frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Signal knows who you're talking to

https://sanesecurityguy.com/articles/signal-knows-who-youre-talking-to/
35•kekqqq•47m ago

Comments

defraudbah•26m ago
people often confuse privacy with anonymity, like in this article.

the question was if signal is secure and private, and the answer is about anonymity

is it secure and private - it is, is it anonymous - it's not, or at least, to some degree

jijijijij•4m ago
Hm. I think, you are confusing general privacy with confidentiality. Observing who I am talking to definitely falls into the privacy domain.

Eg. you are talking to an HIV medical specialist. This inherently has privacy implications, if observable. Likewise, you wouldn't say DNS has no privacy implications.

Anonymity would rather mean, you (or anyone) don't know who exactly you are talking to.

My_Name•26m ago
You can't have end to end encryption without ends. That said, I have managed to write encrypted end to end communication, using wireguard no less, that doesn't tell a third party server who is talking, or what they are saying.

This is single user talking to single user, though. I know it gets more complex when you have more users than that.

zoobab•21m ago
First question after Moxie Marlinspike talk at the CCC conference was: "When will Signal not base itself on a mobile phone number, I am an activist from Iran"

https://media.ccc.de/v/36c3-11086-the_ecosystem_is_moving

udev4096•11m ago
"Never"
guytv•10m ago
what was his answer?
sturza•19m ago
The critique of metadata being hard is fair, the claim that sealed sender is “totally useless” is not. It’s a small, incremental hardening step in a very messy design space, not a magic invisibility cloak, and judging it as the latter sets the bar unrealistically high for anything that still wants to be a drop-in WhatsApp replacement.
HelloUsername•19m ago
I thought you can register Signal with a virtual number, then in settings simply hide the phone number, and create new chats with your username?

Also, what about Briar/Berty as alternative?

https://play.google.com/store/apps/details?id=org.briarproje...

https://apps.apple.com/app/id1535500412

sandblast•17m ago
Since a lot of people might not reach the conclusion at the bottom of the post:

Just use SimpleX.

w1nt3rmut3•14m ago
Simplex is developed by a person who has a rather difficult view of the world. I would not recommend using it as long as this person is responsible for it.
guytv•7m ago
> Simplex is developed by a person who has a rather difficult view of the world. couldn't find it. what's his view of the world?
sandblast•7m ago
I don't know what you're mentioning, but let's not forget that whatever view he might have, it changes nothing in the technology he creates. It's open source, it's auditable, and the code does not have worldviews of its own.

Your comment promotes cancel-culture, and as filthy as it is in general, it's even more is in the technology world. Don't do it. Please.

Xiol•3m ago
At first I was like, how difficult?

That is quite the Twitter timeline.

bjoli•13m ago
I always thought sealed sender was something they implemented for their own sake. The less metadata they can see is better. As a user that means you have to trust them in what they say regarding the data they keep anyway.

Regarding sealed sender I don't think they ever fixed the statistical method of identifying sealed senders described in the "improving sealed sender" paper from 2019 (?), meaning it is pretty useless anyway if signal decided they wanted to identify senders.

jwr•12m ago
Signal is in an impossible position. On one hand, it needs to appeal to the crowds currently using WhatsApp and happily syncing their entire contact list to Facebook/Meta, so that they can be profiled and a social graph can be built. That crowd needs it to be super simple and "just work". If it doesn't do that, people will criticize it for being difficult to use.

On the other hand, it needs to provide ultimate security, even though there is always a compromise between security and convenience. If it doesn't, geeks will criticize it for not being secure enough.

Signal knows who you're talking to

https://sanesecurityguy.com/articles/signal-knows-who-youre-talking-to/
37•kekqqq•47m ago•16 comments

After my dad died, we found the love letters

https://www.jenn.site/after-my-dad-died-we-found-the-love-letters/
137•eatitraw•2h ago•37 comments

Unusual circuits in the Intel 386's standard cell logic

https://www.righto.com/2025/11/unusual-386-standard-cell-circuits.html
122•Stratoscope•7h ago•17 comments

A monopoly ISP refuses to fix upstream infrastructure

https://sacbear.com/xfinity-wont-fix-internet/
280•vedmed•10h ago•118 comments

GCC SC approves inclusion of Algol 68 Front End

https://gcc.gnu.org/pipermail/gcc/2025-November/247020.html
126•edelsohn•8h ago•46 comments

The privacy nightmare of browser fingerprinting

https://kevinboone.me/fingerprinting.html
566•ingve•18h ago•354 comments

We Induced Smells With Ultrasound

https://writetobrain.com/olfactory
491•exr0n•1d ago•130 comments

WorldGen – Text to Immersive 3D Worlds

https://www.meta.com/en-gb/blog/worldgen-3d-world-generation-reality-labs-generative-ai-research/
208•smusamashah•13h ago•69 comments

Ubuntu LTS releases to 15 years with Legacy add-on

https://canonical.com/blog/canonical-expands-total-coverage-for-ubuntu-lts-releases-to-15-years-w...
117•taubek•2d ago•48 comments

Almost all Collatz orbits attain almost bounded values

https://mathvideos.org/2023/terence-tao-almost-all-collatz-orbits-attain-almost-bounded-values/
5•measurablefunc•5d ago•0 comments

NTSB report: Decryption of images from the Titan submersible camera [pdf] (2024)

https://data.ntsb.gov/Docket/Document/docBLOB?ID=18741602&FileExtension=pdf&FileName=Underwater%2...
117•bmurray7jhu•10h ago•57 comments

Show HN: Forty.News – Daily news, but on a 40-year delay

https://forty.news
292•foxbarrington•16h ago•121 comments

Meta buried 'causal' evidence of social media harm, US court filings allege

https://www.reuters.com/sustainability/boards-policy-regulation/meta-buried-causal-evidence-socia...
340•pseudolus•10h ago•129 comments

The Boring Part of Bell Labs

https://elizabethvannostrand.substack.com/p/the-boring-part-of-bell-labs
106•AcesoUnderGlass•3d ago•19 comments

MCP Apps just dropped (OpenAI and Anthropic collab) and I think this is huge

http://blog.modelcontextprotocol.io/posts/2025-11-21-mcp-apps/
49•mercury24aug•7h ago•17 comments

The 1957 “Spaghetti-Grows-on-Trees” Hoax

https://www.openculture.com/2025/11/the-1957-spaghetti-grows-on-trees-hoax.html
29•PaulHoule•1w ago•13 comments

CERN Council reviews feasibility study for a next-generation collider

https://home.cern/news/press-release/accelerators/cern-council-reviews-feasibility-study-next-gen...
23•elashri•1w ago•5 comments

`satisfies` is my favorite TypeScript keyword (2024)

https://sjer.red/blog/2024-12-21/
174•surprisetalk•4d ago•149 comments

$1900 Bug Bounty to Fix the Lenovo Legion Pro 7 16IAX10H's Speakers on Linux

https://github.com/nadimkobeissi/16iax10h-linux-sound-saga
259•rany_•1w ago•115 comments

Pixel Art Tips for Programmers

https://jslegenddev.substack.com/p/5-pixel-art-tips-for-programmers-3d6
109•ibobev•1d ago•25 comments

Google Revisits JPEG XL in Chromium After Earlier Removal

https://windowsreport.com/google-revisits-jpeg-xl-in-chromium-after-earlier-removal/
84•eln1•5h ago•18 comments

Show HN: Build the habit of writing meaningful commit messages

https://github.com/arpxspace/smartcommit
74•Aplikethewatch•14h ago•93 comments

Simplifying Cluster-Wide PostgreSQL Execution with Exec_node() and Spock OSS

https://www.pgedge.com/blog/simplifying-cluster-wide-sql-execution-in-pgedge-with-exec_node
5•pgedge_postgres•6d ago•0 comments

China reaches energy milestone by "breeding" uranium from thorium

https://www.scmp.com/news/china/science/article/3331312/china-reaches-energy-independence-milesto...
292•surprisetalk•17h ago•248 comments

Show HN: A tool to safely migrate GitHub Actions workflows to Ubuntu-slim runner

https://github.com/fchimpan/gh-slimify
52•r4mimu•1w ago•2 comments

Windows ARM64 Internals: Deconstructing Pointer Authentication

https://www.preludesecurity.com/blog/windows-arm64-internals-deconstructing-pointer-authentication
61•todsacerdoti•13h ago•2 comments

Markdown is holding you back

https://newsletter.bphogan.com/archive/issue-45-markdown-is-holding-you-back/
124•zdw•15h ago•85 comments

Garibaldi, History's Sexiest Revolutionary?

https://www.historyextra.com/period/victorian/historys-sexiest-revolutionary-meet-the-mesmerising...
36•thomassmith65•1w ago•30 comments

Tektronix equipment has been used in many movies and shows

https://vintagetek.org/tektronix-in-movies-shows/
106•stmw•6d ago•28 comments

The realities of being a pop star

https://itscharlibb.substack.com/p/the-realities-of-being-a-pop-star
229•lovestory•17h ago•141 comments