How Trail of Bits helps verify the integrity of Signal chats
dgroshev
69 points
41 comments
September 12, 2026
Related Discussions
Found 5 related stories in 58.8ms across 6,361 title embeddings via pgvector HNSW
- Automatic Key Verification meetpateltech · 22 pts · August 11, 2026 · 54% similar
- Compromising Signal's Contact Discovery Enclave (SGX) RobLach · 11 pts · August 27, 2026 · 50% similar
- Trusted URLs via Cryptographic Signatures Edmond · 28 pts · July 30, 2026 · 47% similar
- Mysteries of Telegram Data Centers (2022) theanonymousone · 251 pts · July 15, 2026 · 43% similar
- Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware rzk · 38 pts · July 27, 2026 · 42% similar
Discussion Highlights (3 comments)
chews
I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.
pizzaiolo
Bit of a positive piece amid a negative headline this week: https://cybernews.com/privacy/police-telegram-whatsapp-signa...
iamshs
Recently a bureaucrat who wanted to make a mass protest out of his criticism of Indian Election Commission's drive to remove voters, was picked up by Indian Police and his Signal metadata was accessible to the Police. What is the solution to this thing? His interview does not tell us if it was metadata or actual calls that were surveilled which could point to device compromise too. "What caught him by surprise, he told ThePrint, was the Special Cell officers' access to his calls made via Signal" https://theprint.in/india/ex-civil-servant-ashish-joshi-reca...