Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Anonymity isn't part of Signal's risk model. If you need to stay anonymous, then there are more suitable options.


It's not about that, it's pretty much the same as using a dynamic IP to authenticate you


Not really, a phone isn't assigned a random number from a pool every time you turn it on or reconnect to a tower, then given to other users ad hoc.

A static IP maybe, except the IP is portable to a new AS if/when you want to move to a new provider. It's even susceptible to a false BGP route =)


It is not about being anonymous (though this also could be nice in some situations), it is about identity theft and credentials theft. There are numerous ways to steal my phone number and then impersonate me on Signal. For me, it is not a big deal (though a dedicated hater can probably ruin my life with that). For many people in sensitive positions, this is literally a matter of life and death.


On average, stealing a phone number is much more difficult than stealing someone's password, because of the frequency of password reuse and data breaches.

If someone were to do that, it would be blocked by registration lock (which it prompts you to do). If they were to guess that, all your contacts would be notified that your identity has changed.


My phone number (and probably yours) are in the Facebook 2019-2021 leaks. These are easily downloadable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: