Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is why there is a fingerprint ("Safety Numbers" in Signal), and a warning on every message when that fingerprint changes.


Warning still does not fully prevent the attack. The attacker can still access the account and obtain the data stored at a server (like contact list if it is stored there).


> like contact list if it is stored there

The only thing that we know they store is the creation timestamp and last-seen timestamp for each account: http://arstechnica.com/tech-policy/2016/10/fbi-demands-signa...

Reading over the article again, though, it neither confirms nor denies where these timestamps are the only thing stored about an account. They explain these are the only data matching the concrete subpoena they received.


Which everyone, including myself, clicks through.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: