Getting Started with Signal
justingarrison.com
justingarrison.com
1. Worst Offender : Facebook Messenger --> spyware for tracking all your activities even in background
2. WhatsApp : Lost trust in it since Facebook bought it, more so with the new terms and conditions. Data is not safe anymore.
3. Telegram : Trust it's privacy but it's proposed business model is also advertisement based so avoiding it.
4. Signal : Best option, there are some sacrifices to be made with lack of contacts and some features but slowly and surely we can turn the tide. Also it's open source funded by a Non-Profit so that gets it bonus points.
Reference: https://9to5mac.com/2021/01/04/app-privacy-labels-messaging-...
It is possible to reply to numbers bot listed in your contacts; and apparently it is possible to initiate chats with numbers by using a web api which triggers a platform specific app action.
But you’d be left with phone numbers as identifiers, and at most the user’s self description which is sometimes they name and sometimes just something like “xxx”
If only it could be present-ready.
No, I am kidding :).
The way I see it Matrix and Signal have different short term and long term goals, some overlapping. And both could do way better in term of usability.
I like and use Element but it definitely isn't ahead in usability. Getting e2e set up for "average" people isn't trivial. Especially if they have multiple devices.
That being said it is the the best long term option in my opinion and I am donating to the organization. Hopefully they can work on polishing the e2e UX.
Do you mean about accessing an encrypted chat from multiple devices?
If yes, I was playing with that just this weekend and I did not understand at all how to trust the other devices by using "text" (which "text"? I didn't get anything to type/check/approve anywhere); on the other hand by using the option to use emoji (compare a series of emoji between devices and then confirm) was very simple.
As well finding the link to a group-chat that I just created was not simple (or at least the place where to find it was not obvious).
> That being said it is the the best long term option in my opinion and I am donating to the organization. Hopefully they can work on polishing the e2e UX.
Same here & I agree.
I'm also confused why each device is handled separately. I would rather I just share a key around (and ideally it rotates occasionally) and not share what and how many devices I have and what one I am using at the moment.
Aha, didn't notice that, thx!
> I'm also confused why each device is handled separately.
Well, I can understand it more or less (I guess kind of similar to confirming in Whatsapp your multiple open sessions on different devices, to ensure that nobody is using something that you forgot/left behind?), but doing it this way is quite hardcore - on the other hand it could be that the whole thing is deeply embedded in the software's encryption principles/guidelines => it would probably still be ok, but it needs to be explained better, be more clearly accessible.
I guess that having a rotating key (with the software asking from time to time "do you want to accept key jf8k4d9k?") would probably be confusing for non-technical users and would probably generate uncertainty/anxiety/etc... ?
For the rotating key it would be automatically signed by the previous key or master key so no user-visible change would be shown.
So you don't think that if I cross-sign devices A and B, and then I would cross-sign devices B and C, if I would revoke B then C would automatically become invalid as well?
Kind of similar question about "key backups" (to which keys would device C have access to?).
(I honestly did not ever look into all these details - I was hoping that this would be covered by more clever people)
Maybe the best solution would be revocation after a date. So you can say "don't trust anything after {time-i-lost-the-device}" or "don't trust anything after {now}" and it does the right thing. However that could be complex to implement correctly in software. Lots of bookkeeping.
I set up my own server using Synapse, and invited about half a dozen other IRL techie friends to join me in there to continue chatting during Covid times.
Considering we've all worked in tech for decades and run our own servers/services, none of us can really work out how the hell it's supposed to work. I mean, after lots of time consuming verifying of devices it kind of works. Except recently, all of a sudden, one of the people in our main chat room can not see the messages I sent from one of my devices. It tells him to get my keys from another session, he has only every used a single device/session. There is no UI that either of us can find to help fix it. We can chat fine in a different encrypted room, or if I use a different device.
I'm not pulling anyone else into the Matrix ecosystem until encryption stops being just so god damn awful.
Verify this, is this you that.
I think partly its because i am not always on latest version of Synapse so the self-updating clients expect slightly different backends but uff.
It feels like Moxie is right with his anti federation argument. Call me stupid but i am really trying to keep it together but i still cant tell why some of the popups show up or why some sessions of my friends wont decrypt and they show gibberish.
This is the problem with matrix et al. They have to offer something that is leagues ahead of the current baseline, which I'm not convinced they are.
I've been running my own email server for going on 20 years now.
[edit] To add to the above, I use the same Matrix server to chat in various Matrix, IRC and Gitter rooms, and also to host a couple of self-written bots which I use to control a few aspects of my life. Email isn't really a replacement for the things I use Matrix for.
Also you can use alternative clients, which (I think) is against Signal's TOS, and is at least discouraged.
Although I do praise it for not requiring and collecting my phone number and being a bit more future-proof and decentralised, unlike Signal and Telegram.
But in terms of getting my friends grandmother over it, it completely loses on usability and its name is so confusing to them you just had to also mention the Matrix protocol, when it is just Element. which even that by itself is very ambiguous.
If anything, Signal should adopt some of the crypto identity primitives Keybase was known for [1] for persona management that builds on (but still supports) phone DID identifiers. Would Zoom sell or donate Keybase infra to Signal Foundation? That'd be swank.
It is in an uncertain place though since Zoom bought them and moved its developers to work on Zoom. There has only been one small update to Keybase since zoom purchased them.
Asking repeatedly for information that is not necessary is a red flag. It is suspicious, to say the least, that Signal is not censored from Apple’s Appstore.
Signal (the foundation) does not get to use my phonebook even if Signal (the app) does.
Made the switch yesterday. Hope this will be a turning point for Facebook
And it has support for nearly all desktop and mobile platforms (with all the features we expect from a messaging client, and more - it is also a SIP client). It is fully open source, and all data is stored on your device.
Signal may be run by a non-profit, but it a non-profit based in the United States. In the US, a non-profit can also be converted into a for-profit business.
People use Telegram, because it has a fantastic UX and UI.
If you want people to even considering switching from WhatsApp, then the alternative must be 120% polished.
Most of my network is on Telegram at my urging because it was the best option at the time, but I'm constantly looking for something better to replace it (as I'm aware of the downsides to Telegram). Currently I'm trialing Element with one of my contacts and I'd say it might be ready if I can get past the initial setup headaches, but Telegram just works so darn well and is so amazingly fast that it will be very hard to get buy-in for people to switch. Most people are overloaded with IM apps already, adding another one is tough unless it can completely replace and deprecate one they're already using. Jami definitely is not that IMO.
Otherwise it's totally open source: https://github.com/wireapp/wire-server
Also, no mention of free personal accounts here: https://wire.com/en/pricing/
And phone ID required is a plus. I don't need people to log in or search for contacts. Just install and boom, we're connected.
> Even better is Wire: no phone number required, doesn't access your contacts, free personal accounts available, you can use it on a desktop machine with nothing more than a web browser
Same
> when using an installed app you can be logged into three Wire accounts at the same time
Don't know if that's possible with one of the currently existing Matrix-clients. I guess that maybe in the future that would be possible, respectively, doesn't sound too difficult to implement.
> is open source and has been audited for security, you can set up your own locally hosted (or in your own cloud)
Same for Matrix. Not sure about the official audit, but at least France decided to use it as a base for its own governmental chat ( https://matrix.org/blog/2018/04/26/matrix-and-riot-confirmed... ) so I guess/hope that they audited the original software.
I mean it seriously. Replicating different social graph that automatically includes your closest people is superpower.
I had a contact show up with a super old name that I wanted to update but it was right in all my other apps. Turns out I still had the old name in one of the read only merged contacts from WhatsApp (contact showed up fine in WhatsApp). I had to remove my WhatsApp account clear the app data for signal and resync everything.
Exhibit A: The Signal Foundation's tax reports[0]
Exhibit B: The fact that WhatsApp had a very small team and rather low costs, at least prior to its acquisition by Facebook. (I can't find any numbers right now.)
[0]: https://projects.propublica.org/nonprofits/organizations/816...
Telegram has close to 500 million active users each month. So of course Signal is not using as much money. The same Wired article mentions that Signal recently had gone from 3 to 20 full time employees, that adds a lot of cost as well.
My point is that I don't think Telegram have spent lavishly or focused on big profits, so it's unreasonable to assume that Signal will be able to do what Telegram does for much less money, so they will also need a new monetization eventually.
https://www.wired.com/story/signal-encrypted-messaging-featu...
https://9to5mac.com/2021/01/04/app-privacy-labels-messaging-...
How come you trust its privacy? Its privacy guarantees are by far worse than those of WhatsApp as Telegram messages aren't even end-to-end encrypted by default.
Social media and their users are struggling because their (our) interests have not been aligned all along. Initially, the services grew by providing great value. They developed equity through size and usage. Interests were not aligned for the long term because they lost money quarter after quarter. Then came the day they needed to convert the equity into revenue.
At that point, the pendulum swung back the other way. The users had given up privacy and publicized their lives to the world and developed habitual (addictive?) use. The user experience deteriorated, '3rd parties' paid for access and insinuated their banners into our feeds. We've become invested in these platforms, in some cases literally by developing primary income from YouTube, Locals, OnlyFans, ...
Clearly, we still don't have aligned business interests.
How can 'Big Tech' and 5 billion Internet users align our interests for the long term?
Signal is approaching similar metrics (except it’s supported by a $50m endowment from Brian Acton instead of donations).
It’s easy to say that the mechanics of chat are pretty simple and a global chat service can be maintained by a roomful of engineers, but is the original algorithm-free, chronological Twitter that much more complex? It’s hard to believe there aren’t any other billionaires out there who would be willing to create an endowment securing the perpetual existence of a free social network.
Charging $1 a year like WhatsApp used to wouldn’t be such a bad idea once it got bootstrapped either, since it would make it much harder to run bot armies.
1. As another commenter replied, Big Tech will have to start charging market prices for their services.
2. Big Tech will be unable to charge for their services, and the business relationship between them and their users will collapse, taking Big Tech with it.
3. The relationship between Big Tech and its customers will change from a business relationship to something else, where the truism you stated will no longer applies.
One might argue that (3) has already happened, and the "something else" is more like a manorial or totalitarian relationship, in which the interests of the users are irrelevant.
This is a fascinating question, I want to see this discussed more. I'll throw some thoughts to get a conversation started:
I would happily pay for big tech company services - if I'm worth $30 a month in advertising revenues, I'm willing to pay $30 to subscribe to the same services in exchange for privacy. I'm convinced that I'm not the only person who thinks like this. I am waiting for a product to come around and service this market.
<Shut_up_and_take_my_money.jpeg>
So it ultimately comes down to "do we create an alternative funding model for that 1 percent of user space" which doesn't seem like much incentive vs trying to find ways to get more more out of the 99% of users.
I think the only way this changes is if that userbase grows significantly, I don't think it's simply been an overlooked/forgotten internet business model.
You get the idea- in the end you're paying incredible sums of money for a collection of services that just aren't worth all that much. A conclusion supported by the fact that your use of these services currently generates pennies a day in ad revenue.
We can see this game at play today in news, where you could easily blow $50/mo subscribing to a small selection of decent papers. It's not a big deal if you only had one subscription, but few people read only one paper- or participate in only one social network.
To make matters worse, as seen in the cable industry, paying subscribers by definition have money to spend. This means they are by definition the most valuable advertising targets, which makes the lure of advertising to your subscribers eventually impossible to resist...
Per service though, are you willing to spend $30/m each for what facebook was, for what twitter was, for what youtube was, for what reddit was, before ads took over? (that's over $100/m on 4 sm sites... now we're getting into medium, tech news sites, gmail, google search, maps, etc. And what about the people who can't afford a $300/m "internet" bill are they just cut out of this brave new world?
Facebook messenger history is online and doesn't need to be thought about. I'm fearing there will be a fair bit of resentment once the non-technical Signal users change devices and realise that all their messaging history got lost in the process.
Makes me wonder if with data, math and statistics 'right' or 'left' can be distinguished at all: since they are so ambiguous and fluid concepts.
shireboy's point seems to be that it seems inconsistent to want moderation in one type of network and not mind not having it in the other. Though, it's possible that the users supporting the moderation are different than those supporting e2e networks.
That begs the question which platforms were used for organizing BLM riots for months and why there aren't any consequences?
Companies claiming to uphold democracy are the worst offenders if it makes business or idealogical sense yet HN crowd is cheering. Look at how they are willing to suck upto China, Iran, and even Taliban.
Disclaimer: Trump is a unreliable character so I don't like him personally a lot. But cheering up one-sided suppression without looking at the full picture is distasteful.
https://www.nbcnews.com/storyline/paris-terror-attacks/secre...
Engagement inside Signal is with your existing networks and groups, and can only grow iteratively—not virally/exponentially—it’s a chat app. WhatsApp and Telegram do support and encourage broadcast oriented communication, and personally I do associate WhatsApp with misinformation-fueled violence in countries where it’s the first exposure people have to internet-style mass direct communication.
Signal invented new cryptography to justify its existence. WhatsApp scaled chat, SMS-analogous to start, for the world to use. Telegram invented secret ways to MitM chat connections, and wasn’t under US influence. Parler exists to make a political statement in the current US political context.
I don't think there would be a significant proportion of people that would advocate for Signal to become centralized so it would allow moderation by a central authority.
Another perhaps more cynical take is that even if there is hate-speech and other undesirable communication in Signal, it's not seen so people aren't concerned about it. As they say, "out of sight, out of mind." That makes me wonder if expectations would change if people started publishing screenshots of Signal groups with hate-speech. I think they'd be pretty limited to small sizes, so perhaps they wouldn't be as concerning.
So to sum up. I highly value privacy and security (especially as we're adding more to the internet. The danger is increasing). But I'm against extremism. It is a numbers game that more public members will gain value from privacy than the dozens of terrorists who will. But it is a different situation if someone creates a space dedicated to extremism.
(I do think this is a very reasonable question to ask though)
Edit: I wouldn't say that Signal will be completely unmoderated. Groups still have admins. But you're right that Signal won't be able to moderate. But this isn't that different from any federated platform.
Two follow up questions: How do you objectively determine Parler is dedicated to extremism but Signal is not? I think Parler would argue (even if incorrect or insincerely) that they choose not to be the arbiter of right and wrong too, or at least to do so as minimally as possible. Since we can't see into Signal, we don't have any data on the % of messages dedicated to extremism.
"If a member of the public can get in then why can't someone from the CIA/NSA? It might as well be in clear text. If they can't infiltrate these groups then we have much bigger problems". Isn't that an argument for allowing Parler to stand? It actually _is_ (er, well, was) clear text, and I would be _shocked_ if CIA/NSA weren't monitoring it. Wouldn't we be safer with bad guys coordinating on Parler than on Signal.
The way I see it, Signal will not make it any easier for outsiders to get radicalized (there's no public forum aspect), but once people are already radicalized and connected, it can be used to great mischief. That said, I tend to be liberal on this topic, and I feel the benefits of across-the-board E2E encryption to society outweigh the risks. But it seems likely to me that that principle is about to be sorely tested.
I don't think I'll ever get to request it, because I'm pretty sure it's going to fail, especially with my parents and other from this age group - having them download another app, signup, etc. will be too complicated.
My family group is all iphone users, so I thought about moving this to iMessage, which feels more possible, but again, I'm not even sure my parents understand the difference between whatsapp and iMessage, as they send me messages on both platform without much logic.
Like everything else "bad" that happens to Facebook, this event won't change much and impact on whatsapp will, unfortunately, not change anything.
Remember when corporates stopped advertising on Facebook? They're all back.
I moved my whole family to Signal, and its surprisingly easy. It asks for their phone number, name (it's autocompleted) and a pin. You can create a link to your family's group chat so then can join without needing someone to invite them.
That's the key move, it takes guts
1. Install the app when you visit, go to the process together (difficult these days, I know...)
2. If you have many iPhone users in your family, answer on iMessage whenever they send you a WhatsApp. This way you can pull them over slowly
3. If Android users send you a WhatsApp, check if they have Signal installed and answer there instead.
It is "Salami tactics", but works for me.
1. I noticed that Whatsapp allows me to add someone to a call (sort of like upgrading a phone call to a group call). I couldn't find a way to do that with Signal - although Signal supports group calls (that is, calling an entire group at once).
It's a minor feature, but I discovered that I rely upon it quite often.
2. Last year, I attempted to switch from iOS to Android - and I discovered that there isn't a clean way to move my whatsapp messages over. On iOS, whatsapp creates a backup on iCloud, there isn't any way to recover that on Android.
I aborted the attempt to switch to Android only because losing my whatsapp chat history was unacceptable.
Signal currently seems to be just as bad. However, if signal can implement a reasonable way to create backups and recover them across devices and operating systems, it will seal the deal and convince me to permanently delete whatsapp from all my devices.
Being a house full of Pixel devices and sole IT person, I dont want to be responsible for lost messages when it comes time for a new phone.
Also if your phone is lost or bricked ( either platform ) say goodbye to messages
Moving from Android to iOS, bye messages.
I can move my savvier friends and family over, but the rest will remain on whatsapp where "its easier" compromise works.
It seems like it should be trivial to back up message history to the cloud.
How do you protect from various evil entities from stealing your cloud backups?
Nobody noticed, no warnings about encryption keys changing, no problems whatsoever. Took about 5 minutes each time (including googling of the directions).
Just make a backup (with an encryption key), then do a restore (and enter said key). Not as convenient as if it was automatic, but it does seem like a pretty secure approach.
My personal wishlist:
- Making the app available on F-Droid, either on the official repos or just hosting a third-party one
- Bringing the Android backup solution (encrypted blob) to iOS
- Bringing the iOS backup solution (direct device transfer over Wi-Fi) to Android
- Signup with usernames/emails as an option instead of only verified phone numbers
- A more reliable desktop client, because most of my contacts on Signal (myself included) have experienced syncing issues, message decryption issues, notification issues, etc. I do like that the desktop client is temporarily standalone in that the phone running the app does not need to be available, although I have had to re-connect the two every once in a while so I don't find it reassuring to depend on the desktop client alone.
Plus, some are predicting that forthcoming changes to Android – Google possibly mainstreaming its “advanced protection” model so that phone owners cannot install the F-Droid APK except through enabling ADB and pushing it to the phone from a computer over the command line – will further marginalize F-Droid.
From a security point of view it seems quite reasonable to object to f-droid handling all signatures.
The thing is, people using F-Droid are most likely already aware that they can install the .apk directly from https://signal.org/android/apk/ so there's not much to gain (the .apk prompts the user when an update is available too).
Also, if the gov tries to ban it, its just open-soirce software, right? Haven't courts (in the US at least) ruled that code is speech, and therefore protected from government restrictions by the 1st Amendment?
- stickers (big one!) - if it was possible to import whatsapp stickers library it would be a big win
- on whatsapp it's easier to share news and memes from other groups - network effect
- UX/UI - whatsapp seems to have a much tailored UI for beginners
How so? UX/UI for beginners is a big priority for Signal, your feedback could be helpful.
I might agree with you for Signal-Desktop: installing another application is always more friction, and it will get out of sync if you don't open it regularly, which doesn't happen with WA since the messages are retrieved from the phone.
Note that the safety number is basically a combination of your and your contact's (DHKE-negotiated) keys and is thus going to be different for every conversation. The reason both keys are not shown separately is that it apparently confused users.
In fact, the cryptography is even more complicated: The Signal protocol uses a so-called double ratchet algorithm[0] which derives from the session/conversation keys a new ephemeral message key whenever possible (again using a DHKE). This has the added advantage of providing forward secrecy.
Imagine if e-mail had been like this. You can't talk to your friends if they have a different provider, and you're not allowed to use your own client anymore.
Burner SIM? Google Voice number? Landline service? Go find a payphone?
If you want to change your phone number, how do these platforms handle it? Do your contacts get updated or what? What happens to people with your old number?
If your phone breaks, and you get a new one, how do they handle backups? (My iPhone's WhatsApp backups somehow disappeared when I got a droid.)
These questions are particularly infuriating for digital nomads and people living abroad. I want an inexpensive cheap way to keep my US number I've had for 10 years. I've also heard horror stories that Google Voice (or Fi? Can't figure it out) will shut down your account if you live internationally.
https://support.signal.org/hc/en-us/articles/360007059792-Si...
> The "tied to your phone number" thing is weird for me, both Telegram and Signal.
Isn't this restriction also applicable to WhatsApp?
[0] https://support.signal.org/hc/en-us/articles/360007059752-Ba...
It rejects the correct SMS confirmation code it's sending/receiving itself :)
At any rate, I know a couple of people who have recently signed up so it's not affecting everybody.
Guessing that a lot of WhatsApp users like myself rely on the built in media backup to Google Drive. The automatically, well ordered media stored locally on the phone, with dates received in filenames, is great for people who like to have local media backups. WhatsApp image folder can also be added to services like the Google Pictures backup.
All those missing features are Signal deal breakers for some people
Unfortunately, my messages to the family group are stuck spinning (24 hours now) and I'm not seeing any new messages in the group (and should be). Nightmare.
If anyone knows a fix I'd love to hear it (have tried leaving the group and rejoining, restarting phone etc)
Does anyone have a moment to explain this one to me? Seems to me you'd of course have to store your own key on the device. And if Apple is storing it themselves... that's news to me and pretty concerning.
Page 99 here. https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app...
Which describes that the private keys are generated and held on device.
Now I think this model *may change when you enable icloud messaging, in which case an encrypted messaging key may be stored in your icloud account. So you may opt to have apple store it, but in an encrypted manner that they can't undo. This part is a bit speculative on my part though, so grain of salt.
In a no-trust model once you sign in on a new device you wouldn't see all of your old messages. Because all of your old messages are decrypted and sent to the new device this is evidence that a new signing key was added to the communication chain.
Apple could also do this to decrypt your messages to give to a government agency or for whatever purposes they want without notifying you.
https://techcrunch.com/2014/02/27/apple-explains-exactly-how...
And no web client means I am forced to type on my mobile (ugh), and I cannot mitigate the hurt with Franz.
I don't have a FB Profile hence don't have the FB App nor FB Messenger, but I do use whatsapp extensively. Do I need to be overly concerned with whatsapp's privacy changes?
Discord and Slack are great. Even Microsoft Teams.
Shitty things about Signal:
1) When you set "Disappearing Messages" it's for any messages that come in after that point. I think it should be for the whole thread. Even though the UX implies it's for the entire conversation, it's really just for messages sent after the setting was changed. Moreover... let's say you change the settings a few times... you have no idea if / when individual messages will disappear.
2) When you delete a message on your phone, it's still on your desktop -- and everyone else's devices. It's really frustrating that if I send a typo, I can't delete it or fix it. Worse, it appears to delete... and being native to Discord / Slack / Teams... I expect it to delete for everyone. They did change message text from "Delete" to "Delete message for me" but even that doesn't even delete across all my devices.
3) You can't edit messages after you send them.
4) Functionality is different on a phone vs a desktop. You can't do nearly as much on the desktop version.
5) It's funky when you change phones. You can't like sync all your old messages from one device to another. It'll pull them on to a Desktop client, but it won't pull them into a new Mobile phone client. Dunno, just bad UX.
6) Signal is still based on phone numbers... I don't trust phone number based 2FA, so I don't really trust Signal to be based on phone numbers either.
But it's not all bad! Some things they added which make it feel less horrible... they finally did add meta data previews for URLs. That was nice. They added ability to give tapbacks / emjoi responses, and "reply" to messages. I think all this in the last year or so. They're working on it... but like it still feels like they're aiming for shitty old cell phone text messages as what they are trying to replace... I wish they were aiming for Discord / Slack / Teams as those platforms have really done a great job with chat.
By far, the platform with the most improvement was Microsoft Teams. They had this wonky Skype For Business who knows hybrid approach. And they had a lot of the same issues around messages not being synced between devices. They fixed that in the last 18 months. I've been using Signal since Snowden, but in my opinion Signal still has a long way to go before it's something I would actually want to use to chat with friends.
There's a small clock between the sending date and the (double) tick which indicates just that.
Also, I think it's recent, but if you select a message then click the 'i' (information) at the top there's a countdown that says exactly in how much time it disappears.
> 4) Functionality is different on a phone vs a desktop. You can't do nearly as much on the desktop version.
Which features are you missing on the desktop version? They seem to have implemented calls recently, I'm not sure what's still missing. I mostly write text messages though, so I wouldn't know.
> 5) It's funky when you change phones. You can't like sync all your old messages from one device to another. It'll pull them on to a Desktop client, but it won't pull them into a new Mobile phone client. Dunno, just bad UX.
Is it better with e.g. WhatsApp? You have to transfer the backup files anyway, right? If you're on Android it should boil down to transferring the backup files, just like with WhatsApp. It does suck on iOS from what I've read.
> 6) Signal is still based on phone numbers... I don't trust phone number based 2FA, so I don't really trust Signal to be based on phone numbers either.
Phone numbers are a problem, but they're on a good track to get rid of them while still providing the same privacy. In the meantime, I don't think it's a security risk if you have a random pin.
If you compare Signal with Discord, Slack and Microsoft Teams, Signal will never win on features. AFAIK these are not E2EE and they don't really try to reduce the metadata or even data known by the servers. Basically a feature vs. security trade-off.
Thanks for the response!
> There's a small clock between the sending date and the (double) tick which indicates just that.
Cool, I see it now. But there's still no way to change it. In Snapchat, when I set the time it impacts all messages in the conversation. It'd be nice to have the timer impact all messages in the conversation, it's weird how it is set at the conversation level but doesn't apply to all messages in that conversation.
> Which features are you missing on the desktop version?
Create new group. Invite friends. Change your avatar. Change group avatar. Literally had to text myself a picture from my Macbook to my Phone so I could use it as my avatar. Oof. Windows Desktop version vs iOS app version. MacOS version I dont't think is any better.
Found another annoying thing... two actually. "Mark as unread" is device specific, not message specific. Also under the little info on each message there's a button "Delete Message" but again it's not a real delete, it just impacts the device -- all the other places they said, "Delete message for me" so they know it's confusing to just say "Delete" and not have it actually delete the message for everyone.
> It does suck on iOS from what I've read.
Good it works better on other platforms, but yeah it really sucks on iOS. Get a new phone, and you have to be re-added to groups.
> If you compare Signal with Discord, Slack and Microsoft Teams, Signal will never win on features.
Why? Doesn't seem like it'd be impossible to sync all messages across all devices. Doesn't seem like it'd be hard to allow for deletion of sent messages. It's not peer-to-peer, and they keep all the messages on the server... when you turn on Signal Desktop it goes and retrieves the messages for you going back quite a ways. They just need to sync between devices.
https://battlepenguin.com/tech/matrix-one-chat-protocol-to-r...
I currently have Hangouts/Messenger/Telegram and Signal all connected via bridges to Matrix. I pump all my Facebook/Messenger/Hangouts traffic in my browser through a VPN to the server where the bridges are hosted so Google/Messenger won't flag them for security.
This took a couple of tries of logging in outside of the proxy to FB, getting the security warning and then switching back to the proxy with the same cookies so FB/Google algos learn the IP is safe. Hopefully when I move, if I keep all those same rules in place (using FoxyProxy for Firefox or Chrome-based browsers) and turning off location on my Android device permanently (will also move to a PinePhone soon), I can make it difficult for Google/FB to know my location after I move from my current city.
Singal and Telegram are great because they have standard APIs that make it easy for a Matrix Bridge. For FB and Google I have to trick them, which makes them hostile to developers and tech people. We've had to do this for years with libpurple plugins as well:
https://battlepenguin.com/tech/there-is-an-ios-device-attach...