BBM back in the day worked great with their unique "PINs", that could be shared by QR code, and I could reject an "add" request.
BBM back in the day worked great with their unique "PINs", that could be shared by QR code, and I could reject an "add" request.
The answer is always the same:
Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging. The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for themselves.
The simple answer for a lot of questions about Signal is that they aren't trying to solve every problem, or even many of HN's problems.
If phone numbers are super-problematic for you, use Wire. Consider carefully the privacy tradeoff you'll be making, though.
Signal's goal is to make all the messaging in the world that currently uses phone numbers as identifiers --- which, by a long ways, is most messaging in the world --- cryptographically secure.
Hope that helps. You are welcome to have and to advocate for different goals. Please don't pretend your goals are Signal's, though.
This is a better explanation. However, these goals do not protect privacy. If Signal's main goal is to protect privacy, then they need to change their secondary goals to accomodate it.
Claiming Signal doesn't protect privacy because: phone numbers is an opinion given you haven't qualified your argument.
Finally their goal is not predicated on what you claim just because you claim it. You're effectively creating a false argument so you can justify your position.
Secure systems are not built on trust. They're built with math and with facts.
Their goal isn't based on what tptacek said just because tptacek said it, either. If I'm wrong and privacy isn't their goal, well that speaks volumes on its own.
There are two groups of people (among others) Signal clearly doesn't aim to serve:
1. People that are very sensitive about, and only have access to, their one phone number.
2. People who want to sysadmin their phones.
I have perhaps more sympathy for people in group (1), but, unlike you, in neither case do I think the mismatch is a great moral dilemma. I do, however, believe that promoting inferior and untested cryptography is immoral.
https://news.ycombinator.com/item?id=17723973
The two of us are far apart on these issues and perhaps we should just agree not to engage on them.
So you're doubling down on the lie I called you out on the first time around, then?
I have F-droid installed as a system app and the only method for installing apps on my device. It is an AOSP device without Google play services or anything proprietary save for the minimum blobs required to allow the device to boot and communicate with the cell networks.
I don't enable root, as normally assumed of users that don't run stock. Doing so on Android is a well known terrible security idea. This is a hardened personal device where I choose to opt out of Google tracking, and backdoors like SprintDM.apk that Google bundles with their stock OS.
In order to install signal without Google Play I would need to turn on unverified sources on my phone and open myself up to Man In The Disk style attacks, and other security issues.
This is ridiculuous that a company that champions itself an advocate for security and privacy refuses to support users like me that opt out of proprietary software and the tracking systems that come with them.
Moxie not only said he will never support third party signed installation methods like F-Droid but has been actively hostile to those trying to do this for him.
Example: https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
Moxie suggesting people fork and make their own private network that simply want a secure installation method of third party signed/verified binaries on security optimized Android devices is irresponsible and does not inspire trust.
What you achieve with custom ROMs and custom app stores is customization capabilities and nothing more. If you believe you're achieving next-level security or privacy because you don't have Google installed; you're kidding yourself. Yes, you may be leaking (at first glance) less data to advertisers; but you've opened a whole different kind of attacks that could compromise all your data on your phone, not just what Google and the Android platform allow to share.
A perfect example is the "LibreSignal" project you mentioned, what kind of joke was that? The project was abandoned because it didn't get Moxie's blessing? That's a really strong sign of commitment with the cause. I'm sure that LibreSignal has more than zero active users, what do you think about their security/privacy level currently?
That goal is fundamentally broken, though, because phone numbers aren’t cryptographically secure. One can use any exploit which allows one to take over a phone number to take over someone’s Signal identity. Yes, all of the target's Signal contacts will receive a message stating they his keys have changed — but they are used to that.
Signal's got some awesome crypto, but it also has some intriguing holes.
https://support.signal.org/hc/en-us/articles/360007059792-Re...
I'm not so sure. A lot of the objections to Signal using phone numbers seem similar to objecting to SSL/TLS because it's not Tor.
The type and amount of privacy a user wants and what you can realistically achieve beyond that depend on your market and threat model.
Thinking Privacy is binary is like thinking IT Security is binary; until it's 100% it doesn't exist. That kind of thinking doesn't allow thinking in incremental improvements.
If they catered to what some people want (no phone numbers and federated network) then the regular user would have different options to use Signal. Which one is the correct one? Are they all the same? No. if you decide to develop your own client (like the LibreSignal example), do you trust that the client is secure? If the end application has vulnerabilities, then the communication privacy is compromised. That's why I say they're intertwined. Even Signal suffered from this same thing with the Desktop client. It is not an easy problem to solve, and that's why Signal does not want to have random people creating custom client apps and having them associated with the project, as it could confuse non-technical users.
Then go see what other messengers do to provide the same UX.
Depending on the messenger you pick, you will likely not have to give up your phone number, but you will leave the messenger operator with a log of everyone you've communicated with.
The nice thing about phone numbers is you put them into a non app specific address book, so your friends list is portable.
I personally know at least one person who can't use Signal because they don't have a smartphone to install it on (but could install it on the desktop, if the desktop app didn't require the phone app to be configured first). I know two more people who can't use it because they use tablets, and Signal still hasn't released a table version, even one that works the same as the desktop one.
It's weird to me to see people downplaying this; if they succeed, it will be a monumental achievement, surpassing SSL/TLS in impact to communications.
If you don't have a smartphone you can install apps on - perhaps the company making a smartphone app which happens to integrate with a desktop app as well) isn't for you. Same for "tablet users".
FWIW, you don't need to do _too_ much hoop jumping to get a non-phone device running Signal - I mainly use it on a dedicated iPod Touch, and I've got the iPhone app running on an iPad as well - in old-school 2x ugly-mode, but it works. (You do need to be aware of the risks around whatever phone number you use to bootstrap your way in possibly being reallocated. You might not want to use a 30 day burner SIM or a temporary Twilio number if you might have a targeted enough attack to impersonate you by hoovering up temporary mobile numbers...)
They recently added an optional "Registration Lock" feature to address this: https://support.signal.org/hc/en-us/articles/360007059792-Re...
And I don't think that tablets are an "edge case". I mean, seriously? We're talking about millions of devices on the market. They may not be as popular as phones, but they are popular, and people use them. So when a guy uses, say, iMessage today, because it works across his iPhone and his iPad, I can't really pitch Signal to him. And that, again, has network effects.
Sounds like a broken smartphone platform to me.
I'm not being glib: I really do believe that I should be easily able to replace any app on my phone. Android, while imperfect, is closer to that goal than is iOS, and so I use it, and recommend it to others.
Skype almost managed to replace the legacy phone network, but fell out of favor. If there was interoperability between clients like Signal, Whatsapp, Line, Wechat, it would take over a multi-billion dollar industry. Instead, my bank is trying to use some proprietary video conference system to schedule meetings with me.
What it doesn't answer is: why can't Signal also provide an option to add a contact using something other than a phone number? Bold, italics, and double-underline on the also. Is it simply a question of finite developer time?
I have multiple specific segments of the population in mind who would benefit greatly from the secure private messaging Signal provides but for whom exchanging phone numbers is a total non-starter. "Ordinary", non-technical, non-"elite secure" people. I hate the framing of this problem as some sort of niche techie elitism. That's a dodge that reflects a social blind spot of its own.
(1) allocating developer time and organizational priorities; or,
(2) a technical incompatibility with Signal's existing, phone number-based model?
Based on your response I'm inferring (1), but I'm frustrated that this is never directly answered when the topic comes up.
I seriously don't understand what people expect in these discussions, though. The situation is straightforward. A small but vocal minority of Signal's user base wants non-phone-number identification. Signal hasn't prioritized that feature. Put up, or use a different messenger. How is this complicated?
Don't pick horrible messengers, like ones where encryption isn't enabled by default, or doesn't even exist for group messages, or isn't built on a protocol anyone understands or has reviewed. But even with that constraint, you have options.
Have you done a survey before arriving to this conclusion. If so, I'd love to take a look at it, if possible. Otherwise, I can't see how you can make this assertion; everything can be dismissed as a "small but vocal minority".
As a previous signal user, I stopped using signal because I discovered this issue.
(Also, it's kinda funny that Signal has reimplemented the iMessage problem -- you have to unregister your phone number on your website so people can SMS you again rather than continuously sending you Signal messages unintentionally.)
(There are also other problems that have bubbled up in Signal in the past year since I stopped using it -- I've heard there's an auto-backup process that takes more than an hour and makes your phone unusable and you cannot change when it happens.)
More importantly, I'm still very interested in seeing the data behind your vocal-minority assertion.
Comparing those two userbases doesn't make much sense to me.
I think it's really you who is making the extraordinary claim here and you should be providing the evidence. Signal's goal, as has been repeated many times in these threads is to replace SMS and other less-secure forms of messaging for as many users as possible, not to cater to somewhat off-the-beaten-path concerns over phone numbers. They are aiming for users of messaging. And they are making the very reasonable inference that most of those users are not hung up on identifying themselves with a phone number.
Additionally, if Signal's current users cared about the phone number thing that much, they wouldn't be using Signal to begin with. Where's your survey data that says Signal users just can't stand the phone-number-as-id thing?
What I was trying to convey is that I would expect people who don't understand or care enough about their personal privacy would use more popular and mainstream messengers. Whether people who care about privacy consider phone numbers private or not is something we need data to determine.
> Where's your survey data that says Signal users just can't stand the phone-number-as-id thing?
That's exactly what I'm asking for. At this point, we're both speculating. None of us can make solid claims about either userbase without providing evidence. tptacek most certainly can't claim " a small but vocal minority of Signal's user base wants non-phone-number identification" without providing evidence either, which is the original objection that started this thread.
Don't expect people to take your reason for dismissing their concerns seriously when you base it on your personal perception or beliefs in stead of facts, and don't make unsubstantiated claims to discredit their concerns.
Yes, it is some, but it's not a ton.
But they ‘know’ the phone number is a non starter because that’s how other social networks outed them. So they will also often end up using a string of bad tools as an awkward way to keep several worlds separate.
Most won’t admit it, but this second reason is why they, as iPhone users, aren’t in encrypted Messages for those chats. Neither end wants the chats in their phone number world.
While you can argue this use case is for hiding that one even participates in chats others might frown on, that to me sounds like a use case that matters, since today, most of the world doesn’t agree what should be frowned upon.
// This is not a technical assessment, it’s from the non-technical users’ point of view, how they think it’s working or not working. Same folks assume phone number is more identifying than finding an app that doesn’t need phone number because it can accept their FB log in. It’s a pretty rough world for non-techies.
Use the phone number just to prevent spam (though it can't prevent one user having multiple accounts using the same phone number).
This will serve two use cases:
1. People who need simple private IM like WhatsApp can continue using it without asking for A or without giving it any heed.
2. Or you go for A and you are communicating w/o any real world identity attached to your messages.
1. Use the device's address book (phone numbers).
2. Use Facebook Connect (FB id).
3. Store the entire social graph on the server (custom identifiers).
I think #3 is what every messenger that offers non-phone identifiers does (Snapchat, Twitter, Telegram, Wire, Viber, etc).
The reason is simple: if someone does manage to create a social network by slowly discovering a bunch of usernames from their friends, but then they reinstall the app or get a new phone, it would be pretty unusable if that entire social graph was just... gone. It's bad enough to have to create this social graph from scratch, but to do it every time you reinstall, lose your phone, or get a new device?
The consequence is that many people advocating for this feature (or using other messengers because of it) probably don't understand what it is that they're really advocating for or getting themselves into.
Right now Signal is much more "private" than any other messenger, if you measure that by how much Signal knows about you (timestamp of account creation is the only thing iirc). By supporting a custom identifier, they would have to store your entire social graph, like other less private messengers.
On iPhone, after a hardware upgrade w/ restore, Threema offers to restore your client side graph from a client side backup.
By way of analogy: In every HN thread about Firefox there are dozens of comments by people who say that they just couldn't use Firefox because page loads are so awfully slow.
Consider that for a second: HN readers are willing to give their entire browsing history to Google in return for at the very worst a few dozen microseconds of load time saved.
The equivalent here is, that for non telephone number identifiers you have to create a whole UI for actually adding/discovering people. That's the equivalent of the few microseconds. You can argue that it's not a big deal, but it's exactly the type of friction in the ecosystem that hinders adoption ("I already have your phone number, why do I need another number to contact you? Know what, I'll just send you an SMS.").
And it's exactly the type of UI/UX problem that prevented encrypted email adoption ("Download a new program and some sort of key for you? I'll just send you an email directly, I'll figure this out later...").
I don’t want to be discovered. I want to give you my pseudonymous pointer and you can ping me to connect.
Using phone numbers to ‘discover’ doesn’t solve the problem you say prevented encrypted email adoption, that’s a next step in the dance.
There are exactly two pseudonymous identifiers that have "made it". Both associated to technological revolutions. One is phone numbers, the other is email. You put them on business cards and save them in your contacts.
This is strong evidence that this is a hard problem. No other identifiers have been successful long term.
And yes, this absolutely prevents encrypted email adoption. Imagine if switching to encrypted was like installing signal (back in the SMS fall back days).
It's: "Hey use this email client, it automatically detects when the person you're mailing also has an encryption capable client and then all your communication with that person is encrypted."
vs.
"Hey use this EMail client, and if you find out that someone you know is also using it, you can go to this menu item here and search this database in order to find out how to email them securely, and if that doesn't work just email them normally to get a public key from them, before you send them the document you wanted to send."
No guarantee that the former would work, but it would have a fighting chance.
Of course such a solution isn't possible partly due to usage patterns that email has that would break. But that's why I'm relatively forgiving of Signals strict stance on shooting down these type of feature requests. Because they actually have massively improved secure communication for more than a billion people.
On the contrary, this is precisely the discovery many users do not want. 1. Someone you know can discover you’re using this channel. 2. You can’t use the same channel both overtly and with deniability. I should be able to have as many faces for speech as I choose.
If you need deniable encryption today use WhatsApp. Done.
Maybe. Or it could be because they don't want to. People equipped to solve one problem may not want to solve another, related problem. It might not be a priority, interest, or motivation for them. That's not apathy; that's decision-making.
Yes, it is – and it turns out that Go 2 will be adding generics.
Before that, you could have said "If generics are super-important to you, use Rust." But it turns out you can have both Go and generics, and (if you prefer Go over Rust for other reasons) that's even better than having to pick one or the other. The designers made a choice to omit generics in the initial version due to difficulties reconciling it with their goals of simplicity and ease of use, but (unlike some posters on forums like this) they never claimed that generics were fundamentally bad or that Go would never add them. Now that they have had time to think about how to work generics into the design without compromising their other goals, they are planning to do so.
I hope Signal does something similar.
Its easy to imagine that adding an alternative UX in Signal for non-phone based contacts might complicate user flows. Creating a user-flow for alternative contact discovery without hurting the user experience for existing users I think is not simple and easy to underestimate.
Go and Signal both choose a set of trade-offs that consider both technical and human elements. I think this irks people that don't understand these trade-offs since the human side of trade-offs is harder to define or evaluate the importance of. Ergonomics plays a huge role in the ultimate value of Go and Signal to society.
Let'a say a journalist is targeted by a sophisticated attacker. The attackers want everything on the phone,why just calls and messaging? They won't even attack the protocol,they'll first try putting a RAT in place which will have access to everything. Signal does not promise to protect your communication after your phone is compromised(which only makes sense) but now the attackers don't just have access to your messages but also to your contacts. They now know the journalists sources and contacts by the phone number they used.
This approach enables "easy" mode for casual users who prefer phone number registration, while supporting additional privacy for others.
If IETF efforts to standardize E2E messaging protocols can lead to interoperability between clients, we can reduce the influence of social network inertia on messenger client selection.
But I want to use signal forfor cross platform messaging. Can't use Facebook without a testable phone number either now.
Phone authentication is better than nothing and lowers barriers to adoption.
Perhaps when manually verifying an identity via the QR code add an option to generate a new id not tied to the phone number.