When I first looked at this, it boggled my mind that they require a phone number to sign up. Maybe that's no longer the case? But assuming it is, it just struck me as the epitome of breaking away from the concept of secure anonymity.
You are absolutely right! Plus, getting a copy of all your contacts is and invasion of privacy for an app that is advocating for privacy and security.
You cant even use a online voip phone number for this app. Its just such a turn off and I'm extremely disappointed with endorsements from people like Snowden ignoring such fundamental flaws.
In fact, what you just claimed is wrong. The app waits for the phone to receive the text and there is no way to enter the verification code you receive in another voip app.
This is on top of not being able to use this app on multiple devices.
I have tried that and it didnt work but I'll give it a try one more time.
Regarding multiple devices I mean multiple mobile devices (iOS and Android apps) and not through a browser and extension.
> Plus, getting a copy of all your contacts is and invasion of privacy for an app that is advocating for privacy and security.
You really need to do research into this before making this claim. The phone numbers are hashed (Or something like it) before being sent to the Signal servers.
Unfortunately, hashing provides no meaningful protection here. The preimage space (i.e. the set of all possible phone numbers) is just too small. See https://whispersystems.org/blog/contact-discovery/
I thought the system was supposed to provide encryption to known communication, not anonymity?
If that's the case, choosing to use an existing identity management system most people are part of is an excellent bootstrapping decision. Identity management is hard, and it's a fair problem to punt on if it's not your focus.
Encryption != anonymity. (In fact, it usually does the opposite, because encrypted messages stand out.)