At Signal, we’ve been thinking about the difficulty of private contact discovery for a long time. We’ve been working on strategies to improve our current design, and today we’ve published a new private contact discovery service. Using this service, Signal clients will be able to efficiently and scalably determine whether the contacts in their address book are Signal users without revealing the contacts in their address book to the Signal service.
h/t cryptographer Matthew Green
Private contact discovery for Signal. Make no mistake: what Moxie is doing here is going to revolutionize messaging. https://t.co/RjAMWIpXui
— Matthew Green (@matthew_d_green) September 26, 2017
In short: your contact list will no longer be available to Signal servers. If you trust Intel SGX this wipes out a load of info leakage.
— Matthew Green (@matthew_d_green) September 26, 2017