I don't understand how a company based in the US and one that requires a phone number can make any kind of claims about security or privacy, without being looked on as a honeypot untill it redeems itself with evidence to the contrary.
Why would a privacy centric protocol choose to use a phone number which directly connects a user to their identity. How can this make sense?
There is enough evidence most US based companies are in bed with the nsa, compromised or can be easily compromised.
Companies or open source projects can be bullied and threatened by government officals, legally forced to give up their users, gagged and forced to betray users, co-opted, infiltrated or compromised. Lavabit has already happened.
Why do we need encryption, security or privacy? If it is exclusively against state actors then we know its a serious challenge against extremely powerful, well resourced, and legally empowered actors and illusions of privacy, hand flailing 'something is better than nothing' and half baked measures won't do.
It's reasonable then to expect any solution claiming security or privacy in this context to explicitly spell out how they address or plan to address these threat models. The alternative is acting in bad faith and making users vulnerable.
Why would a privacy centric protocol choose to use a phone number which directly connects a user to their identity. How can this make sense?
There is enough evidence most US based companies are in bed with the nsa, compromised or can be easily compromised.
Companies or open source projects can be bullied and threatened by government officals, legally forced to give up their users, gagged and forced to betray users, co-opted, infiltrated or compromised. Lavabit has already happened.
Why do we need encryption, security or privacy? If it is exclusively against state actors then we know its a serious challenge against extremely powerful, well resourced, and legally empowered actors and illusions of privacy, hand flailing 'something is better than nothing' and half baked measures won't do.
It's reasonable then to expect any solution claiming security or privacy in this context to explicitly spell out how they address or plan to address these threat models. The alternative is acting in bad faith and making users vulnerable.