zlacker

[parent] [thread] 2 comments
1. jwr+(OP)[view] [source] 2020-06-05 10:21:00
Not the full contact list, just hashes.

That was exactly my point: few people know about this.

replies(2): >>est31+S >>CultOf+Hl6
2. est31+S[view] [source] 2020-06-05 10:28:38
>>jwr+(OP)
A hash of the phone number is as good as the phone number itself. Given a list of all phone numbers in use, it's trivial to build a rainbow table for them. And many you can also brute-force.
3. CultOf+Hl6[view] [source] 2020-06-07 22:11:39
>>jwr+(OP)
Actually Signal is uploading contacts with their first and lastname to the cloud now. Or is planning to do so. Read their blog about that f-ing PIN feature. Its explained there. I hope they don’t go through with it, I absolutely do not wish to use some cloud; not even Signal’s. My data should be 100% local. And that they’re gonna push this without a back-up feature for iOS feels a bit like them raising their middle finger to us.
[go to top]