• mox@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    8
    ·
    1 day ago

    Just keep in mind that any service that asks for a phone number can also disclose it.

    I hope what leaves the Signal client is a hash of your phone number, rather than the number itself. They might even be using salts and expensive-to-execute key derivation functions, to mitigate brute force searches (which are otherwise easy given the relatively small search space of phone numbers). But if compelled, it would be trivial for Signal to change that behavior.