Surely this is referring to the ability to use a non-phone number ID, which they've hinted at before [1]. Looking forward to that, only because I know many others are!
[1] https://www.reddit.com/r/technology/comments/kt91qk/comment/...
Surely this is referring to the ability to use a non-phone number ID, which they've hinted at before [1]. Looking forward to that, only because I know many others are!
[1] https://www.reddit.com/r/technology/comments/kt91qk/comment/...
As I see it, there are three aspects to protected communication: privacy (no one sees what you're saying), anonymity (no one sees who's communication), and censorship prevention (no one can shut down communication). If we get strong anonymity in Signal then that is 2/3 and would be a great leap forward for free speech _everywhere_. I expect censorship prevention to be the hardest of these to tackle, even with decentralization.
[0] https://www.reddit.com/r/signal/comments/skoaf6/poll_why_do_...
[1] Yes, I realize there are issues with the poll. Polling is hard.
Quite a bit of code related to usernames has already been checked into Signal. Here's the username regexp and the method that checks if a username is valid: https://github.com/signalapp/Signal-Android/blob/a5e5a735800...
The other problem is actually the act of sharing a username. If my username is "godelski" then yeah, I can share it on HN and Reddit where I use that username. But now I've deanonymized myself to friends and family who can see that username through Signal. Alternatively, if I have a username "not_godelski" then how do I get in contact with someone on HN while maintaining anonymity? If I use share it under this account then those two names are linked forever and that deanonymizes me. I can't create a new account just to share that name because those groups know me by that name. If I can have an infinite number of usernames, that solves the problem, but this isn't practical (even 5 usernames would be problematic and requires a lot of cognitive load, which is antithetical to Signal's philosophy).
There's also a third problem I don't care as much about but I'd assume Signal does. And that's naming collisions. NYT has a Signal number that allows whistleblowers to contact them. What's stopping me from creating the username NYT_Whistleblower and becoming a honeypot?
Edit: Lots of people are saying you can't share contact without revealing your identity. Does a 1-click link not solve this issue? If I post a signal.me/#one-time-code/jdjkerfe2r3rfwseffre5ge5g then I don't see how that would reveal my identity. (I'm also not a fan of "you can't". I can understand this being unsolved, but it feels like there are solutions to this problem)
That's easy; you want an internal identifier for Signal accounts that is unrelated to display name. This is already routine in most places including Discord.[1] Nothing stops you from creating the username NYT_Whistleblower, but that won't be what the NYT advertises to potential whistleblowers.
> Alternatively, if I have a username "not_godelski" then how do I get in contact with someone on HN while maintaining anonymity?
Well, you can't. Revealing your identity necessarily involves losing your anonymity, and I don't understand how you think those two actions could be theoretically separated. If you want to share your Signal identity with someone who only knows you as "godelski from HN", then once the sharing is accomplished they will know that "godelski from HN" and "godelski from HN's Signal username" are the same person. So will anyone who was allowed to watch the sharing.
Perhaps what you want is a single buffer account, where you tell people on HN to contact your buffer account (openly identifying it with yourself), and then you use the buffer account to reveal the identity of your actual account?
[1] Note that there is a tension between having a unique identifier by which Signal knows who you are, and the need for participants in two group chats not to be able to notice that your two usernames in those two chats belong to the same person. Discord is failing at this. To be part of a group chat at all, someone is going to have to have an identifier for you; if you want to maintain cross-chat anonymity, you'll need to be able to generate disposable identifiers that you can give to chat admins.
Suppose Signal generates a one-click (or even temporary) link. I can share that link that'll connect. That can accomplish the same thing as a signal.me address. Onetime links are definitely a thing. I'm sure people that know more can share even more creative ways to accomplish this. Someone has to have some fancy ZKP method for initiating contact.
> Perhaps what you want is a single buffer account
I think I covered this in my "infinite accounts" above.
> [1]
Seems to be more easily solved by letting me specify a handle at the per-chat level.
> Nothing stops you from creating the username NYT_Whistleblower, but that won't be what the NYT advertises to potential whistleblowers.
Seems you're passing the buck. Making it a "not my problem" issue and I think this is a big enough problem that it would make platforms like NYT wary of using such a system.
How? So you've got your account with a display name of "NYT_Whistleblower". Now... how does somebody else find it by accident?
On the far anonymous end you've got 4Chan style anonymity, no permanent or any ID at all. Keeping track of individual people is nearly impossible. Conversations are chaotic and hard to follow. Pretty solid privacy.
I guess the next step up would be per conversation/thread/group whatever ID, you trade a small amount of privacy for improved conversation, privacy is still pretty good, a poor choice in username or username reuse could prove to be privacy risks.
I guess next up from that would be something like forum style usernames, like hn or reddit where it's persistent across the entire platform, but still doesn't have to be linked to anything permanent or 'real'. It increases the privacy risk again because now, your conversation history can be tracked across time. This does make it easier for more permanent connections to be made between users but does make it easier for sensitive details to be leaked depending on the user's behaviour.
Up from there you start getting into IDs that are linked to real world information about a user. This provides some pretty obvious privacy risks.
Ids linked to phone numbers are a strange case of trying to take an ephemeral ID that in todays world can change quite regularly and use it as a source of info for an ID based on real world information.
Connecting consists of exchanging public keys (which can be global per person, or compartmentalized per contact/conversation).
Rather than a central server relating messages to the right peers, there’s a global feed where you attempt to decrypt everything and the ones which succeed are obviously addressed at you.
The benefit here is that not even a central server operator like Signal can trivially tie messages or chat identities to peers.
You can't, and I don't think that's a surprising outcome. If you have a non-anonymous identity on one platform, and link it to your anonymous identity on another, then that latter identity is no longer anonymous.
You just can't really mix your anonymous and non-anonymous worlds without de-anonymizing the latter. That's kinda a fundamental property of how anonymity works, isn't it?
Well, if you're under attack, the 1-click link will reveal your identity to the first person to click on the link. But that's entirely different from what you're asking for, which is to reveal your identity to a specific person designated by yourself, regardless of who sees your link first.
The reason people are telling you you can't reveal your identity while staying anonymous is that those are opposite concepts. But if you're not trying to preserve your anonymity against the same person you want to reveal your identity to, you're on the much simpler problem of communicating in a way that is resistant to eavesdroppers. You don't need anything from Signal; you need an encrypted channel of communication with your counterparty.
That's true, but much easier to defend against. Since you can talk in a semi-synchronous manner and we can have a high _probability_ that the correct person will be be the one clicking on the link.
So if it works:
Godelski: Hey, let's chat on Signal, my link is signal.me/#one-time-code/jdjkerfe2r3rfwseffre5ge5g
Thaumasiotes: Great!
If it doesn't work:
Godelski: Hey, let's chat on Signal, my link is signal.me/#one-time-code/jdjkerfe2r3rfwseffre5ge5g
Thaumasiotes: Hey, link seems bad
While you're right that there are no guarantees, I don't think that's true for any system. There's only probabilities. Obviously there are other ways to do this along the same lines. I can have a global link that has infinite links (e.g. one I could place under my HN profile) that I can only have there. These strings are much easier to generate than usernames given that with higher entropy you don't have the same likelihood of a birthday clash.
I'm not saying that communicating without revealing your identity isn't a challenging problem. But there are clearly some versions that reveal _more_ than others. Maybe there's no perfect system (I'm not smart enough to know) but there's clearly better ones than others. Standard usernames seems to just be throwing your hands up and giving up.
> you're on the much simpler problem of communicating in a way that is resistant to eavesdroppers
We already have that. It's called E2EE.
> Godelski: Hey, let's chat on Signal, my link is signal.me/#one-time-code/jdjkerfe2r3rfwseffre5ge5g
> Thaumasiotes: Hey, link seems bad
Sure, that interaction degraded gracefully. But your identity was also permanently compromised; it doesn't make sense to focus on how easy it was for me to say "hey, that didn't work". The reason the link went bad is that you disclosed your identity to someone you were specifically trying to keep it a secret from. This is an unforgivable flaw in the protocol.
>> you're on the much simpler problem of communicating in a way that is resistant to eavesdroppers
> We already have that. It's called E2EE.
Well, no. E2EE is the answer to resisting one particular eavesdropper. What you're trying to get at is called "public key cryptography", the system whereby two strangers can establish a secure channel without relying on an already-existing secure channel. E2EE has nothing to say about establishing secure channels; it just refers to the concept of using one.
Here's the system you actually want:
Godelski: Hey, let's chat on Signal, what's your PGP public key?.
Thaumasiotes: My PGP key is yyyyy.
Godelski: [encrypted for yyyyy: Here's how you can find me on Signal]
But notice that Signal doesn't participate in this exchange. Nor can it. I'm not on Signal, as far as you know; your messages to me have to use some other medium.
Only if I accepted the request. Clicking the link would presumably act the same way as a contact that you don't know. It asks before you accept. So I can wait till you respond.
1. Godelski shares 1-click link with Brigandish.
2. Brigandish clicks link and that registers Brigandish's Signal account with Godelski's Signal account, but no communication can take place yet.
3. Brigandish shares 1-click link with Godelski.
4. Godelski clicks the link, if Godelski has a registration waiting for Brigandish's Signal account then the handshake is complete.
I came up with this right now, I'm sure someone else can find a problem with it beyond it being a tad more bothersome than usual.
Users in conversations are linked by (private id and the persona id at creation), where messages get sent between the clients.
Meanwhile, people (or rather private ids) get added to conversations by using the publicly searchable personas (i.e. any globally unique string). Then for the life of that conversation, the persona is sticky. You could even add multiple personas from the same user to the same conversation if that is necessary. For some the persona id could be phone numbers, full names, online aliases, emails, etc.
People can then hand out different personas depending on the context.
A Signal username is global to Signal communication; a phone number is global to far more.
Scope tends to widen.
It was trivial to create multiple pseudonyms and the only one who could unmask it was Google and whoever could force Google.
This of course meant you had to trust Google but compared to having to trust everyone that is still a huge improvement.
I can see some reasoning, but there's technically nothing stopping them from allowing more universal ASCII characters at the very least.
Session has a lot of cool things going for it. They managed to solve the problems of P2P (high battery life number one) with these incentivised traffic passing nodes. They improved on TOR and you can already use the fruits of its invention for general traffic.
The big problem as I see it is the team is all Australian. They'll need to find a way to pass stewardship to the community in time.
> Even if you create a throwaway email account somewhere, it'll often be traceable back to you somehow.
I'm surprised to hear you say this considering your completely opposite stance in response to a comment of mine. I don't see how a throwaway email is any less anonymous than a username. In fact, I see it as more anonymous since I can generate these on the fly whereas I can't do this with usernames.
i'm really glad that they're moving away from phone number as identity, and hopefully to fully anonymous, which they've rightly been criticized about up until this announcement.
Because that's a pipe dream.
First of all, you can't monetize it, and, unfortunately that is a non-starter. I can't see people throwing money at this, with the implications. Secondly, assume I want to contact the same anonymous person again. They have to somehow easily prove they have access to that username.
Even 4chan had a mechanism for this. Assuming you don't shield your IP, or you move between locations between, at least the service knows that, and that isn't anonymous.
A pre shared key off a one time pad only proves that someone has the same pad.
I think anonymity isn't achievable. Secure is more important. I talk to someone a lot, I want that secure. I don't really care if anyone knows we're talking, just whether they know the content.
Hosting your own metal somewhere helps with that. You'd obviously notice a warrant or whatever.
They are promising this for years and years, I hope this time is real. Specially if we don't need a phone number to create an account: that's just incompatible with privacy.
;)
It's about storing as little personal information as they can.
But no, I don't use Signal. I just think it's strange how some people can't seem to wrap their head around any of the rationale for this when it's the most transparent thing in the world. Do I like it? No, but it's ridiculous how some people pretend to be incapable of critical thinking in order to talk about how it's horrible. If something is actually horrible, being deliberately obtuse isn't needed.
Whatsapp has 2 billion users, and they are pretty open that they upload entire user's phonebooks to Facebook-owned servers. We know Facebook is not worried much about privacy, so I am pretty sure that this data can be subpoenaed, sold and so on. If you care about privacy, you probably want to install something else, like Signal.
But you know what happens if you cannot get all of your friends converted at once, so you keep Whatsapp around? It will keep sending your contact list changes to Facebook, just at it is designed to.
Let me repeat this: you worry about metadata, so you want to chat to a friend via Signal. But the moment you add them, this is reported to all other apps including Facebook's Whatsapp. And there is no way to opt out of it.
How can people not notice this? How can any company call themselves "privacy friendly" and do this stuff?
This isn't that hard.
There's just so so many places to get tripped up by keeping data rather than just routing bits and never storing them.
Just delete them manually then.
Update Discord.messages
Set Deleted=True
Where messageID='71d01110-e3d8-4673-9ba0-7bc676c5b6e6'
Deleted!There is no such thing as privacy on Discord.
I don't think they're totally off-base: I haven't used my phone contact list for personal contacts for most of the last decade. It's just a collection of work contacts that I don't trust enough to add anywhere I actually talk to people.
I'd say at least 95% of smart phone users in the UK use WhatsApp. I think that's probably true of the rest of Europe as well.
We had AIM and message boards pretty early, but no dedicated phone lines. By the time cell-phones became ubiquitous, we had cars and could just actually hang out. And by the time we all moved apart, voice chat services were good enough to just hop back to the old chat model.
Do you have multiple Discord servers or just one for all your friends?
Roughly how old are you and are you a student or in a job or something else? What country or region?
When you meet a new person you want to stay in contact with, how do you do so?
Do you use only Discord with friends or do you also add them on eg Facebook or Email or any other communication system?
In my world (employed, UK, middle aged) at work generally we use Slack (kinda like you’re using Discord in a way), shifting to phone numbers when you know people well for non work stuff.
Everyone else I meet, the assumption is to exchange phone number and use WhatsApp - exceptions would be iMessage or Signal sometimes. Or email or Twitter in business circumstances.
However, the current wave of phone-number-tied messengers (WhatsApp, Signal) have definitely pushed me in that direction.
They have a desktop client, but it's just a weird thing that proxies through my phone in a sort of bizarre backwards self-hosting sort of way.
How does it help security?
You can use discord on multiple devices at the same time without the devices needing to directly sync with each other (because the state is stored on the server).
FYI there is a permission to disable this for a channel
I understand that Signal wants to be blame it all on users, but the practical consequence of their design is that the moment people want to talk to a single person on Whatsapp, they give out Signal contact list to Facebook.. and the moment they start using Google's backup, they give out Signal contact list to Google.. and if they ever buy a new phone, they share Signal contact list with whoever wrote migration tool for their data. And there are tons of other random apps which all require contact list access...
From the privacy standpoint, Signal having contact list would be better. At least then, I'd have a single party to worry about, instead of dozens.
And, that software regularly re-sends that encrypted list to Signal's servers' SGX enclaves for their contact-discovery protocol.
So whether or not Signal, or some entity near/around it, "has" the contact list is a matter of how much users trust Intel™ SGX® (as well as the chain of processes that deliver/update the Signal software on-device.)
What they're moving towards is a design that looks like what Apple did with their HSM quorum system. The contact information we're talking about is encrypted clientside, but with (usually) a memorable pin. Without countermeasures, memorable PINs are very easy to attack; SGX allows them to artificially limit guesses. As a user, you retain a security dial on this: you can use a more complicated passcode than a 4-digit pin if you don't trust SGX.
Obtaining the whole database Signal maintains gives you ciphertext that you need to mount attacks on user-by-user (and to make those attacks, you'd have to break SGX). It doesn't simply give you the plaintext SQL database other messaging systems collect.
AFAIK, it prompts at first, maybe a few times, but then stops.
> Signal's software-on-device definitely has the contact list
Definitely not required at all. Signal can use its own contact list.
> that software regularly re-sends that encrypted list to Signal's servers' SGX enclaves for their contact-discovery protocol
The SGX enclaves are not for contact discovery. Contact discovery worked long before Signal implemented the SGX enclaves.
As I understand it: The SGX enclaves store a crypto key that Signal adds to the user's password, to enable data migration: Users tend to choose weak passwords; if Signal truly wants their data to be secure, strong passwords aren't realistic. Their solution is ingenious (IMHO): 1) Append a random key to strengthen the password chosen by the user. 2) A locally stored key would be a big problem for data migration, such as lost phones; the key would be lost too, and thus all the user data. 3) Therefore, they store the key centrally, as securely as possible (in the SGX enclave). That does make the key more vulnerable, but if you choose a strong password then it's irrelevant - the attacker needs to defeat both the key and your password. You can also disable this backup feature if you like. Some reading (partly because I might misremember a detail or two):
https://signal.org/blog/secure-value-recovery/
https://blog.cryptographyengineering.com/2020/07/10/a-few-th...
I am not sure how Signal backups work or that user contacts, encrypted, are backed up to the SGX enclave. Where does it say that?
> So whether or not Signal, or some entity near/around it, "has" the contact list is a matter of how much users trust Intel™ SGX® (as well as the chain of processes that deliver/update the Signal software on-device.)
Again, if you choose a strong password then you only need to trust yourself, and I think you can disable it altogether.
It's been re-prompting me for years. If there's a time it stops, I haven't found it.
> I am not sure how Signal backups work or that user contacts, encrypted, are backed up to the SGX enclave. Where does it say that?
You're talking about backups. I'm talking about contact-discovery, wherein the client regularly sends (hashed versions of) all the phone numbers from your contacts (if you've shared them with the app) to Signal's servers, to let you (& them!) know you're both on Signal. How else would you think the notification you get when someone in your contact list joins Signal is generated?
Signal's claim that these oft-repeated intersection operations leave no permanent records on their servers seemed (last I looked deeply) based on the SGX attestation: that your list is encrypted such that only the trusted code will process it. If Signal, or hackers, or Intel Corp, or the "Intel Community" can compromise SGX's guarantees, they can decrypt & log the full set of phone numbers uploaded.
So again, it reduces to how much you trust Intel™ SGX®.
(Also note that even if you do trust SGX, someone you've never met can, by having your phone number in their contacts, receive a notification when you join Signal. And separately from any SGX-mediated threats, a persistent attacker with privileged views of your devices' network traffic – such as via an ISP or mobile carrier – can get, via the volume & timing of traffic to and from Signal's servers, a pretty good idea of who you're talking to.)
> I'm talking about contact-discovery, wherein the client regularly sends (hashed versions of) all the phone numbers from your contacts (if you've shared them with the app) to Signal's servers
If they are hashed, why do you need to trust anyone?
Note it relies on SGX for privacy. (Anything they did earlier may have involved even more trust of Signal Inc's servers.)
Hashes across the (tiny!) space of all phone numbers are easy to reverse via brute-force.
But also, again: how do you think Signal is able to notify you when any phone number in your contacts – even if you're not in theirs! – first joins Signal?
I think novok is right in their uncle comment -- the decision to force people to use phone numbers, with all the related privacy problems, was to increase adoption. And we should be upfront on it: "Yes, Signal could have made things more private if they would allow usernames/emails/UINs... but instead they decided to force phone numbers to get market share as fast as possible. Yes, this means millions of people are forced to share the Signal contact list with Facebook and Google, but it was worth it -- look we have 40 million users now!"
There is nothing wrong with reducing user's privacy in order to get more market share. But let's not claim that this was for users' benefits.
You have to remember, signal is about E2EE security for EVERYONE, not just nerds. There will imperfect solutions along that path, which also means things like no federation. Signal is very much about being effective vs about being 'right' and ineffective, because when you are king, you can start being right and effective.
Signal can operate using its own contact list, without accessing your phone's central contacts.
Next time when Facebook pulls something user-hostile (e.g. monetization with ads, yet another privacy policy change for the worse, ...) some people will simply install Signal. If they use phone numbers as (an) identifier, two people who do this independently can immediately switch to Signal.
If A convinces B to switch, and C convinces D to switch, B and D can now talk to each other, reducing the pressure to keep WhatsApp as more and more of your friends are reachable on Signal. Even if you're using WhatsApp in addition to Signal, with phone numbers as identifiers, you're no longer contributing to the network effect that makes it painful for your friends to switch from WhatsApp to Signal.
Given that network effect is what makes or breaks messengers, phone numbers as the primary identifier are the only reasonable choice.
In my opinion with or without FB putting anything more hostile people are moving, in drones, to Telegram. I see regular people (non-tecchies at all) in my friends' circle joining Telegram regularly.
I'm not saying TG is better than Signal but I think TG's userbase is many orders of magnitude bigger than Signal's.
As an aside, the idiom is "in droves".
In Switzerland for example Threema is popular. In many countries you still can't really exist without Whatsapp. In China, Wechat. In Taiwan I believe you use Line if you want to have any friends (or reach businesses). In the US, iMessage with a fallback to SMS is popular, while it's rare in Europe because the SMS fallback would bankrupt you due to per-SMS charges.
> They don't want phone numbers on the merits of phone numbers.
I thought they were pretty vocal about wanting to use phone numbers to save people from the pain and despair of having to enter their friends' usernames into Signal, a pure UI concern.
The server needs to store each pair of communicating parties if it wants to announce presence information like AIM did. But that's unnecessary for a phone-based messenger - everyone is always "present" at all times.
https://signal.org/blog/private-contact-discovery/
... Signal began by using the social graph that already lives on everyone’s phones: the address book. Rather than a centralized social graph owned by someone else, the address book is distributed and user-owned. Additionally, having the social graph already on the device means that the Signal service doesn’t need to store a copy of it. Any time someone installs or reinstalls Signal, their social graph is already available locally.
If a person has your number in the contacts then your username and phone number are automatically merged together even if you were conversing to that person using your username from your perspective. That’s such a safety nightmare.