• ryannathans
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    2
    ·
    10 months ago

    Can LEO tie a username to a phone number?

    • Vent@lemm.ee
      link
      fedilink
      English
      arrow-up
      8
      ·
      10 months ago

      From Signal’s blog footnotes:

      Usernames in Signal are protected using a custom Ristretto 25519 hashing algorithm and zero-knowledge proofs. Signal can’t easily see or produce the username if given the phone number of a Signal account. Note that if provided with the plaintext of a username known to be in use, Signal can connect that username to the Signal account that the username is currently associated with. However, once a username has been changed or deleted, it can no longer be associated with a Signal account.