Signal cloud backups: Difference between revisions
Kestrelbird (talk | contribs) m Edited tone, and tried to make phrasing more clear |
Kestrelbird (talk | contribs) m changed formatting for better readability. |
||
| Line 6: | Line 6: | ||
==Background== | ==Background== | ||
Over the years Signal has curated a reputation that they do not collect or keep data on their users. | Over the years Signal has curated a reputation that they do not collect or keep data on their users. Signal has publicly disclosed that they have received legal requests for subscriber's names, telephone numbers, histories, and contacts and Signal has said that they were unable to supply that information because it was never collected by Signal in the first place. These incidents have been reported in the media.<ref>{{Cite web |title=FBI demands Signal user data, but there’s not much to hand over |url=https://arstechnica.com/tech-policy/2016/10/fbi-demands-signal-user-data-but-theres-not-much-to-hand-over/ |archive-url=https://web.archive.org/web/20240401002649/https://arstechnica.com/tech-policy/2016/10/fbi-demands-signal-user-data-but-theres-not-much-to-hand-over/ |archive-date=1 Apr 2024 |access-date=6 Mar 2025}}</ref> Signal's website states:<ref name=":0">{{Cite web |title=Grand jury subpoena for Signal user data, Eastern District of Virginia |url=https://signal.org/bigbrother/eastern-virginia-grand-jury/ |archive-url=https://web.archive.org/web/20250302042109/https://signal.org/bigbrother/eastern-virginia-grand-jury/ |archive-date=2 Mar 2025 |access-date=6 Mar 2025}}</ref> | ||
''"We’ve designed the Signal service to minimize the data we retain about Signal users, so the only information we can produce in response to a request like this is the date and time a user registered with Signal and the last date of a user’s connectivity to the Signal service.'' | |||
''"We’ve designed the Signal service to minimize the data we retain about Signal users, so the only information we can produce in response to a request like this is the date and time a user registered with Signal and the last date of a user’s connectivity to the Signal service.'' | |||
''Notably, things we don’t have stored include anything about a user’s contacts (such as the contacts themselves, a hash of the contacts, any other derivative contact information), anything about a user’s groups (such as how many groups a user is in, which groups a user is in, the membership lists of a user’s groups), or any records of who a user has been communicating with."'' | ''Notably, things we don’t have stored include anything about a user’s contacts (such as the contacts themselves, a hash of the contacts, any other derivative contact information), anything about a user’s groups (such as how many groups a user is in, which groups a user is in, the membership lists of a user’s groups), or any records of who a user has been communicating with."'' | ||
==Incident== | ==Incident== | ||
In 2019, Signal previewed a feature called "secure value recovery".<ref>{{Cite web |title=Technology Preview for secure value recovery |url=https://signal.org/blog/secure-value-recovery/ |archive-url=https://web.archive.org/web/20241228040757/https://signal.org/blog/secure-value-recovery/ |archive-date=28 Dec 2024 |access-date=6 Mar 2025}}</ref> This feature would allow users installing signal on a new device to pull down the user's encrypted data from cloud servers.<ref>{{Cite web |title=Technology Preview for secure value recovery |url=https://signal.org/blog/secure-value-recovery/ |archive-url=https://web.archive.org/web/20241228040757/https://signal.org/blog/secure-value-recovery/ |archive-date=28 Dec 2024 |access-date=6 Mar 2025}}</ref> | In 2019, Signal previewed a feature called "secure value recovery".<ref>{{Cite web |title=Technology Preview for secure value recovery |url=https://signal.org/blog/secure-value-recovery/ |archive-url=https://web.archive.org/web/20241228040757/https://signal.org/blog/secure-value-recovery/ |archive-date=28 Dec 2024 |access-date=6 Mar 2025}}</ref> This feature would allow users installing signal on a new device to pull down the user's encrypted data from cloud servers.<ref>{{Cite web |title=Technology Preview for secure value recovery |url=https://signal.org/blog/secure-value-recovery/ |archive-url=https://web.archive.org/web/20241228040757/https://signal.org/blog/secure-value-recovery/ |archive-date=28 Dec 2024 |access-date=6 Mar 2025}}</ref> The feature has been accused of being a breach of privacy, with claims that Signal would start collecting the same kinds of information that Signal had been getting legal requests to turn over, and that Signal would keep that data in the cloud. As discussed later on, whilst the data is stored in the cloud, it is stored in a securely encrypted manner.<ref name=":7" /> | ||
The data being collected and stored in the cloud includes the user's name, photo, phone number, and a list of every Signal user they have contacted.<ref>{{Cite web |title=What contact info does the Signal PIN functionality actually save |url=https://community.signalusers.org/t/what-contact-info-does-the-signal-pin-functionality-actually-save/16854/4 |access-date=6 Mar 2025}}</ref>{{DisputedInline|Cited source is heavily cherry picked|reason=contact discovery on Signal is private and does not share the phone number as explained later in the cited sources}} Messages are not saved, however. | The data being collected and stored in the cloud includes the user's name, photo, phone number, and a list of every Signal user they have contacted.<ref>{{Cite web |title=What contact info does the Signal PIN functionality actually save |url=https://community.signalusers.org/t/what-contact-info-does-the-signal-pin-functionality-actually-save/16854/4 |access-date=6 Mar 2025}}</ref>{{DisputedInline|Cited source is heavily cherry picked|reason=contact discovery on Signal is private and does not share the phone number as explained later in the cited sources}} Messages are not saved, however. | ||