Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Phone number sharing behaviour #5765

Open
S5NC opened this issue Feb 23, 2024 · 0 comments
Open

Phone number sharing behaviour #5765

S5NC opened this issue Feb 23, 2024 · 0 comments

Comments

@S5NC
Copy link

S5NC commented Feb 23, 2024

About this beta feature

New default: Your phone number will no longer be visible to everyone in Signal

If you use Signal, your phone number will no longer be visible to everyone you chat with by default. People who have your number saved in their phone’s contacts will still see your phone number since they already know it.

Does this means that even if the user A is added using via their username by user B, if user B had user A's phone number in their contacts previously, that it would be revealed in the app that user A's phone number corresponds to a contact on user B's phone?

If so this could be used to reveal the phone numbers of Signal users. An attacker could store all possible phone numbers as contacts on their phone, then add users. If phone numbers are revealed if a phone number is added to a contact after the username is added, it would still reveal phone numbers corresponding to users.

Perhaps this is just vague wording in the article, and doesn't specify that this is only the case for contacts that you add via phone number? Of course, this is only an issue if "Who can find me by my phone number" is set to "Nobody".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant