BLUE
TH
Tjaden Hess
@tjade273.bsky.social
19 followers44 following8 posts
THtjade273.bsky.social

I guess the question is: What kind of adversary knows H(username, discriminator) but not username and discriminator?

1

Sstr4d.xyz

It's possible that the hash is just inherently disclosed by the server. At a minimum I presume that Alice can distinguish between "this Signal recipient exists on the server" vs not, which in the nickname setting is hash existence oracle. Dunno how the nicknames are hooked to their rate limit HSMs.

1
TH
Tjaden Hess
@tjade273.bsky.social
19 followers44 following8 posts