• Natanael@slrpnk.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    7 months ago

    FYI, SNI is a thing (included encrypted SNI these days) and you absolutely can share an IP among many many unrelated domains.

    Domain lookups have a TTL (time to live) and they stop advertising IPs which they’ll stop using a little bit before those IP addresses are taken out of rotation. That’s why it doesn’t break even when addresses keep changing.

    Signal have an active incentive NOT to use static IP addresses!

    https://support.signal.org/hc/en-us/articles/360007320291-Firewall-and-Internet-settings

    The underlying IPs are constantly changing, so it’d be hard to define accurate firewall rules.

    Realistically if you don’t want the government to know you’re using Signal… Do you want them to know you use Tor?

    Probably not, but you don’t need to run the Tor client on the phone, you can run an anonymous proxy and point your phone at it.