• 0 Posts
  • 13 Comments
Joined 3 years ago
cake
Cake day: July 6th, 2023

help-circle



  • Fwiw: signal is a honey pot, perhaps not by intent but by architecture.

    Security postures are driven by capabilities not intentions.

    Signal:

    • centralized
    • uses centralized push notifications
    • stores encryption keys in the cloud SVR

    Thus a three letter agency has the capability of breaking signal, even if they don’t intend to.

    As a thought experiment imagine you run the intelligence service of a non-us ally country (nk, Iran, China, Russia, etc) - would you in good faith recommend using signal, as is, for your classified and sensitive government communications?

    how to break signal

    SVR stores master key backed by a trivial pin, but uses Intel sgx enclaves to prevent brute forcing… a TLA just gets Intel to sign new code for the sgx enclave that allows brute forcing, runs it against the cloud data extracts master keys, and ta da all communication revealed.

    Signal allows people to store their master key using a random bip32 key, but even if you do this, none of your contacts will do this









  • If you have a international branch of a Chinese bank nearby setup a account. Icbc is everywhere. If your visa allows it get a local bank account setup asap! Makes life so much easier

    Consider a VPN like obscura which proxies behind http3 quic for harder identification

    I’ve had success with mullvad in china myself. Get two vpns setup.

    If you bring a sim card with you, the data is usually routed out of china to your home providers network without filtering.

    Bring a backup cell phone, no particular reason, it’s just good to have a backup setup Incase you lose your main phone.


    The major problem isn’t getting a VPN to work, it’s having it work when you need it. VPNs in China go up and down all the time. If your meeting someone and need to message them and the VPN is down… Your going to have a bad time.


    Privacy: everything you do in china will be monitored, all your traffic patterns, every WeChat and qq message. If you want to have interesting conversations try to move them to signal or simplex over a VPN.