47
Comments (12)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
6
DoubleEagle 6 points ago +7 / -1

Signal is fine, stop with the FUD. Why not make posts about how session uses the Google notification servers, if you actually want to receive messages?

1
wumao [S] 1 point ago +1 / -0

You have the option which way you decide to receive notifications.

Android

Session’s Android client has two options for notifications: background polling, and Firebase Cloud Messaging.

If you choose the background polling method, the Session application runs in the background and periodically polls its swarm for new messages. If a new message is found, it is presented to the user as a local notification.

If you choose Firebase Cloud Messaging (FCM), Session will use Google’s FCM push notification service to deliver push notifications. Your device IP and device ID are exposed to Google and a push notification server. The push notification server also knows your Session ID. However, this doesn’t mean much, because Google already knows your device IP and ID, and as long as you keep your Session ID private, the push notification server can’t do much with that information. Neither Google nor the Loki Foundation can see the contents of your messages, who you’re talking to, or exactly when messages are received.

1
DoubleEagle 1 point ago +1 / -0

The app explicitly tells me to not use background polling, because it doesn't work well.

So either signal gets phone number or google gets the fact that I'm using session. Neither service can't see the contents of my messages.

Do you know much about signal analysis? Comparing these two systems, if I'm to trust session and use FCM as it recommends, session is leaking more data. Especially if Signal is combined with a VPN.

1
wumao [S] 1 point ago +1 / -0

So either signal gets phone number or google gets the fact that I'm using session.

I don't use FCM and Signal doesn't have my number, so your logic doesn't apply to me.

1
DoubleEagle 1 point ago +1 / -0

So you go against session's advice about how to use it? Opting for the unreliable method?

Security has three primary components, Confidentiality, Integrity, and Availability. Unreliable message delivery is an Availability failure.

This is just signal FUD from someone willing to accept a huge security fault, which you aren't disclosing up front.