Signal Fork with WhatsApp Migration
github.com
github.com
This fork would end up being a significant maintenance overhead for something that could be done more simply.
I would guess it was easier (or even only possible) this way.
Doesn't sound like he really put much more thought into it than "make it work". Like most of these one-and-done things, as a developer, you take the easy path, then forget about it.
See: https://github.com/signalapp/Signal-Android/issues/1014
> Thanks, we know [backup] is a big deal and think about it a lot. We're working on ways to do it that would be privacy preserving, and in the mean time we've got the p2p device transfer you mention. We'll keep working to make it better!
[1] https://www.reddit.com/r/technology/comments/kt91qk/signal_p...
So, no, they're not interested in WhatsApp import (per the closed ticket liked by the parent).
Additionally, the statement from signal is just PR spew. It boils down to "Nah, we won't make a way to do that.". The "privacy preserving" bit is nonsense because they have an export/import to a file on android.
Wat?
In this day and age 99% (OK, this number is exaggerated, but you get my point) of software includes some sort of encryption. For one, think about all the libs/apps which communicate over the Internet and use encryption libs to talk via HTTPs. Is mentioning The Wassenaar Arrangement [1] in terms of software even necessary nowadays?
Linux, Windows, MacOS - all have encryption libs built in (at least on the kernel level). They have been made in various countries, yet they are used all over the world. Do they fall under the terms of The Wassenaar Arrangement?
--------
[0] https://github.com/jukefoxer/Signal-Android/tree/feature/wa-...
> Wat?
> In this day and age 99% (OK, this number is exaggerated, but you get my point) of software includes some sort of encryption. For one, think about all the libs/apps which communicate over the Internet and use encryption libs to talk via HTTPs. Is mentioning The Wassenaar Arrangement [1] in terms of software even necessary nowadays?
> Linux, Windows, MacOS - all have encryption libs built in (at least on the kernel level). They have been made in various countries, yet they are used all over the world. Do they fall under the terms of The Wassenaar Arrangement?
> --------
> [0] https://github.com/jukefoxer/Signal-Android/tree/feature/wa-...
> [1] https://www.wassenaar.org
It's also mentioned in the original signal repo.I guess they have their reasons to include it and the fork just left it there.
There is demand. If (for legal, security or UX reasons) Signal cannot offer a solution to that demand, others will step in.
On desktop you can copy the appdata folder over to the new device. (warning: this is not officially supported)
Note that you must close the app on desktop from the host computer before copying the files over, otherwise the forward secrecy stuff breaks and you'll have to reset the sessions on the migrated computer.
FWIW it's nice to have a plain text backup anyway, and a lot better than nothing. Maybe it works fine but I'd rather not import a backup that has "weird" results.
[1] https://github.com/johanw666/Signal-Android
[2] https://community.signalusers.org/t/lets-talk-about-backups/...
All you need to do is convince them that it's for their good, if they can agree on that then the technicality isn't difficult.
I suspect one of the most difficult to address is getting it to successfully evade the random vendor-built aggressive battery saving settings in Android. WhatsApp is usually whitelisted from those so "just works". If you don't do similar things for Signal, it will stop picking messages up/notifying you after a day or two of inactivity.
Unfortunately, that leaves me with ... nothing to recommend people switch to.
Whatsapp allows media from specific chats to be auto saved to photos. It is a very important feature, not sure how these aren’t making the priority bar.
So, get better parents?
My parents (and my extended family + friends) have been using signal since the Snowden leaks.
All I had to do was ask :) It's not really a hard app to use either, I had a few calls from them when they introduced the PIN stuff and when I or someone else have switched phone but it's not comprehensible. My parents are closing in on 80 now.
It sounds like your parents are very unusually observant! I have had coworkers much younger than that who cannot be bothered to read messages like that.
I'm not kidding - it worked amazingly well for us.
There have been lots of Signal forks with a variety of features the official client refuses to add or merge.
Yes MTProto is not audited blah blah. I use IRC too and that has exactly butkus for encryption :D
Telegram proves that to have even better UX, you need to sacrifice security (and privacy).
I can understand that they have limited funding and want to focus on the security features first and foremost, but that makes it really hard for me to get some of my friends to use it.
Having said that, I agree that Signal's UX is not bad, just that it could be better.
Telegram went UX first and turned down the crypto so that I can install Telegram on a fresh laptop and I've instantly got the same chats, with history, as I do on my phone.
But yeah, Telegram can't be trusted either. I hope matrix/element will replace both soon.
It took me at least twenty minutes to figure out how to add my friends to a room I created too long enough ago to have memorized the UI. And they added "Communities" which I created one of but cannot even tell what functionality it even provides.
I don't know if that's a client issue or not but it seems like (maybe?) it's trying to be a social network in addition to a chat app? Some kind of adding in Discord functionality or something?
I guess as long as I can not use social network features and still use it like I use Signal... to flexibly chat with whomever I know the ID of.
FWIW I've had one (very small thing) accepted and another not. That second wasn't a net positive if "security for the masses" is the only important goal.
The file is named `1b6b187a1b60b9ae8b720c79e2c67f472bab09c0`, `275ee4a160b7a7d60825a46b0d3ff0dcdb2fbc9d`, or `7c7fba66680ef796b916b067077cc246adacf01d`.
1. Make sure you've recently backed up your iPhone
2. Open up terminal and $ open ~/Library/Application\ Support/MobileSync/Backup
3. Pick the relevant Backup folder (look at the most recently updated column)
4. To find the files mentioned by umanghere, go to the folder with the relevant starting characters. Eg: 7c7xxx is in the '7c' folder.
5. Find the file and open using any SQLite browser. For OSX, this is a decent and simple option: https://sqlitebrowser.org/
From there, once you figure out the tables, you can ostensibly write a script to also migrate your chats from Whatsapp to Signal.
For media transfer, this may also be helpful (though I haven't tried it myself): https://apple.stackexchange.com/questions/365950/accessing-w...
I may write a script for this if I get a weekend free soon, but happy if anyone else does it as well.
The ReadMe says to 'Build and install this version of the Signal App and import the encrypted Backup of your signal messages.', so I am assuming we would have to build it but there are no instructions/steps on how to actually do that.
I have been struggling to get my family all moved over but if they have access to their old messages (so I might have to do this for multiple people), that might make it easier to convince them.
e.g. On reddit it's common for r/dataisbeautiful to have posts which show graphs/charts on texting activity from the beginning of relationships and stuff. Which requires some way of keeping that data around.
Bridging Signal to Matrix has been notoriously difficult because Signal is actively hostile to all non-official clients.
So yeah. Open source, but no open values was gained from that.
(I always come across sounding like I'm dunking on Matrix; I like Matrix. Different project, different goals.)
Also, XMPP is a good example of a 'victim' of embrace, extend, extinguish. I remember Facebook messenger, hyves chat, Google talk and briefly even WhatsApp, all in my desktop chat app. They all 'did' XMPP, but then removed federation, features or killed it entirely.
Actually this is exactly what Snikket is doing: https://snikket.org/about/goals
But in fact most servers are mobile friendly, and have been for many years. You can dig into the data at https://compliance.conversations.im/ (Conversations being the leading mobile XMPP client).
There is an active project working to improve things on the Apple side:
This phone number requirement is the biggest letdown ...
Personally I just read incoming message and never "scroll back".
Many also keep information around in chat messages, knowing "it's there", and don't copy it elsewhere.
Example from recent days: "what was [friend]'s postal address again, I didn't copy it over to contacts, search for address, there it is".
If Signal wants to provide a mainstream secure and private alternative to WhatsApp, then it needs to make concessions to accommodate these preferences. If they don't want to, that's fine, but it also means I can't recommend Signal to non-tech friends/family.
In case of whatsapp and keeping chat history it can mean years of chat history becoming public if for example your Apple / Google account (where whatsapp automatically stores your conversation backups) gets hacked.
Do you think the people on Parler would have used the DM function if they had realised all those DM's could become public one day? Of course not. But they simply didn't realize that the "handy" DM function meant those messages were stored somewhere and that in turns means it can all get public one day.
IIRC the backups aren't stored in plaintext. They are encrypted with a key known to the device and whatsapp. The key is restored to a new device by whatsapp after SMS authentication.
Hence only a Google Drive compromise will not lead to full chat history compromise. That also requires something like a Sim Swap attack.
This just isn't the threat model most people care about, nor do they have to. Given a choice between preserving their chat history with their loved ones and not having any of it in the off chance that it might be leaked somewhere, the vast majority of people will opt for the former. Once you value chat history and other media in this way, then the risk simply isn't relevant. Again, this is all irrelevant. You people keep thinking on this one track of "but it's not secure" when that isn't the overriding concern for these people. It needs to be secure enough while not completely disregarding one of their core needs (preserving history). It's non-negotiable and no amount of discussing of risk or privacy will change this. Again, I find it insufferable that tech people are so unwilling to take normal peoples' needs into account.
Signal has the opportunity to become the default secure messaging app while also providing "secure" backups. They don't even need to be cloud backups, though that would be preferred. Even local backups can be sufficient. But as long as they don't account for the needs of "normal" people, Signal isn't a real option.
If I go to my friend's girlfriend and say, here's this awesome secure messaging app that you need to switch to and she switches, then something happens to her phone and she loses all her precious chats, how do you think that's going to go over? I can blabber on about privacy and risks all I want, I'm still the asshole.
My parents wanted me to check on their house while they were away. I messaged them on whatsapp when I left my house and then again when I arrived at theirs.
A month or so after my trip I was sent a fine for not displaying my car license while my car was parked on a public road. I had driven down the road where the fine was recorded during the trip. Using the timestamps of the whatsapp messages I was able to show that there was not enough time during my trip for me to have stopped to park.
More of an aside, but what sort of car license must be displayed for parking but not for driving down the same road? Is it some sort of parking permit or disc?
My car was licensed at the time and the license was displayed correctly. I was not guilty of the offense and the whatsapp messages allowed me to prove that the officer who issued the ticket was lying.
Addresses were already mentioned, but that also applies to IBAN, email addresses, door codes, restaurants...
It's also some kind of light diary: you can easily deduce what you were doing on a certain day if you look at the corresponding message.
For me it's not important enough that I would want to migrate it to another app if I were switching (I'd just save the DB), but it's not completely useless either. And of course some people just store everything there, including things that were not messages in the first, just like they do with email. You can argue that they shouldn't, but if that's what they want...
Obviously that's also a privacy risk, e.g. in case you lose your phone. There are many countries where I wouldn't keep my chat history for more than one week.
More philosophically, the fact that such a doubt even exists is a little disturbing sign of society today.
Also Telegram is not open-source.
Also Telegram did some shenanigans with cryptocurrency a few years back[2].
Telegram does have better UX than Signal though.
[1] https://en.wikipedia.org/wiki/Telegram_(software)#Security
[2] https://en.wikipedia.org/wiki/Telegram_(software)#Telegram_O...
The Telegram apps are GPL. Their server is (afaik) closed-source, but having an open source server implementation doesn't mean much for a centralised service without any server-switching support anyway, so no effective practical difference to Signal here in that regard.
The E2E situation on Telegram is poor however.
If the E2EE situation is poor, what is happening on the backend with your data becomes more relevant.
Telegram is much better for “chat room” type capabilities, because that’s not what Signal does. Telegram, Discord, Matrix, Slack all have more robust large group features, but none of them are secure and private by default and none of them hide your social graph.
Failing that, certainly Matrix is the best option?
IRC is not even close to filling that role. It’s not more robust nor more secure. At the same time it does several things that Signal doesn’t. Signal, as a messenger, is not a “chat room” or “social network” in the same way that IRC, Matrix, and even Telegram function. There are. I thousand member rooms you can join. It’s meant for secure, small group, communication.
Maybe that will change and they’ll broaden, but I would rather see them keep to their niche and do it well. I have no problem having one messenger app and another for “communities” of sorts.