this post was submitted on 01 Sep 2025
        
      
      80 points (96.5% liked)
      Open Source
    41627 readers
  
      
      240 users here now
      All about open source! Feel free to ask questions, and share news, and interesting stuff!
Useful Links
- Open Source Initiative
- Free Software Foundation
- Electronic Frontier Foundation
- Software Freedom Conservancy
- It's FOSS
- Android FOSS Apps Megathread
Rules
- Posts must be relevant to the open source ideology
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
- !libre_culture@lemmy.ml
- !libre_software@lemmy.ml
- !libre_hardware@lemmy.ml
- !linux@lemmy.ml
- !technology@lemmy.ml
Community icon from opensource.org, but we are not affiliated with them.
        founded 6 years ago
      
      MODERATORS
      
    you are viewing a single comment's thread
view the rest of the comments
    view the rest of the comments
Your statement was that phone numbers make users identifiable. If they don't have my phone number, how can they use it to identify me?
I don't know if you've noticed but it's nearly impossible to exist without a SIM these days. You can't even access your bank account remotely. But I suppose you only have a home phone and don't have internet access outside of WiFi?
You're lying. You don't need to verify it at "random intervals", you only need it once when you initially sign up. You're just spreading misinformation at this point.
It's not, but please do elaborate.
You know what else is funded by the gov? TOR. But I suppose that's compromised as well? Which also compromises many of the messengers using the TOR network?
I don't support phone # verification, but they do have valid reasons for it, and it doesn't compromise the service at all, as you claim, because the only things tied to your phone number is:
Which isn't really super useful information to the gov. And in order to get that info they have to ALREADY HAVE YOUR #. Which, of course, they do already have everyone's #. It's not exactly private information.
Thanks! :)
But no. Happened to several friends of mine, out of the blue: phone# verification to their signal account. Therefore when accusing people of lying... you are lying! :)
It's not just about "having your phone number", it is indeed relating it to the phone numbers of all the people you interact with, and (at least) processing these data in the RAM of amazon servers while promising they do not use or store it. It is strongly identifying "strong selector" metadata that is incompatible with the protection of users' privacy.
You can call me a lier, but you better check your sources.
Please provide evidence when you make such wild claims.
Evidence is: Signal still requires a phone# that is your unique identifier. Thus when connecting two parties, it is bound to have identifying metadata about them. (and that Signal still operates within AWS cloud, and is bound by US law: FISA, Patriot Act, etc.) How much more than this do you need?
This does not even remotely resemble evidence.
No it isn't.
There's no law in existence that requires them to store metadata or hand anything over to the feds. They have been subpoenaed several times and it always comes out the same: the only data they have is what I detailed above. Even if they DO have it (which they don't) they don't provide it, which is effectively the same thing.
Literally anything legitimate.
It is just enough that this metadata be handled within the computing environment of Amazon. Their refusal for anyone use their own server and federate with "their" (as in captive) users also prevents anyone for using it in any other way...
If you dont see that Signal requires that its users use a strong-selector phone# in order to use the service, there is nothing i can do for you.
If you're unable to explain or provide evidence as to why any of that is problematic, there's nothing I can do for you.
Authorities don't need to ask Signal for metadata; Signal promises they don't log any themselves and that is probably true.
But, they outsource their server operation to Jeff Bezos, and then they do some absurd security theater to pretend that cryptography makes it so that the server (Amazon) couldn't possibly log metadata - which is obviously false.
You think Bozos has access to information that Signal does not?