• ᗪᗩᗰᑎ@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    10 months ago

    Not necessarily.

    Signal has people who are experts in their field. They engineer solutions that don’t exist anywhere else in the market to ensure they have as little information on you as possible while keeping you secure [0]. This in turn means high compensation + benefits. You don’t want to be paying your key developers peanuts as that makes them liable to taking bribes from adversaries to “oops” a security vulnerability in the service. In addition, the higher compensation is a great way to mitigate losing talent to private organizations who can afford it.

    [0] Signal has engineered the following technologies that all work to ensure your privacy and security:

    • kpw@kbin.social
      link
      fedilink
      arrow-up
      0
      ·
      10 months ago

      At least the private contact discovery is not very private:

      The client calculates the truncated SHA256 hash of each phone number in the device’s address book.
      The client transmits those truncated hashes to the service.

      Phone numbers are so not-sparse that there even was a game to text your “number neighbor”. I can probably build a pretty effective rainbow table for this with my current hardware.