic of push tokens.When … | |
| Post #AuslKgOBXp8CLMqKhc by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat @arianvp I see 3 potential reasons for them being silent:1. They have bee… | |
| Post #AuslKgWL3VeYkeeqPY by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat @arianvp And FYI, Signal's privacy policy does say they store push to… | |
| Post #AuslKq3HcOLyJR8mVk by [email protected] | |
| 0 likes, 0 repeats | |
| @pixelschubsi @arianvp can you link to any instance of the question being put t… | |
| Post #AuslKqryZuu2qerGWe by [email protected] | |
| 0 likes, 0 repeats | |
| @gnat https://github.com/signalapp/Signal-Server/blob/a1b0c1a4aa03ee24cb37f0358… | |
| Post #AuslKtGreM02IQWAb2 by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp @gnat I just want to say that I'm grateful for your comments, both… | |
| Post #AuslL2oWAbGbtPKfnk by [email protected] | |
| 0 likes, 0 repeats | |
| @arianvp fair enough. I’m persuaded that if the feds have already managed to … | |
| Post #Av0DKSYL92HAFpziC0 by [email protected] | |
| 0 likes, 1 repeats | |
| @arianvp, US law states:"No provider of wire or electronic communication … |