top | item 46791636

(no title)

Grisu_FTP | 1 month ago

I might be misremembering or mixing memories but i remember something about them only storing the hash of the number.

So the FBI cant ask what phone number is tied to an account, but if a specific phone number was tied to the specific account? (As in, Signal gets the number, runs it through their hash algorythm and compares that hash to the saved one)

But my memory is very very bad, so like i said, i might be wrong

discuss

order

account42|1 month ago

It would be absolutely trivial for the FBI to hash every single assigned phone number and check which one matches. Hashing only provides any anonymity if the source domain is too large to be enumerable.

kreetx|1 month ago

Brief research says that Signal does store phone numbers.

Regarding hashing: while unsalted phone number hashes would be easy to reverse then I doubt that any hashing scheme today is set up like that.