You can change your number
signal.org
signal.org
Surely this is referring to the ability to use a non-phone number ID, which they've hinted at before [1]. Looking forward to that, only because I know many others are!
[1] https://www.reddit.com/r/technology/comments/kt91qk/comment/...
;)
It's about storing as little personal information as they can.
But no, I don't use Signal. I just think it's strange how some people can't seem to wrap their head around any of the rationale for this when it's the most transparent thing in the world. Do I like it? No, but it's ridiculous how some people pretend to be incapable of critical thinking in order to talk about how it's horrible. If something is actually horrible, being deliberately obtuse isn't needed.
Whatsapp has 2 billion users, and they are pretty open that they upload entire user's phonebooks to Facebook-owned servers. We know Facebook is not worried much about privacy, so I am pretty sure that this data can be subpoenaed, sold and so on. If you care about privacy, you probably want to install something else, like Signal.
But you know what happens if you cannot get all of your friends converted at once, so you keep Whatsapp around? It will keep sending your contact list changes to Facebook, just at it is designed to.
Let me repeat this: you worry about metadata, so you want to chat to a friend via Signal. But the moment you add them, this is reported to all other apps including Facebook's Whatsapp. And there is no way to opt out of it.
How can people not notice this? How can any company call themselves "privacy friendly" and do this stuff?
This isn't that hard.
There's just so so many places to get tripped up by keeping data rather than just routing bits and never storing them.
Just delete them manually then.
Update Discord.messages
Set Deleted=True
Where messageID='71d01110-e3d8-4673-9ba0-7bc676c5b6e6'
Deleted!There is no such thing as privacy on Discord.
I don't think they're totally off-base: I haven't used my phone contact list for personal contacts for most of the last decade. It's just a collection of work contacts that I don't trust enough to add anywhere I actually talk to people.
I'd say at least 95% of smart phone users in the UK use WhatsApp. I think that's probably true of the rest of Europe as well.
We had AIM and message boards pretty early, but no dedicated phone lines. By the time cell-phones became ubiquitous, we had cars and could just actually hang out. And by the time we all moved apart, voice chat services were good enough to just hop back to the old chat model.
Do you have multiple Discord servers or just one for all your friends?
Roughly how old are you and are you a student or in a job or something else? What country or region?
When you meet a new person you want to stay in contact with, how do you do so?
Do you use only Discord with friends or do you also add them on eg Facebook or Email or any other communication system?
In my world (employed, UK, middle aged) at work generally we use Slack (kinda like you’re using Discord in a way), shifting to phone numbers when you know people well for non work stuff.
Everyone else I meet, the assumption is to exchange phone number and use WhatsApp - exceptions would be iMessage or Signal sometimes. Or email or Twitter in business circumstances.
However, the current wave of phone-number-tied messengers (WhatsApp, Signal) have definitely pushed me in that direction.
They have a desktop client, but it's just a weird thing that proxies through my phone in a sort of bizarre backwards self-hosting sort of way.
How does it help security?
You can use discord on multiple devices at the same time without the devices needing to directly sync with each other (because the state is stored on the server).
FYI there is a permission to disable this for a channel
I understand that Signal wants to be blame it all on users, but the practical consequence of their design is that the moment people want to talk to a single person on Whatsapp, they give out Signal contact list to Facebook.. and the moment they start using Google's backup, they give out Signal contact list to Google.. and if they ever buy a new phone, they share Signal contact list with whoever wrote migration tool for their data. And there are tons of other random apps which all require contact list access...
From the privacy standpoint, Signal having contact list would be better. At least then, I'd have a single party to worry about, instead of dozens.
And, that software regularly re-sends that encrypted list to Signal's servers' SGX enclaves for their contact-discovery protocol.
So whether or not Signal, or some entity near/around it, "has" the contact list is a matter of how much users trust Intel™ SGX® (as well as the chain of processes that deliver/update the Signal software on-device.)
What they're moving towards is a design that looks like what Apple did with their HSM quorum system. The contact information we're talking about is encrypted clientside, but with (usually) a memorable pin. Without countermeasures, memorable PINs are very easy to attack; SGX allows them to artificially limit guesses. As a user, you retain a security dial on this: you can use a more complicated passcode than a 4-digit pin if you don't trust SGX.
Obtaining the whole database Signal maintains gives you ciphertext that you need to mount attacks on user-by-user (and to make those attacks, you'd have to break SGX). It doesn't simply give you the plaintext SQL database other messaging systems collect.
AFAIK, it prompts at first, maybe a few times, but then stops.
> Signal's software-on-device definitely has the contact list
Definitely not required at all. Signal can use its own contact list.
> that software regularly re-sends that encrypted list to Signal's servers' SGX enclaves for their contact-discovery protocol
The SGX enclaves are not for contact discovery. Contact discovery worked long before Signal implemented the SGX enclaves.
As I understand it: The SGX enclaves store a crypto key that Signal adds to the user's password, to enable data migration: Users tend to choose weak passwords; if Signal truly wants their data to be secure, strong passwords aren't realistic. Their solution is ingenious (IMHO): 1) Append a random key to strengthen the password chosen by the user. 2) A locally stored key would be a big problem for data migration, such as lost phones; the key would be lost too, and thus all the user data. 3) Therefore, they store the key centrally, as securely as possible (in the SGX enclave). That does make the key more vulnerable, but if you choose a strong password then it's irrelevant - the attacker needs to defeat both the key and your password. You can also disable this backup feature if you like. Some reading (partly because I might misremember a detail or two):
https://signal.org/blog/secure-value-recovery/
https://blog.cryptographyengineering.com/2020/07/10/a-few-th...
I am not sure how Signal backups work or that user contacts, encrypted, are backed up to the SGX enclave. Where does it say that?
> So whether or not Signal, or some entity near/around it, "has" the contact list is a matter of how much users trust Intel™ SGX® (as well as the chain of processes that deliver/update the Signal software on-device.)
Again, if you choose a strong password then you only need to trust yourself, and I think you can disable it altogether.
It's been re-prompting me for years. If there's a time it stops, I haven't found it.
> I am not sure how Signal backups work or that user contacts, encrypted, are backed up to the SGX enclave. Where does it say that?
You're talking about backups. I'm talking about contact-discovery, wherein the client regularly sends (hashed versions of) all the phone numbers from your contacts (if you've shared them with the app) to Signal's servers, to let you (& them!) know you're both on Signal. How else would you think the notification you get when someone in your contact list joins Signal is generated?
Signal's claim that these oft-repeated intersection operations leave no permanent records on their servers seemed (last I looked deeply) based on the SGX attestation: that your list is encrypted such that only the trusted code will process it. If Signal, or hackers, or Intel Corp, or the "Intel Community" can compromise SGX's guarantees, they can decrypt & log the full set of phone numbers uploaded.
So again, it reduces to how much you trust Intel™ SGX®.
(Also note that even if you do trust SGX, someone you've never met can, by having your phone number in their contacts, receive a notification when you join Signal. And separately from any SGX-mediated threats, a persistent attacker with privileged views of your devices' network traffic – such as via an ISP or mobile carrier – can get, via the volume & timing of traffic to and from Signal's servers, a pretty good idea of who you're talking to.)
> I'm talking about contact-discovery, wherein the client regularly sends (hashed versions of) all the phone numbers from your contacts (if you've shared them with the app) to Signal's servers
If they are hashed, why do you need to trust anyone?
Note it relies on SGX for privacy. (Anything they did earlier may have involved even more trust of Signal Inc's servers.)
Hashes across the (tiny!) space of all phone numbers are easy to reverse via brute-force.
But also, again: how do you think Signal is able to notify you when any phone number in your contacts – even if you're not in theirs! – first joins Signal?
I think novok is right in their uncle comment -- the decision to force people to use phone numbers, with all the related privacy problems, was to increase adoption. And we should be upfront on it: "Yes, Signal could have made things more private if they would allow usernames/emails/UINs... but instead they decided to force phone numbers to get market share as fast as possible. Yes, this means millions of people are forced to share the Signal contact list with Facebook and Google, but it was worth it -- look we have 40 million users now!"
There is nothing wrong with reducing user's privacy in order to get more market share. But let's not claim that this was for users' benefits.
You have to remember, signal is about E2EE security for EVERYONE, not just nerds. There will imperfect solutions along that path, which also means things like no federation. Signal is very much about being effective vs about being 'right' and ineffective, because when you are king, you can start being right and effective.
Signal can operate using its own contact list, without accessing your phone's central contacts.
Next time when Facebook pulls something user-hostile (e.g. monetization with ads, yet another privacy policy change for the worse, ...) some people will simply install Signal. If they use phone numbers as (an) identifier, two people who do this independently can immediately switch to Signal.
If A convinces B to switch, and C convinces D to switch, B and D can now talk to each other, reducing the pressure to keep WhatsApp as more and more of your friends are reachable on Signal. Even if you're using WhatsApp in addition to Signal, with phone numbers as identifiers, you're no longer contributing to the network effect that makes it painful for your friends to switch from WhatsApp to Signal.
Given that network effect is what makes or breaks messengers, phone numbers as the primary identifier are the only reasonable choice.
In my opinion with or without FB putting anything more hostile people are moving, in drones, to Telegram. I see regular people (non-tecchies at all) in my friends' circle joining Telegram regularly.
I'm not saying TG is better than Signal but I think TG's userbase is many orders of magnitude bigger than Signal's.
As an aside, the idiom is "in droves".
In Switzerland for example Threema is popular. In many countries you still can't really exist without Whatsapp. In China, Wechat. In Taiwan I believe you use Line if you want to have any friends (or reach businesses). In the US, iMessage with a fallback to SMS is popular, while it's rare in Europe because the SMS fallback would bankrupt you due to per-SMS charges.
> They don't want phone numbers on the merits of phone numbers.
I thought they were pretty vocal about wanting to use phone numbers to save people from the pain and despair of having to enter their friends' usernames into Signal, a pure UI concern.
The server needs to store each pair of communicating parties if it wants to announce presence information like AIM did. But that's unnecessary for a phone-based messenger - everyone is always "present" at all times.
https://signal.org/blog/private-contact-discovery/
... Signal began by using the social graph that already lives on everyone’s phones: the address book. Rather than a centralized social graph owned by someone else, the address book is distributed and user-owned. Additionally, having the social graph already on the device means that the Signal service doesn’t need to store a copy of it. Any time someone installs or reinstalls Signal, their social graph is already available locally.
They are promising this for years and years, I hope this time is real. Specially if we don't need a phone number to create an account: that's just incompatible with privacy.
As I see it, there are three aspects to protected communication: privacy (no one sees what you're saying), anonymity (no one sees who's communication), and censorship prevention (no one can shut down communication). If we get strong anonymity in Signal then that is 2/3 and would be a great leap forward for free speech _everywhere_. I expect censorship prevention to be the hardest of these to tackle, even with decentralization.
[0] https://www.reddit.com/r/signal/comments/skoaf6/poll_why_do_...
[1] Yes, I realize there are issues with the poll. Polling is hard.
Quite a bit of code related to usernames has already been checked into Signal. Here's the username regexp and the method that checks if a username is valid: https://github.com/signalapp/Signal-Android/blob/a5e5a735800...
The other problem is actually the act of sharing a username. If my username is "godelski" then yeah, I can share it on HN and Reddit where I use that username. But now I've deanonymized myself to friends and family who can see that username through Signal. Alternatively, if I have a username "not_godelski" then how do I get in contact with someone on HN while maintaining anonymity? If I use share it under this account then those two names are linked forever and that deanonymizes me. I can't create a new account just to share that name because those groups know me by that name. If I can have an infinite number of usernames, that solves the problem, but this isn't practical (even 5 usernames would be problematic and requires a lot of cognitive load, which is antithetical to Signal's philosophy).
There's also a third problem I don't care as much about but I'd assume Signal does. And that's naming collisions. NYT has a Signal number that allows whistleblowers to contact them. What's stopping me from creating the username NYT_Whistleblower and becoming a honeypot?
Edit: Lots of people are saying you can't share contact without revealing your identity. Does a 1-click link not solve this issue? If I post a signal.me/#one-time-code/jdjkerfe2r3rfwseffre5ge5g then I don't see how that would reveal my identity. (I'm also not a fan of "you can't". I can understand this being unsolved, but it feels like there are solutions to this problem)
That's easy; you want an internal identifier for Signal accounts that is unrelated to display name. This is already routine in most places including Discord.[1] Nothing stops you from creating the username NYT_Whistleblower, but that won't be what the NYT advertises to potential whistleblowers.
> Alternatively, if I have a username "not_godelski" then how do I get in contact with someone on HN while maintaining anonymity?
Well, you can't. Revealing your identity necessarily involves losing your anonymity, and I don't understand how you think those two actions could be theoretically separated. If you want to share your Signal identity with someone who only knows you as "godelski from HN", then once the sharing is accomplished they will know that "godelski from HN" and "godelski from HN's Signal username" are the same person. So will anyone who was allowed to watch the sharing.
Perhaps what you want is a single buffer account, where you tell people on HN to contact your buffer account (openly identifying it with yourself), and then you use the buffer account to reveal the identity of your actual account?
[1] Note that there is a tension between having a unique identifier by which Signal knows who you are, and the need for participants in two group chats not to be able to notice that your two usernames in those two chats belong to the same person. Discord is failing at this. To be part of a group chat at all, someone is going to have to have an identifier for you; if you want to maintain cross-chat anonymity, you'll need to be able to generate disposable identifiers that you can give to chat admins.
Suppose Signal generates a one-click (or even temporary) link. I can share that link that'll connect. That can accomplish the same thing as a signal.me address. Onetime links are definitely a thing. I'm sure people that know more can share even more creative ways to accomplish this. Someone has to have some fancy ZKP method for initiating contact.
> Perhaps what you want is a single buffer account
I think I covered this in my "infinite accounts" above.
> [1]
Seems to be more easily solved by letting me specify a handle at the per-chat level.
> Nothing stops you from creating the username NYT_Whistleblower, but that won't be what the NYT advertises to potential whistleblowers.
Seems you're passing the buck. Making it a "not my problem" issue and I think this is a big enough problem that it would make platforms like NYT wary of using such a system.
How? So you've got your account with a display name of "NYT_Whistleblower". Now... how does somebody else find it by accident?
On the far anonymous end you've got 4Chan style anonymity, no permanent or any ID at all. Keeping track of individual people is nearly impossible. Conversations are chaotic and hard to follow. Pretty solid privacy.
I guess the next step up would be per conversation/thread/group whatever ID, you trade a small amount of privacy for improved conversation, privacy is still pretty good, a poor choice in username or username reuse could prove to be privacy risks.
I guess next up from that would be something like forum style usernames, like hn or reddit where it's persistent across the entire platform, but still doesn't have to be linked to anything permanent or 'real'. It increases the privacy risk again because now, your conversation history can be tracked across time. This does make it easier for more permanent connections to be made between users but does make it easier for sensitive details to be leaked depending on the user's behaviour.
Up from there you start getting into IDs that are linked to real world information about a user. This provides some pretty obvious privacy risks.
Ids linked to phone numbers are a strange case of trying to take an ephemeral ID that in todays world can change quite regularly and use it as a source of info for an ID based on real world information.
Connecting consists of exchanging public keys (which can be global per person, or compartmentalized per contact/conversation).
Rather than a central server relating messages to the right peers, there’s a global feed where you attempt to decrypt everything and the ones which succeed are obviously addressed at you.
The benefit here is that not even a central server operator like Signal can trivially tie messages or chat identities to peers.
You can't, and I don't think that's a surprising outcome. If you have a non-anonymous identity on one platform, and link it to your anonymous identity on another, then that latter identity is no longer anonymous.
You just can't really mix your anonymous and non-anonymous worlds without de-anonymizing the latter. That's kinda a fundamental property of how anonymity works, isn't it?
Well, if you're under attack, the 1-click link will reveal your identity to the first person to click on the link. But that's entirely different from what you're asking for, which is to reveal your identity to a specific person designated by yourself, regardless of who sees your link first.
The reason people are telling you you can't reveal your identity while staying anonymous is that those are opposite concepts. But if you're not trying to preserve your anonymity against the same person you want to reveal your identity to, you're on the much simpler problem of communicating in a way that is resistant to eavesdroppers. You don't need anything from Signal; you need an encrypted channel of communication with your counterparty.
That's true, but much easier to defend against. Since you can talk in a semi-synchronous manner and we can have a high _probability_ that the correct person will be be the one clicking on the link.
So if it works:
Godelski: Hey, let's chat on Signal, my link is signal.me/#one-time-code/jdjkerfe2r3rfwseffre5ge5g
Thaumasiotes: Great!
If it doesn't work:
Godelski: Hey, let's chat on Signal, my link is signal.me/#one-time-code/jdjkerfe2r3rfwseffre5ge5g
Thaumasiotes: Hey, link seems bad
While you're right that there are no guarantees, I don't think that's true for any system. There's only probabilities. Obviously there are other ways to do this along the same lines. I can have a global link that has infinite links (e.g. one I could place under my HN profile) that I can only have there. These strings are much easier to generate than usernames given that with higher entropy you don't have the same likelihood of a birthday clash.
I'm not saying that communicating without revealing your identity isn't a challenging problem. But there are clearly some versions that reveal _more_ than others. Maybe there's no perfect system (I'm not smart enough to know) but there's clearly better ones than others. Standard usernames seems to just be throwing your hands up and giving up.
> you're on the much simpler problem of communicating in a way that is resistant to eavesdroppers
We already have that. It's called E2EE.
> Godelski: Hey, let's chat on Signal, my link is signal.me/#one-time-code/jdjkerfe2r3rfwseffre5ge5g
> Thaumasiotes: Hey, link seems bad
Sure, that interaction degraded gracefully. But your identity was also permanently compromised; it doesn't make sense to focus on how easy it was for me to say "hey, that didn't work". The reason the link went bad is that you disclosed your identity to someone you were specifically trying to keep it a secret from. This is an unforgivable flaw in the protocol.
>> you're on the much simpler problem of communicating in a way that is resistant to eavesdroppers
> We already have that. It's called E2EE.
Well, no. E2EE is the answer to resisting one particular eavesdropper. What you're trying to get at is called "public key cryptography", the system whereby two strangers can establish a secure channel without relying on an already-existing secure channel. E2EE has nothing to say about establishing secure channels; it just refers to the concept of using one.
Here's the system you actually want:
Godelski: Hey, let's chat on Signal, what's your PGP public key?.
Thaumasiotes: My PGP key is yyyyy.
Godelski: [encrypted for yyyyy: Here's how you can find me on Signal]
But notice that Signal doesn't participate in this exchange. Nor can it. I'm not on Signal, as far as you know; your messages to me have to use some other medium.
Only if I accepted the request. Clicking the link would presumably act the same way as a contact that you don't know. It asks before you accept. So I can wait till you respond.
1. Godelski shares 1-click link with Brigandish.
2. Brigandish clicks link and that registers Brigandish's Signal account with Godelski's Signal account, but no communication can take place yet.
3. Brigandish shares 1-click link with Godelski.
4. Godelski clicks the link, if Godelski has a registration waiting for Brigandish's Signal account then the handshake is complete.
I came up with this right now, I'm sure someone else can find a problem with it beyond it being a tad more bothersome than usual.
Users in conversations are linked by (private id and the persona id at creation), where messages get sent between the clients.
Meanwhile, people (or rather private ids) get added to conversations by using the publicly searchable personas (i.e. any globally unique string). Then for the life of that conversation, the persona is sticky. You could even add multiple personas from the same user to the same conversation if that is necessary. For some the persona id could be phone numbers, full names, online aliases, emails, etc.
People can then hand out different personas depending on the context.
A Signal username is global to Signal communication; a phone number is global to far more.
Scope tends to widen.
It was trivial to create multiple pseudonyms and the only one who could unmask it was Google and whoever could force Google.
This of course meant you had to trust Google but compared to having to trust everyone that is still a huge improvement.
I can see some reasoning, but there's technically nothing stopping them from allowing more universal ASCII characters at the very least.
Session has a lot of cool things going for it. They managed to solve the problems of P2P (high battery life number one) with these incentivised traffic passing nodes. They improved on TOR and you can already use the fruits of its invention for general traffic.
The big problem as I see it is the team is all Australian. They'll need to find a way to pass stewardship to the community in time.
> Even if you create a throwaway email account somewhere, it'll often be traceable back to you somehow.
I'm surprised to hear you say this considering your completely opposite stance in response to a comment of mine. I don't see how a throwaway email is any less anonymous than a username. In fact, I see it as more anonymous since I can generate these on the fly whereas I can't do this with usernames.
i'm really glad that they're moving away from phone number as identity, and hopefully to fully anonymous, which they've rightly been criticized about up until this announcement.
Because that's a pipe dream.
First of all, you can't monetize it, and, unfortunately that is a non-starter. I can't see people throwing money at this, with the implications. Secondly, assume I want to contact the same anonymous person again. They have to somehow easily prove they have access to that username.
Even 4chan had a mechanism for this. Assuming you don't shield your IP, or you move between locations between, at least the service knows that, and that isn't anonymous.
A pre shared key off a one time pad only proves that someone has the same pad.
I think anonymity isn't achievable. Secure is more important. I talk to someone a lot, I want that secure. I don't really care if anyone knows we're talking, just whether they know the content.
Hosting your own metal somewhere helps with that. You'd obviously notice a warrant or whatever.
If a person has your number in the contacts then your username and phone number are automatically merged together even if you were conversing to that person using your username from your perspective. That’s such a safety nightmare.
And everybody does that, either phone number or email.
The only software I could find for anonymous communication was old Polish communicator http://gg.pl which uses arbitrary numbers as identifiers
I understand that startups are scared that they won't be able to build up userbase from scratch but come on! Discord and Slack did it.
If I have this level of trust with someone they are about at level of adding them as a friend on Facebook. Who knows, I even might invite them on Facebook sooner than I decide to give them my phone number.
> what's the big issue with them having your number?
Seriously? With my number you can harass me endlessly with phonecalls, text messagers, registering for various services that will harass me basically forcing me to abandon this phone number and notify all of my valuable contacts of the number change.
Hell, they might even plaster town with my number with advert saying "Win 50$ in Chewbaca noise contest by subitting your best attempt at that number." as one creative asshole did to some poor girl.
> There's nothing stopping your interlocutor from leaking all of the messages you send to them
That way less of a problem if I haven't doxed myself in those conversations. All he will publish is some conversations he had with someone.
Yes that's exactly what Signal is for. Talking to people you would otherwise talk to on facebook messenger but you rather not have facebook engineers be able to read your personal conversations.
I don't care if you seen my dick if you have no way of knowing it was mine.
Do you want me to continue?
Yes actually.
The problem I'm seeing here with the responses is that people are only thinking of "one move." That first move is creating a anonymous username. Yay. Easy. Now here's the problem. How do I share that while staying anonymous? What conditions do I need? If I can only have one username for all of Signal, does that create a bigger problem? There's a few more "moves" for you and these are what I'm looking for answers to.
But some people are happy messaging people based on the phone number, because everything else is too cumbersome. Different people have different threat models, and one chooses the best UX for their threat model. For millions of people (maybe not you), apparently it is Signal.
> Can you send SMS to a regular number with this?
Why would it do that? Every phone has perfectly good sms app.
What would that even mean? Using sms as a transport layer? Or making messages passed through internet look like pseudo sms messages to someones phone number?
https://support.signal.org/hc/en-us/articles/360007321171-Ca...
Something like Google Fi can provide a web-based client for your SMS (which works on any device and doesn't require cellular) because they know your virtual SIM and can emulate it as needed. But I don't see how Signal could pull that off.
To avoid splitting one's messaging threads between two different apps.
> Every phone has perfectly good sms app.
Eh, I find the default Android SMS app to be lacking. I can't organize threads or mark messages as unread. You know, basic stuff that email apps figured out a long time ago.
If I remember correctly, Signal was first explained to me as a secure SMS app. That is it stores your SMS's more securely than the stock apps did... and if you were messaging somebody who also used Signal, then you'd be upgraded to an end-to-end encrypted message.
That said, now I'm on iOS, it doesn't let me do that, so I only use it for contacts with Signal.
They just wanted to piggyback on already existing network of people contacts.
Standard startup "growth hack".
,,To Signal'' it is a graph of random numbers.
Decentralisation and all that - again, other people.
It's pretty simple - user friendliness and sign-up friction.
Signal's main market is not us HN user tech bros who want (pseudo)anonymity. It's main market is closer to regular people, the same people who are fine with using WhatsApp or Facebook messenger or whatever, with their phone number.
They also want it to be as easy as possible for new users to sign up. Simply enter your phone number and boom you have a signal account. With email the sign up process is not insanely difficult - but its still more steps than phone signup for the regular person.
One counterpoint to using phone numbers: In China mobile phone numbers are almost universally enforced as your digital identifier because it makes surveillance extremely easy for a government while making it relatively hard for platforms themselves. Registering for a phone number mandates an ID check at the point of the service provider. This means that with a phone number based login, (1) you can be largely anonymous to platforms as you can have > 1 phone number, (2) you have 2fa built in automatically, but also (3) that the government can easily figure out who owns what accounts because your accounts are directly linked to your phone(s) and your phone(s) directly to you.
It would be a great step forward if Signal moves towards alternate verifications that don't involve phone numbers...
I remember looking into this a few years back and the only issue I found was that the company that owns it now itself wasn’t entirely trustworthy.
Spam protection is hard. Forcing to use phone numbers is a "easy" protection against spam. It's harder to get thousands of SIMs than thousands of usernames.
Taking a new device into use was as simple as authorizing it from one of your existing devices. All the data would sync over and be encrypted with a device specific key locally. And you could disable that key from any of the other devices.
Too bad that company more or less failed. They never really figured out a business and the zoom acquisition looked more like an acquihire than a long term commitment to the product. But it's a good design that is worth copying.
I don’t use slack but the few times I tried to use discord it always said something suspicious was going on and asked me for my email (needless to say I immediately closed the window) I wasn’t using vpn, only my default ublock and Firefox built in track blocking.
Phone numbers though are terrible because they're tied to countries, their security depends only on your carrier, you can't run your own carrier to take it into your own hands, and sending SMS costs money. Also the underlying interconnection networks like SS7 aren't secure at all and rely on trust.
TLDs are managed by governments or government-adjacent organizations. Domains are managed by the TLD manager. Email addresses are managed by the domain manager.
I've never had a phone number or a domain name taken from me, but I've heard of more cases of the latter than of the former.
I've heard stories of how a US carrier issued a replacement sim card to a fraudster. I've also heard stories of how a Russian carrier intercepted someone's SMS messages to break into their Telegram account.
SIM swapping is a big problem, but that is more equivalent to DNS hijacking of your domain than to the concept of legal/contractual "ownership" or rights to operation.
But semantics aside, the important question is how easy would it be for a malfeasant to interfere with your quiet enjoyment of your public identifier (phone number or email address). SIM swapping is way too easy. Domain hijacking isn't hard either, and sometimes one attack can leverage the other.
https://support.signal.org/hc/en-us/articles/360007061192-De...
> Signal must be actively working on your phone to make changes to the account. Register to see these options for your number. Deletion requests are not accepted outside of the registered app because there is no way to accurately verify whether or not a number is truly associated with the requester.
You don't have to figure out if the user uninstalled. This also happens if they get a new phone and don't re-install on it, so relying on uninstalls wouldn't work anyway.
Or when you start writing a message to somebody, if they haven't read the last couple messages signal could make that obvious. Etc. Lots of easy fixes.
Signal does let you know, it never gets the delivered mark.
I found out many months later when we ran into each other by chance that they don't use Signal anymore and my messages had gone to a blackhole..
On android it easily replaces messages app and you do all messaging, SMS and signal in one chat.
Complain to Apple. Not to Signal.
I use my google voice number on multiple phones.
Quite a workaround, but should work ;-)
On the other hand, if the second phone should have the same capabilities as the first one, key management suddenly gets extremely complicated. For instance, each device has to be able to revoke others; what happens if the revoked device had granted access to three other phones, are they revoked as well? Can a device revoke it's "parent" device? And so on. I imagine they avoid this while they can.
Almost never is this true, even on small projects, which Signal is definitely not.
Any use of a non-e2e service as a replacement for an e2e service basically means either self-censorship or recklessness. The data is not going away, and if context changes can implicate everyone involved.
https://www.brainyquote.com/quotes/cardinal_richelieu_183310
It's also impossible to effectively self-censor in the present for potential content-based threats in the future.
Discord also bans certain entire domains from being sent as links in DM, as an antispam measure, and requires in their ToS that people give up their civil rights to join. It's not polite to ask friends to submit to third-party censorship of private conversations just to talk to you.
If Signal didn’t suck as much, my friends wouldn’t have left and I wouldn’t have followed them. It’s really that simple.
I have only a handful of people that know and we negotiated that face to face prior, Signal breaks that trust
Are there communities out there where someone being on signal is a red flag?
Let people decide for themselves what in their lives is OK to share with others. You don't need to know the reason why.
The behavior which is reliably objected to by someone on HN, every time Signal is mentioned, is that the app sends a user an alert when someone in their contacts list is on Signal.
Phone numbers are the only resolution mechanism in Signal. Should that change? Separate question.
Having someone's phone number is by definition a way to contact them. Registering for Signal is by definition agreeing that anyone who searches for your phone number can send you a message on Signal.
What is the privacy violation in pushing awareness of that affordance? What about pull-only is better?
Signal does what I want it to here, and my trouble understanding why someone would be ok with everything about Signal except the push notification on join to people who have your number is genuine.
It's easy for me to understand why people don't like that a phone number is inherent to Signal, don't much care for it myself. But it's unrelated.
A username kinda restore that, but it could be taken a step further and ask for a secret token when adding contacts. That way you know exactly who has you in their contact list, and this token could be revoked (equivalent of blocking the person).
Absolutely. Outside of the tech industry, people have a "reason" for using Signal. My wife remarked one day that one of her coworkers (a plant operator) suddenly appeared on Signal. I mused that he is probably cheating on his wife. She found out a few weeks later that my hunch was correct.
Other people I've seen on it I've been able to deduce that they're using it for drug purchases (simply by process of elimination, nothing else made sense) even when I didn't already know they were into recreational drugs.
In some circles, Signal is used just for general conversation. But in most, it's not. So being on it is a pretty strong signal that you're doing something 'important' on it...and usually its easy for friends and neighbors to narrow down what that is.
And then there's my mom, she's on a grandfathered mobile plan that charges her $1 every day that she sends any text messages. I got her on signal so she didn't have to pay the $1 when she texts me. She got her whole church music group to switch for the same reason.
Adobe doesn't tell everyone that I own Photoshop. Gmail doesn't tell everyone that I have a Gmail email. PornHub doesn't tell everyone that I subscribe to their premium account.
Why the fuck does Signal need to? Broadcast should be off by default, on by opt-in.
Adobe and PornHub don't have the contacts list. Google likely does but maybe they are restrained by privacy laws.
https://support.signal.org/hc/en-us/articles/360007061452-Do...
It doesn’t send the number to them - Signal don’t get the contact list from your phone. It uses a very clever private contact discovery protocol.
The reason their phone has to know is so that they can then message you. Otherwise there would be no way to message people - a phone has to know who is on Signal to be able to do that.
While the notification could be off by default, since the phone necessarily has to know when your contacts are on Signal for the app to function, it is being transparent about the privacy situation.
Details of the private contact discovery system:
Don't know about Signal, but Whatsapp does the same thing (advertise to your contacts that you have a whatsapp account) and I find it extremely offensive.
Context: I am an ardent anti-whatsapp activist, thus I don't have a whatsapp account. This activism has created quite a stir in my family and made a lot of people angry, yet I stick about it. I have forced many of my close family and friends to use a different communication channel with me, and I have lost the contact of quite a few acquaintances. When my dad died a few months ago, her wife needed to talk to me (and I needed to talk to her quite a lot). She was not really in the mood for listening to my techno-activism platitudes, and I was not in the mood to perform them, so I had to open a whatsapp account. Since all the people who I had forced to stop using whatsapp to talk to me would have felt alienated by this at this point, I needed to take a new phone number to talk to my stepmom via whatsapp.
This is a concrete example of why advertising the fact that I have a whatsapp account is an extremely annoying anti-feature. I'm sure there are similarly legitimate reasons for disliking the same feature in Signal. In any case, for a platform that has the privacy of users as one of its main tenets, this is a clear-cut case of anti-privacy feature. I can imagine reasonable people avoiding Signal precisely for this.
I don't know precisely how Signal does things, but I know this can be an issue on Telegram - and I assume they work similarly. I can see a lot of reasons folks might not be fans of phone-number-as-ID, especially when it alerts folks that you've joined, or gives folks who merely possess your phone number an easy way of viewing your profile details.
I think the first quality E2EE messaging service that provides users an alternative to phone-as-ID could give Telegram/Signal (not that the former is necessarily E2EE) a serious run for their money among privacy-conscious users and members of fringe communities.
- the person is in your own contact list
- you create a conversation with them
- you accept a conversation from them
see: https://support.signal.org/hc/en-us/articles/360007459591
That's what I observe by using Axolotl on the phone and Signal Desktop on the computer.
Sure, but this is realistically a tiny group, and development effort is probably better spent making the 99% that don't fall into this category happier rather than prioritizing features needed for the 1%.
And pleas don't respond with "you could just block them" that not in line with how the psych of many, especially vulnerable people work.
Also pleas don't respond with "you can just change your number", for many people changing their number is hard which again for some vulnerable people can mean it's basically impossible.
Sure it's not a "my whole live will be messed up because of it" feature, but it easily can be very very unpleasant.
Like as an harmless example I know someone who completely changed their live and do not really want to have contact with anyone from their old circle of friends (not because of them being bad people, but because of the memories this includes). But they are to polite and insecure to outright block them, similar changing the number isn't an option for them. And guess what happened recently Signal told me: Hy person X joined Signal. I knew better then to contact them, but I wouldn't be surprised if this caused them quite a bit of distress/discomfort.
Anyway, I'm fine that people which have my number can write me over signal, or that their app knows when the number is changed, to warn if the old number is used and hint at you when you try to contact the old number. I'm not happy about Signal (and others) actively telling everyone "Hy this person did [join|change number]". It's unnecessary and for some people harmful.
I use a virtual number for Signal and any such services, and it's a different virtual number than the one I give to humans.
Can't a person who wants to know if you are on signal do so simply by starting a message to you?
Are you suggesting that simply making this less convenient on the client will somehow discourage someone who is determined to figure this out about you?
But who knows, the private contact discovery is quite magical so maybe there’s a way….
On the other side of associating me with people, I'm also looking for an Apple iOS update that lets me upload just some contacts, when an app asks.
You draw the attention of people with whom you have perhaps decided to let the relationship cool, and suddenly: "Hey, [YOURNAME] is here! Remember him? And how you have unfinished business? Why don't you message him right now?" :-(
ID shouldn't matter to most users (it can be hidden behind the scenes). Phone # is great for looking up the ID, but users should be able to remap it at will.
Example:
register with your phone #. This generates a new ID (you don't know or care about it). If you have to login from a new device, that doesn't have the ID stored, can you login with your phone #, but all this does is look up the ID and uses that ID to try and then authenticate you.
If someone wants to find you, they use the phone number to look up your ID. Once its looked up and mapped, the phone number never needs to be used again.
If I change my phone #, all I have to do is update the mapping of phone # -> id (i.e. add a new entry, remove the old entry). Anyone contacts who have me already, will not be bothered by this (they only care about the ID, which they already have). new "contacts" will also behave correctly, as I no longer have that phone #, so it shouldn't be able to be used to find me (it might be someone else's # now).
Users would be able to move phone #s and their existing contacts would be able to follow them. New telephone users would be able to get recycled old phone #s without getting messages from the old owner of number's contacts (assuming they had previously contacted).
the only places I see people think this might fall down (but I think are wrong) is
1) if the same user creates a new id with the old phone #. However, the solution seems pretty simple, you just need a way to invalidate the old ID (i.e. never to be used again) and force the contact to get the new id for the phone number.
2) what happens when a user moves devices. i.e. they might have to redo the mapping of phone # -> id. However. at its worst, this is no worse than the current system (which effectively does that update on every single message). In practice, there are ways to move data between devices which would just move the mappings with it (examples being a cloud cache backup, the ability migrate data from device to device, or probably other ways as well).
If they didn't anchor to something that they knew you only had one of, then it's not clear which of your devices should be authoritative. The alternative is to store your contact list on their servers, but they don't do that because they aren't confident that they could do so in a way that keeps your contacts hidden from somebody who gained access to their servers.
Often, letting an adversary know who you associate with is just as dangerous as letting them know what you say to those people. Having your phone number be the key means that metadata security comes down to whether you lock your phone instead of whether the bad guys can get a warrant to compromise Signal's servers.
It's a worse user experience, but I can understand not wanting to be responsible for the bad things that happen when bad guys map a target's social network.
End to end encrypted messages are harder than end to end encrypted contacts. Using phone numbers encourages people to use their phone's contacts app. Most people have theirs connected to Google or Apple. If they have other devices especially.
As for your second: what are the "ends" you're taking about with this "end to end encrypted contacts" idea?
Certainly, a contact list has to be visible at the device--otherwise it's useless. Where else would you want it to be visible?
* RingCentral: Softphones only (i.e., applications on a computer), IIRC - no hardware handsets.
* Nextiva: In my one experience, the sales culture as a bit of a hustle, but it worked out.
* 8x8
* Star2Star: Don't know much about them; maybe medium-to-large business only.
- Strong anonymity
- Offline and cloud encrypted backups that can be imported to the new IDs (also potential monetization source)
- Secondary IDs per user and one off IDs, with the nature of said IDs communicated to the other party (primary, secondary permanent, one off). Of course it could create problems but with a proper blocking mechanism within signal (e.g. block one off IDs and secondary IDs from unknown numbers) by default would be seamless.
-Mobilecoin usage seamless across IDs, retaining anonymity
Is there a way to export chat history into HTML or other file? I want to re read my chat sometime later.
While you can add your number to be searchable by others, it doesn't let strangers with your number know you signed up automatically, either.
Full disclosure: I work on the infrastructure behind it.
> Full disclosure: I work on the infrastructure behind it.
Oh cool... I ran a node for many months during the beta (from home, fiber optic at home). I'm busy atm so I'm not running anything anymore but I do really hope that a real secure messenger that doesn't leak metadata left and right, and which uses advanced cryptography, shall eventually prevail.
It protects metadata using a mixnet and the E2E encryption for authenticated channels uses post quantum cryptography(SIDH) to establish symmetric keys. The infrastructure is run by 3rd party node runners and there's an open source API for other applications in addition to the messenger being open source.
It's the project of David Chaum: https://en.wikipedia.org/wiki/David_Chaum
Which makes that messenger very interesting. It's also quantum-resistant from the get go. I think the beta just went live.
I'm also curious about scaling and collisions. Not only do you have a birthday problem with normal usernames, but what about special classes? Why do I not take all "nyt" and similar usernames to honeypot the actual NYT's contact?
It's not fully baked, but my expectation is that it will work similarly to how the .eth, namecoin, and other systems work, where you'll be able to register a user discovery service on a blockchain which the clients will recognize and use for searching. In this model, NYT registers "nyt.xx" and "rcarback" pops up in the interface as "rcarback@nyt.xx". As it stands, we've rolled out a basic version with a single central user discovery point for now.
That's a useful feature. Others (above) are telling me this is useless (I disagree). Are these identities separate?
The discovery service sounds useful
No idea what's going on with that site but I can't check out your project. I'd be interested in a ~two-sentence description of what it's like and how it's different. E.g., is it using the Signal protocol without phone numbers? It so, how's it different from Wire? If not, what does it use, custom protocol? Does it have a description I can look up elsewhere?
I'm not having issues with the website, but I will raise it with the web developers to see if they know what's happening.
As an example, one of the next applications I am working on with it is voting (a continuation of my PhD research). You can do things with this that you can't do anywhere else because you've got hundreds of untrusted, uninterested nodes, changing the threat model in a very important way. Unfortunately, I'm not aware of any other way to incentivize that without some form of payment system, which is why it is intrinsic to this chain.
It is fundamental to safe and fair commerce to be able to not be tracked in the ways we care about folks not being tracked. I want to do things like read my news subscription without them being a data vampire that tracks how long my eyes hover over each paragraph of every story then sells that to some advertiser. I also don't want my credit card company selling my purchase history to some government that then uses that information to decide if I am allowed to enter their country 15 years from now.
In other words, the project is not trying to be a slower, less private version of a credit card. We do not want to be just another privacy coin or utility for some pre-existing internet service and, unlike other mixnet projects, our goal is a much more ambitious resistance to global adversary threat model. We want to enable folks to do things over the internet with similar properties and experience as buying milk from the corner store with real money. We might not get there, but that's my vision for what we are trying to achieve.
Okay, im in
I cannot take seriously any claims made by the company or its employees / owners. None of it can be used as evidence of their goodwill or what they do with my data. They have an interest in deceiving me.
The whole plan to finally have usernames comes down to their use of Intel SGX.
They were forced to store (encrypted) information on servers anyway, since client-side contact matching didn't end up scaling, which is why stuff like this and usernames are now being developed.
Their new security strategy now relies on decryption being done by client-attested code on SGX enclaves, so that the server still doesn't have access to the plain-text contact graph.
All of this took a huge amount of time to come up with, and you can see the progress if you read their blogs or forums.
Are you suggesting that there isn't a contact graph on their servers? How exactly do they route from one user to another? It's certainly not P2P.
If you are suggesting that we should trust them just because it could work without them storing who I've contacted, you are mistaken. The whole point of private messaging is to obviate the need for trust. The code should be auditable/open source, and everything on the server should be either transparent, or assumed to be compromised. They certainly do send your contact graph to their servers, and whether they say they discard it or not is irrelevant. In the context of privacy, you must assume your data is persisted once it is behind a curtain you have no visibility into.
They can theoretically rebuild a contact graph by finding everyone you’re talking to, but that’s a small subset of the contact graph created by contact matching.
The code is open source and SGX literally means that the client attests that the code on the server matches what it’s expecting.
Signal might be the most audited stuff out there.
Also, aren't most mobile processors not Intel? How would SGX be used?
How do we know the closed source version of signal on the app stores is using the same MRENCLAVE as the one from the open source server?
Also, my understanding as to why a contact graph is needed at all is because signal wants to increase their virality. Couldn't we forgo this unnecessary feature? Signal could generate a long enough key locally, and if you want to add another signal user, the client could send it automatically to a contact through SMS. The client on the other side could automatically read the key through SMS and add the contact. Or the user could manually send the key through any mechanism they wanted.
A third note, trusting SGX assumes that 1. it has no bugs, and 2. it has no backdoors, 3. Signal server code has no bugs, 4. Signal server code has no backdoors. The first two of these are not strong guarantees, especially considering that it's not open source, intel doesn't have a great track record, and nation state actors have been involved in weakening these sorts of features in the past. At least with the Signal server code you can audit it.
The version on app stores is not a closed source version. However it is a binary, and there might be questions on build reproducibility. I do not know the answer to this nor the answer to your MRENCLAVE question.
Virality is because of their philosophy - their first goal is to end mass surveillance, not provide custom software for preventing individual surveillance. The quicker everyone in the world is using E2E, not only is there less mass surveillance, contact discovery leaks zero additional information at that point.
Concerns with SGX are real - but it remains the state-of-the-art - your criticism assumes that the competitors do any better, at this point they do not. They have traditional backends or are as flawed. Signal is doing the hard work on researching solutions at this point, the others are not as close.
> Signal could generate a long enough key locally, and if you want to add another signal user, the client could send it automatically to a contact through SMS. The client on the other side could automatically read the key through SMS and add the contact. Or the user could manually send the key through any mechanism they wanted.
This is what happens when contacts verify each other through QR codes on Signal. But this mechanism does not solve your problem nor are you solving the problem Signal wanted to solve - minimizing data on servers. Even with keys, servers still has to route messages, and with your solution they'll have to maintain a user database.
And why has this been "in the works" for years? It's certainly not that hard to implement. Many less capable and mature messengers work without a phone number.
It's hard to implement it in a privacy-preserving way. Many other messengers of similar scale implement it by storing your social graph unencrypted on their servers.
Signal does not, and that's guaranteed by the client code (i.e. no need to trust anything on the server for that).
This is not true. This is not guaranteed even by the "sealed sender" feature that signal has.
My use case for Signal is friends and family, and it was easy to get everyone onboard because we all have each other's phone numbers already and didn't need to build a new list of contacts. It's a drop-in Android-compatible replacement for iMessage.
You have to give up your anonymity to get one in many places.
"Just give your phone number to us, and don't worry, we won't share it with anyone!".
That exactly what Signal does.
Until they allow user-created ID's with no link to any identity - the above concern stays.
You don't need to use a GSM number, and you don't need to use the country code in which you live. The fact is, mostly anonymous phone numbers are available on the internet for use with Signal, and Signal (correctly) does not discriminate on country code or "type" of number. Any number that can receive phone calls or texts will do.
There are indeed countries that want to tie phone numbers to strong identity, but you can simply get a second number from a country that's not so hellbent on restricting access.
The number you're logged in to in Signal on a phone does not need to be the same number of the SIM card inside that phone. You can use any number you wish.
My phone number identifies my country, my address and my real name - even if I restrict the listing, it's tied to my credit card. It's tied to a sim card with separate geolocation data to the GPS tracking Google does; even if I active signal from eg a pine phone, the number is tied to a 4g base station.
Ed: and its tied to my current place of employment, too.
None of this is needed/wanted for my signal identity (for me or signal).
I could go out of my way to acquire a pseudonymous phone number, but I guess I'd have to be able to use it somehow - which seems pretty hard to keep anonymous. At the very least I'd probably have to pay for it.
Signal should be able to do better than PGP and five mix master hops of 90s-era anonymous email...
Or you get the old problem of those needing actual secure communication using terrorist@phreak.suspicious.net.ru and using signal just for "other" stuff..
Ed: note that this mostly about connecting with people on signal that otherwise might not have my number, than about (almost) random people that have my phone number discovering that I'm on signal.
An article has only 15 minutes in /new to attract enough votes. Sticking with a crappy title nobody will click on wastes everyone's time. Obviously don't go full clickbaity.
Sometimes the HN mods change them back.
It's more nuanced than that. See https://news.ycombinator.com/newsguidelines.html: "Please use the original title, unless it is misleading or linkbait; don't editorialize."
Worst yet, the title edits that would annoy people if HN had a different policy (and they would be legion) go uncounted because we don't allow them to happen in the first place. Such a regime would be much less smooth, because for each title edit you (i.e. anyone) happened to agree with, there would be a lot more rubbing you the wrong way.
The fundamental principle here is that on HN, being the one to submit an article confers no special right to interpret or frame it for others. We want the articles to speak for themselves, and we want the front page to be as accurate and neutral as possible ('bookish', to use PG's old word for this). Misleading titles and clickbait titles get in the way of that, so the HN guidelines ask submitters to change those. Otherwise not.
Threads are so sensitive to initial conditions that the power to rewrite a title is literally the power to reframe the entire discussion, and therefore control it. On HN, we want the author of the article (or creator of a project) to have that power, not the submitter. That really is fundamental—it's the reason why HN's front page is the way it is, and therefore the reason why HN is the way it is. To change it would be to mess with the DNA of this place and would soon lead to a completely different forum. Maybe a good forum, but not the kind that HN is trying to be.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
FWIW, I think this is an unfair characterization of my complaint. Yes: I can and would (and once in a blue moon even do) make this complaint "as a user" of Hacker News, and you can certainly claim that I only notice the places where it is bad and am failing to notice all the places where it is good. I assure you: I understand this well enough to make your argument for you against me as a user and I agree we can bicker back and forth about whether this is a good idea without it mattering much. (I do think you are wrong there also, and I think that you are incorrectly associating one property of your platform you are tasked with defending as somehow being center of it, but that is again a separate argument we could have.)
However, what I think you are missing is that, when you are making arguments about content in general across this website and how most cases work, you are doing so from the vantage point of the moderator and have--in my eyes--become blind to the plight of publishers, some of whom run into this policy not every now and then but on every single post they are involved in due to their medium or other constraints of their audience. While on average it is maybe not so harmful, it disproportionately negatively affects some content that the readers of Hacker News do seem to greatly value more than other other content.
If you primarily publish changelogs or summary pieces (both of which can get a lot of play on Hacker News... but only for one subsection, not the whole article), publish to mailing lists or forums (where the titles are often under someone else's control or abnormal to use at all; we see a lot of great content these days on Twitter, and I would use it more often were it not for Hacker News and its title policy), or even technical articles on smaller blogs designed for closed audiences that would find a title for a "general" audience off-putting, you become permanently trapped in what to you is a disregarded corner case.
> On HN, we want the author of the article (or creator of a project) to have that power, not the submitter. That really is fundamental...
I am thereby very glad (though also quite a bit sad) you said this (and might have not bothered to respond had you not, btw), because I am an author making this argument first and foremost on behalf of my work as an author, and I feel this power dynamic issue deeply (on reddit, every now and then someone is egregious with an edit... and sure it might feel to you that that is a problem as you remember when it was a problem, but the vast majority it goes unnoticed ;P). And yet, I claim the policy as used and enforced isn't giving authors the power you might think they are being given, because--as I had indicated--the concept of titles is not anywhere near as well-defined as you make it out to be, and so as an author I think this policy is actually poorly designed.
About a decade ago I seriously got into a (quick, but so very memorable) argument with someone on Hacker News about the title of one of my own articles, one which--in its medium (Google+)--should not actually have a title. The article did have an official title that was used everywhere the article was linked, but it wasn't part of the article due to its medium. I think that was probably the first day I got angry at the policy, and it was "top of mind" as it was itself an article about policies (real name policies) that disproportionately affected certain users but are defended by moderators because it works for the majority... that was itself running into issues on another website due to a different policy with a similar kind of inherent design flaw falling into a similar blind spot (though of course the real name policy is much worse, I do want to make clear; that said, permanent unique user names are almost as bad, and Hacker News has those).
Over the years, then, I came to the point where I actually feel a need to give advice to people publishing content so it can be "Hacker News compatible", and that advice generally harms the person's "usual" audience :(. In particular: you need to publish things only on mediums that support titles (or if you must, add a title; yes: if you publish content on Twitter, if it might get linked by someone to Hacker News, I guess you need to dedicate part of your thread to give the thread a "title"), with "boring titles" for a general audience, with a separate top-level URL for each and every single topic.
BTW: I want to expand on the "boring titles" part of that. The best titles to choose in most contexts--and I am not saying that is true of Hacker News, as that is but one of many venues--are often "editorialized", because they are designed to be catchy and memorable and create a strong hook for the reader, who shares context that you have due to being part of your audience. And yet, Hacker News has a quirk in their policy whereby, if an upstream title is editorialized, then the author suddenly isn't supposed to be given the power. If you were consistent on that front I might find the policy more sympathetic.
As a local politician who pays careful attention to this kind of editorialization, I see this dynamic play out a lot with the local newspaper: the news articles in their print edition have highly editorialized titles designed to even be "misleading", while their online version?... not so much. That is because their audience in the physical paper is different from their audience on their site, the latter of which more often being random people linked to one post. One that was so memorable it has stuck with me for many years: online it said "UCSB Acquires Dublin’s, Precious Slut Property", while the paper copy said "UCSB Buys Precious Slut" (which doesn't even have the same meaning, but we get what they are after and it is funny).
And so after a full decade of dealing with this over and over again, I now find myself thinking about it every single time I publish anything anywhere. And it sucks: I spend most of my time on this website in this community (which I will note I absolutely do not believe is reliant on this policy to function any more than Facebook is reliant on a real name policy), and yet I also resent it deeply due to a rule that--at least in its exact implementation (which I bet could be fixable with minor changes)--almost no one in my circle thinks is a good idea: we just tolerate it because of network effect lock-in. I don't think I have published anything anywhere in the past decade without having to decide how to placate this policy. The best idea I have come up with so far is to use User-Agent detection tricks to give people on Hacker News a different title than anyone else, in my attempt to actually feel like I am in control as the author (which I clearly don't currently feel I have).
If you primarily publish changelogs or summary pieces (both of which can get a lot of play on Hacker News... but only for one subsection, not the whole article), publish to mailing lists or forums (where the titles are often under someone else's control or abnormal to use at all; we see a lot of great content these days on Twitter, and I would use it more often were it not for Hacker News and its title policy), or even technical articles on smaller blogs designed for closed audiences that would find a title for a "general" audience off-putting, you become permanently trapped in what to you is a disregarded corner case.
We're trying for a global optimization here—interesting content, free of sensationalism to the extent possible. We're not bureaucrats trying to enforce little rules. Always the intent is to be a spirit-of-the-law place, not a letter-of-the-law place [1]. If you've got content that you feel is great for HN but whose title doesn't fit the cookie cutter, you're always welcome to email us at hn@ycombinator.com. Our goal is also for HN to feature the best content, where 'best' means most interesting to the community. (Of course, there's also often a tension between what an author feels is great content vs. what the community (or moderators as a proxy for the community) feel is great content. That aspect is unavoidable, given how scarce frontpage space is.)
It's true that baity titles work better for attracting enough quick upvotes to make HN's front page, but then one of two things typically happens: either readers (who there are far more of) see the bait, go "WTF is this doing on HN" and flag the submission; or, moderators notice the submission, see that the article is good, and replace the title with something more accurate and neutral. That's not such a bad thing in practice. Some good content does surface that way.
[1] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
Certainly this list isn't complete, and just as surely the moderators are open to adding to that list as contenders enter the ring.
This impacts everyone who takes photos on Android with Signal, it's not a niche problem. It seems like an easy fix, and I'm perplexed that it doesn't get prioritized. Ah well, can't complain too much about a free product.
It’s a ridiculously consequential bug and they don’t seem motivated to even comment.
Pretty sad.
Every time I upgrade my phone I have to reformat & disable iCloud lock and hand in my device before I get a new one. So Signal's workaround of having two phones side-by-side to transfer is a non-starter. (Also useless if you happen to physically lose your old phone.)
They don't have the resources to store files on the cloud, even encrypted, and don't appear to have taken WhatsApp's approach of backing up unencrypted media and messages on user's third-party cloud services like Google Drive and iCloud.
You can mitigate this by having disappearing chats (current longest self-destruct time is 4 weeks), or by going to Settings->Data and Storage->Review Storage and deleting the largest files.
This isn't a great UX design, as users are not informed there is a problem, or how to solve it.
When you select “delete all message history” it should free up the disk.
Also, what good is secure encryption if i have to give out my phone number?
Actually how could you possibly deliver secure messaging if it doesn't work with simple identifiers you already have like your phone number? Everything should be secure, that's Signal's thesis.
This reminds me of the people who were convinced HTTPS should only be used for "important" stuff that "needs to be secure" like banking and so it's wrong to have HTTPS on your blog, or news site, or whatever.
It's tying my Signal identity to my phone number. To speak in US terms, you're safe from your comms being intercepted by the KGB, but now you're a person of interest to the CIA :)
I don't want to disclose my phone number to any user, platform or any app.
Just please STOP.
Regardless, I don't know why they are pushing in a somewhat unregulated, volatile cryptocurrency that will be used by extremists, terrorists and the like who in no doubt will not only use it to fund their activities and will be sitting in their group chats but now they can change their phone numbers to hide even further?
The road to hell is been paved with good intentions. Hasn't it? But at least Wire does not still require a phone number, nor does it have silly cryptocurrencies in their product for pump and dump purposes.
The alternative is having the server know who is talking to whom. Further, phone numbers provide a valuable bootstrap to connect with people.
Other secure messengers have chosen a different design than Signal. This means you can choose the one you prefer.
It's clearly a lot higher data overhead, but that'd acheive phone numberless accounts without signal knowing 100% A is talking to B.... Only that 'A' might be talking to 'B'..Or C..or D.. Or sending decoy msgs intended for nobody.
Settling for phone numbers on a privacy based messenger because it's too hard to do an alternative implem is a cop out I feel. What do you think of the above proposal?
How are you going to do this without getting this person's public key? And how are you going to get their public key without asking signal?
So signal knows you requested all your contact pubkeys, that you sent a duplicate broadcast to all contacts, obscuring who it was intended for... that could be 0-n of m persons.
Despite a really good uptake, some didn't make the move and it's definitely fragmented some of our online groups (makes it more interesting when physically catching up though, silver linings!). I'm not sure throwing yet another messaging platform would help.
But at that moment a choice for a new system was made, it's not so much about doing yet another move right after the previous and fragmenting it further. Any particular reason you didn't try Wire in the first place, if you don't like the phone number requirement?
This is why I use Matrix/Element
Have the option of decoupling it entirely from the phone.
The government can track you a lot easier than pinging via signal btw. A lot easier!
All phones have internet connectivity... The phone number is completely useless to talk via the internet anyways...
> The government can track you a lot easier than pinging via signal btw. A lot easier!
I think that it is easier to connect a real-world identity to an internet account when they also have your phone number associated with the account...
That the default is phone-number based for discovery is a savvy and logical move for adoption. So add it as an optional feature.
The conclusion that I immediately arrive to is that this software must be a honeypot of some sort because it makes no sense. Literally zero.
Otherwise anonymous usernames + passwords would perfectly do.
Okay, then.