🌐 Website Issue | Should Signal (Android) have a warning about the insecurity of SMSes? #1573

Closed
opened 2019-12-05 22:29:16 +00:00 by Mikaela · 3 comments
Mikaela commented 2019-12-05 22:29:16 +00:00 (Migrated from github.com)

Description

Currently the card just says:

All communications are E2EE unless you choose to send as SMS.

I wonder if it should be expanded to warn about SMSes in general and how the carrier can read them and store/share them and what other problems there are? Or perhaps there should be a blog post we could link to?

This was brought up to me as a result of a private query asking about #859 and referring to Signal's metadata when SMS option is chosen.

## Description Currently the card just says: > All communications are E2EE unless you choose to send as SMS. I wonder if it should be expanded to warn about SMSes in general and how the carrier can read them and store/share them and what other problems there are? Or perhaps there should be a blog post we could link to? This was brought up to me as a result of a private query asking about #859 and referring to Signal's metadata when SMS option is chosen.
blacklight447 commented 2019-12-06 07:01:11 +00:00 (Migrated from github.com)

Ehh, as this isn't a signal issue, i would say your better off making a seperate section of why sms is bad.

Ehh, as this isn't a signal issue, i would say your better off making a seperate section of why sms is bad.
danarel commented 2019-12-06 17:21:56 +00:00 (Migrated from github.com)

This was discussed in a group chat a while back and I think it fell somewhere in the realm that @blacklight447-ptio mentioned. The insecurity of SMS isn't Signal's fault and they make no claim that if you choose to use Signal as your SMS messenger than those texts are E2EE.

The description on PT also states "All communications are E2EE unless you choose to send as SMS." - which I would say makes it clear enough that this is the case. I think a warning would be overkill and make it seem as though it's a security flaw in Signal.

This was discussed in a group chat a while back and I think it fell somewhere in the realm that @blacklight447-ptio mentioned. The insecurity of SMS isn't Signal's fault and they make no claim that if you choose to use Signal as your SMS messenger than those texts are E2EE. The description on PT also states "All communications are E2EE unless you choose to send as SMS." - which I would say makes it clear enough that this is the case. I think a warning would be overkill and make it seem as though it's a security flaw in Signal.
Mikaela commented 2019-12-07 19:02:44 +00:00 (Migrated from github.com)
https://github.com/privacytoolsIO/privacytools.io/issues/1578
This repo is archived. You cannot comment on issues.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#1573
No description provided.