> The design of signal’s protocol is such that messages are authenticated but deniable: it is possible for the recipient to determine that the message was genuine
Via the use of MACs, yes. I never said otherwise. What I said before still holds, as the recipient you can't prove to others that you indeed received a message by a certain someone rather than forged it yourself to incriminate them.
> See also, this article about doing the same for email: https://blog.cryptographyengineering.com/2020/11/16/ok-googl...
The "Marisa" person in the comments is a friend of mine from IRC and I agree 100% with what she said.