Signal has started rolling out Signal Login, an optional registration method that allows users to create a Signal account without providing a phone number. The feature will be rolled out first on Android and will come to iOS later.

As we previously reported, Signal Login is not a free alternative registration method. Signal requires users who choose to register without a phone number to make a one-time payment. The price at launch is $2.99 / € 3.49, although this may vary by region and currency.

  • XLE@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    What do you think makes Delta Chat uniquely impervious to leaking your private key compared to the other E2EE messaging apps that do implement forward secrecy?

    • amzd@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 day ago

      I’m saying those others that pretend to implement pfs, still leak all chats the user didn’t delete (and in some cases even then) when an attacker has access to the private key because that’s stored in the same database.

      • XLE@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        13 hours ago

        Can we focus on the apps that do implement it instead? I’m getting more and more lost in the point you’re trying to make here.

        E2EE messaging puts encrypted messages on a server without the private keys. The concern PFS addresses is to prevent a server from getting one private key and using it to decrypt all messages. This is a vulnerability of Delta Chat, and not one of Signal.

        • amzd@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          9 hours ago

          Okay and how would you get that private key?

          By having access to an unlocked device: which means you also have access to all messages. Therefor this attack vector is not as big a deal as you are making it.

          • XLE@piefed.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            9 hours ago

            You are, by extension, saying that PFS is not as big a deal as you are making it. Do you have anything to back this up that Signal et al aren’t aware of?

            With DeltaChat, you can get a private key just by accessing a file on a desktop client. Or a backup file . Then you can pass that onto a compromised server and restore chat history that wasn’t present on the client or backup file.