• Vent@lemm.ee
      link
      fedilink
      English
      arrow-up
      8
      ·
      4 months ago

      From Signal’s blog footnotes:

      Usernames in Signal are protected using a custom Ristretto 25519 hashing algorithm and zero-knowledge proofs. Signal can’t easily see or produce the username if given the phone number of a Signal account. Note that if provided with the plaintext of a username known to be in use, Signal can connect that username to the Signal account that the username is currently associated with. However, once a username has been changed or deleted, it can no longer be associated with a Signal account.