<oembed><type>rich</type><version>1.0</version><title>paulmillr wrote</title><author_name>paulmillr (npub10j…03kag)</author_name><author_url>https://yabu.me/npub10jcnehsxwrjepupvh602pl83up0dh3wv3fqfwv062smygqvpeuwsk03kag</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>It&#39;s possible to deduce who messages whom (timing / correlation attack). All user contacts are uploaded to Signal servers (they say it&#39;s stored in SGX - which may be broken). Groups also store some data on Signal servers. And - most important - Signal relies on phone numbers.</html></oembed>