This is a year-old paper but now there is an easy-to-use implementation of the attack: https://github.com/gommzystudio/device-activity-tracker
Signal developers’ verdict is WONTFIX: https://github.com/signalapp/Signal-Android/pull/14463
Is there any reason to use Signal over Matrix?
https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/
This is the most strongly written writeup I know of (whether it’s something you, likewise, find worth being wary about is, naturally, up to you, though).
I remember trying to sign up for signal and stopped when it wanted my phone number. It’s no longer anonymous at that point. When I talk about it theres always people who come at me about it being secure and whats my attack vector? Well, its not secure. My vector is a desire to be anonymous, and clearly the anonymity this presents is a facade.




