

Unpopular takes incoming.
Signal.
Way too many red flags.
- Why ask for mandatory phone numbers? You could at least make it opt in.
- Why we can’t inspect the latest server code?
- Why not make it easy for people to run their own servers?
Do you truly believe that a company that wants to preserve your privacy would take this direction?
And i don’t care how secure the protocol is, how well the code is audited. They can still map your social graph.
Anyways, because of my threat model, i still use Signal. But if i were an activist i wouldnt touch it.
More unpopular takes:
Tor and Mullvad probably compromised too. If a service gets too mainstream, I dont believe for a second that they would let it run without care. They would take it down, or control it.
Now, these services are still usefull. For example mt threat model is to deny my shit to the big tech. So they are useful if you want to escape data collection for adversiment purposes.
I don’t think they would burn the reputation of these services for low hanging fruit like selling data for ads.






The Crypto AG story shows that the location of a company doesn’t matter that much. The US simply made legal what they were already doing behind the scenes. Intelligence services have always been and still are above the law.