Signal Desktop beta now publicly available
whispersystems.org
whispersystems.org
Here is a convoluted process that will allow you to register with any SMS-capable phone number, no Android app required:
First, install the Signal GitHub repo (unzip https://github.com/WhisperSystems/Signal-Desktop/archive/mas...) unpacked in Chrome, inspect the background page and enter `extension.install("standalone")` in your console. Enter a phone number to get your verification code. Do not submit your registration using the standalone UI! Keep your verification code for use with the official app.
Next, uninstall the source app and install the official app. Inspect the background page and type this in your console: `getAccountManager().registerSingleDevice("your phone number", "verification code")`. Don't forget to include your country code in your phone number (+...) and remove the dashes from your verification code, or you will probably get an error.
No idea why Open Whisper Systems felt that it was necessary to entirely remove this hidden UI, when it wasn't accessible through any of the standard UI anyways. The feature works completely fine (and has for months). The only purpose this removal seems to serve is to force users to install their mobile app.
Edit: Ah, it's using a broken SSL cert (chain is broken). Going to the URL manually and accepting the break works.
Edit 2: The verification code doesn't work.
"You need to open TCP 31337 and all UDP ports in order for Signal to work." Emphasis mine.
http://support.whispersystems.org/hc/en-us/articles/21369721...
When I first read that I was sure that must largely apply to the calling (voip) features, but testing showed me I was wrong. I couldn't even make messaging work through a firewall so now I sourly use Telegram instead (no private chats by default in telegram??).
Note: Telegram desktop alternative apps have major usability issues at least on Linux.
Edit: Also, many people refuse to install/use Chrome for various reasons, so even if you don't have to open ports, this still won't be a solution.
Let's be honest, there aren't many. Chromium is enough to please the majority of OSS people. And if they are not using Chrome for 'security' reasons they are very misinformed.
Chromium is the best product on the market. I honestly don't see what negative influence Google's business model has on it. I use Duckduckgo as my default search engine and Google doesn't do any monitoring/tracking in Chrome, despite what most people think.
Firefox is the best product on the market.
Google makes money from tracking people on the web. They will not introduce or develop new technology to their web browser which hits that revenue stream hard.
By using Chrome or Chromium you are giving them market share and therefore power to shape the future of the web. The future of the web under Googles custodian is more advertising, more tracking and less privacy.
It's pretty obvious.
Currently am using Firefox. Recently gave Chromium a good try for a month or so, for my personal experiences, right now best product on the market is Firefox. The address bar / search bar in Chromium is just inferior--you only get ~five autocompletes from your history and bookmarks, total. That basically means there's a reasonable chance the thing you're looking for will appear, but it's not really something you can rely on to navigate the personal knowledge base of bookmarks and history. Not talking about search suggestions btw. The other thing is Firefox Android supports Add-ons, so you can have uBlock and Ghostery on your phone (not even sure why anyone would even begin to consider a browser that doesn't support adblocking?) and Firefox Sync works well, to connect to the desktop and back (gave Pocket a try, didn't like it).
I also use DDG as default search in Firefox, very useful with the bang syntaxes, more powerful than Google (which is just a !g away anyhow). Also in Chromium, so the address bar feels more familiar and somewhat makes up for its lack of power :)
https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-qu...
This would require some kind of key exchange i.e. scanning bar codes.
I haven't looked into it at all, but one way I just thought of right now is to have your own devices p2p the message among themselves with original sender's information after the one used most recently receives it.
Do you know if it's open source or at least gone through an audit?
I don't know whether they have been formally audited.
Also have a look at https://wire.com/legal/#privacy
https://app.wire.com offers full functionality on Linux.
That tweet you link to is over a year old. Wire is E2EE since March 2016. https://wire.com/privacy has security and privacy whitepapers.
PS. I work at Wire.
But yeah, no encryption to speak of. So I'm no longer going to recommend Telegram over Whatsapp :) Just pointing out how much I like the UX of the Telegram client, no reason why you couldn't have that on a properly encrypted platform, after all :)
That last comment makes me wonder if they understand the objections being raised in that ticket though.
8443 != 443
That's really, really strange. I sit behind an IPv4 NATting router whose policy is "default REJECT unless the packet is related to a connection that conntrack knows about". [0] The device also runs UPnP, but Signal never attempts to forward any ports. Full disclosure: I have good IPv6 service, but textsecure-service-ca.whispersystems.org doesn't have any AAAA records, so I don't see what that would have to do with anything.
My friends and I can use both Signal text and voice messaging without issue.
Just what sort of obscenely restrictive firewall are you behind?
[0] You know, a typical NAT firewall configuration.
Many companies block outbound on non-well known ports, for various reasons. tcp/443 is almost always available though.
Mmmhmm. Yeah, I'm aware of that. :) However, click170 made no mention of a corporate firewall. He said:
> I just wish Signal was easier to get through a firewall.
Which is dramatically at odds with my and my friends experience with Signal; namely that it passes through firewalls with no configuration required.
If he would have mentioned that it was a corporate firewall that he was trying to get through, I expect his comment would have been much less popular, and much less confusing. :)
Signal has done an excellent job of branding itself as the one true E2E encrypted messaging app made by real experts, as against e.g. Telegram. But the actual product is hugely disappointing because of these apparently arbitrary and, in the case of requiring a phone number, privacy-damaging restrictions.
I'm ready to look for something else.
Gave up. =(
Have you had any experience with twilio? Any problem receiving calls?
I've not looked at the internals — it's possible of course that it already does exactly this.
Check the second result of [0] (entitled "What is Signal Desktop? How can I sign up?").
[0] https://encrypted.google.com/#q=%22signal+desktop+ios%22