@mattblaze I did wonder. I'm like, if they want some secure chat Signal is probably about as secure as any government solution that can just run on your phone, signal themselves can never see the contents of it, but the vector of attacking the device itself is a hard one to handle, which I assume is why the government still has that policy about not using stuff like this for secure communications. Hense the national security guy being in deep shit for more than just adding the wrong guy.

@x0 No, Signal is not as "secure as any government solution", because it lacks specific features for protecting classified material from going to the wrong places. Signal does a good job with the cryptography, but there's much more to it than that. Signal lacks security labels, authenticated identities with clearance levels, policy enforcement, etc. Those features make it virtually impossible to add a reporter to your war planning thread.

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://federate.social/users/mattblaze/statuses/114223837550859054 on your instance and quote it. (Note that quoting is not supported in Mastodon.)