• Arthur Besse@lemmy.mlOP
    link
    fedilink
    English
    arrow-up
    11
    ·
    edit-2
    16 hours ago

    You can literally turn off read receipts in signal

    But you can’t turn off delivery receipts, which is what this attack uses.

    • ryannathans@aussie.zone
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      15 hours ago

      But you can turn off sealed sender messages from anyone, so they’d have to already be a trusted contact

      • Arthur Besse@lemmy.mlOP
        link
        fedilink
        English
        arrow-up
        10
        ·
        15 hours ago

        But you can turn off sealed sender messages from anyone, so they’d have to already be a trusted contact

        The setting to mitigate this attack (so that only people who know your username can do it, instead of anybody who knows your number) is called Who Can Find Me By Number. According to the docs, setting it to nobody requires also setting Who Can See My Number to nobody. Those two settings are both entirely unrelated to Signal’s “sealed sender” thing, which incidentally is itself cryptography theater, btw.