How would it do that? While the Play Services app has more privileges than many other apps on a device, it's still running in an application sandbox, and shouldn't have permission to read the Signal app's data or attach…
The notifications Signal pops up, with contact name and message text, are generated from within the app itself, not sent via Google. It does receive some Firebase messages from Google, but not the type that…
Does anyone know why Signal has decided to not let people sign up without a phone number? That would avoid any such vector relating to SMS, albeit at the expense of making it more difficult to recover an account from a…
In what way does a Play Services dependency make them insecure?
How would it do that? While the Play Services app has more privileges than many other apps on a device, it's still running in an application sandbox, and shouldn't have permission to read the Signal app's data or attach…
The notifications Signal pops up, with contact name and message text, are generated from within the app itself, not sent via Google. It does receive some Firebase messages from Google, but not the type that…
Does anyone know why Signal has decided to not let people sign up without a phone number? That would avoid any such vector relating to SMS, albeit at the expense of making it more difficult to recover an account from a…
In what way does a Play Services dependency make them insecure?