It's about storing as little personal information as they can.
But no, I don't use Signal. I just think it's strange how some people can't seem to wrap their head around any of the rationale for this when it's the most transparent thing in the world. Do I like it? No, but it's ridiculous how some people pretend to be incapable of critical thinking in order to talk about how it's horrible. If something is actually horrible, being deliberately obtuse isn't needed.
Whatsapp has 2 billion users, and they are pretty open that they upload entire user's phonebooks to Facebook-owned servers. We know Facebook is not worried much about privacy, so I am pretty sure that this data can be subpoenaed, sold and so on. If you care about privacy, you probably want to install something else, like Signal.
But you know what happens if you cannot get all of your friends converted at once, so you keep Whatsapp around? It will keep sending your contact list changes to Facebook, just at it is designed to.
Let me repeat this: you worry about metadata, so you want to chat to a friend via Signal. But the moment you add them, this is reported to all other apps including Facebook's Whatsapp. And there is no way to opt out of it.
How can people not notice this? How can any company call themselves "privacy friendly" and do this stuff?
This isn't that hard.
There's just so so many places to get tripped up by keeping data rather than just routing bits and never storing them.
Just delete them manually then.
Update Discord.messages
Set Deleted=True
Where messageID='71d01110-e3d8-4673-9ba0-7bc676c5b6e6'
Deleted!There is no such thing as privacy on Discord.
I don't think they're totally off-base: I haven't used my phone contact list for personal contacts for most of the last decade. It's just a collection of work contacts that I don't trust enough to add anywhere I actually talk to people.
I'd say at least 95% of smart phone users in the UK use WhatsApp. I think that's probably true of the rest of Europe as well.
We had AIM and message boards pretty early, but no dedicated phone lines. By the time cell-phones became ubiquitous, we had cars and could just actually hang out. And by the time we all moved apart, voice chat services were good enough to just hop back to the old chat model.
Do you have multiple Discord servers or just one for all your friends?
Roughly how old are you and are you a student or in a job or something else? What country or region?
When you meet a new person you want to stay in contact with, how do you do so?
Do you use only Discord with friends or do you also add them on eg Facebook or Email or any other communication system?
In my world (employed, UK, middle aged) at work generally we use Slack (kinda like you’re using Discord in a way), shifting to phone numbers when you know people well for non work stuff.
Everyone else I meet, the assumption is to exchange phone number and use WhatsApp - exceptions would be iMessage or Signal sometimes. Or email or Twitter in business circumstances.
However, the current wave of phone-number-tied messengers (WhatsApp, Signal) have definitely pushed me in that direction.
They have a desktop client, but it's just a weird thing that proxies through my phone in a sort of bizarre backwards self-hosting sort of way.
How does it help security?
You can use discord on multiple devices at the same time without the devices needing to directly sync with each other (because the state is stored on the server).
FYI there is a permission to disable this for a channel
I understand that Signal wants to be blame it all on users, but the practical consequence of their design is that the moment people want to talk to a single person on Whatsapp, they give out Signal contact list to Facebook.. and the moment they start using Google's backup, they give out Signal contact list to Google.. and if they ever buy a new phone, they share Signal contact list with whoever wrote migration tool for their data. And there are tons of other random apps which all require contact list access...
From the privacy standpoint, Signal having contact list would be better. At least then, I'd have a single party to worry about, instead of dozens.
And, that software regularly re-sends that encrypted list to Signal's servers' SGX enclaves for their contact-discovery protocol.
So whether or not Signal, or some entity near/around it, "has" the contact list is a matter of how much users trust Intel™ SGX® (as well as the chain of processes that deliver/update the Signal software on-device.)
What they're moving towards is a design that looks like what Apple did with their HSM quorum system. The contact information we're talking about is encrypted clientside, but with (usually) a memorable pin. Without countermeasures, memorable PINs are very easy to attack; SGX allows them to artificially limit guesses. As a user, you retain a security dial on this: you can use a more complicated passcode than a 4-digit pin if you don't trust SGX.
Obtaining the whole database Signal maintains gives you ciphertext that you need to mount attacks on user-by-user (and to make those attacks, you'd have to break SGX). It doesn't simply give you the plaintext SQL database other messaging systems collect.
AFAIK, it prompts at first, maybe a few times, but then stops.
> Signal's software-on-device definitely has the contact list
Definitely not required at all. Signal can use its own contact list.
> that software regularly re-sends that encrypted list to Signal's servers' SGX enclaves for their contact-discovery protocol
The SGX enclaves are not for contact discovery. Contact discovery worked long before Signal implemented the SGX enclaves.
As I understand it: The SGX enclaves store a crypto key that Signal adds to the user's password, to enable data migration: Users tend to choose weak passwords; if Signal truly wants their data to be secure, strong passwords aren't realistic. Their solution is ingenious (IMHO): 1) Append a random key to strengthen the password chosen by the user. 2) A locally stored key would be a big problem for data migration, such as lost phones; the key would be lost too, and thus all the user data. 3) Therefore, they store the key centrally, as securely as possible (in the SGX enclave). That does make the key more vulnerable, but if you choose a strong password then it's irrelevant - the attacker needs to defeat both the key and your password. You can also disable this backup feature if you like. Some reading (partly because I might misremember a detail or two):
https://signal.org/blog/secure-value-recovery/
https://blog.cryptographyengineering.com/2020/07/10/a-few-th...
I am not sure how Signal backups work or that user contacts, encrypted, are backed up to the SGX enclave. Where does it say that?
> So whether or not Signal, or some entity near/around it, "has" the contact list is a matter of how much users trust Intel™ SGX® (as well as the chain of processes that deliver/update the Signal software on-device.)
Again, if you choose a strong password then you only need to trust yourself, and I think you can disable it altogether.
It's been re-prompting me for years. If there's a time it stops, I haven't found it.
> I am not sure how Signal backups work or that user contacts, encrypted, are backed up to the SGX enclave. Where does it say that?
You're talking about backups. I'm talking about contact-discovery, wherein the client regularly sends (hashed versions of) all the phone numbers from your contacts (if you've shared them with the app) to Signal's servers, to let you (& them!) know you're both on Signal. How else would you think the notification you get when someone in your contact list joins Signal is generated?
Signal's claim that these oft-repeated intersection operations leave no permanent records on their servers seemed (last I looked deeply) based on the SGX attestation: that your list is encrypted such that only the trusted code will process it. If Signal, or hackers, or Intel Corp, or the "Intel Community" can compromise SGX's guarantees, they can decrypt & log the full set of phone numbers uploaded.
So again, it reduces to how much you trust Intel™ SGX®.
(Also note that even if you do trust SGX, someone you've never met can, by having your phone number in their contacts, receive a notification when you join Signal. And separately from any SGX-mediated threats, a persistent attacker with privileged views of your devices' network traffic – such as via an ISP or mobile carrier – can get, via the volume & timing of traffic to and from Signal's servers, a pretty good idea of who you're talking to.)
> I'm talking about contact-discovery, wherein the client regularly sends (hashed versions of) all the phone numbers from your contacts (if you've shared them with the app) to Signal's servers
If they are hashed, why do you need to trust anyone?
Note it relies on SGX for privacy. (Anything they did earlier may have involved even more trust of Signal Inc's servers.)
Hashes across the (tiny!) space of all phone numbers are easy to reverse via brute-force.
But also, again: how do you think Signal is able to notify you when any phone number in your contacts – even if you're not in theirs! – first joins Signal?
I think novok is right in their uncle comment -- the decision to force people to use phone numbers, with all the related privacy problems, was to increase adoption. And we should be upfront on it: "Yes, Signal could have made things more private if they would allow usernames/emails/UINs... but instead they decided to force phone numbers to get market share as fast as possible. Yes, this means millions of people are forced to share the Signal contact list with Facebook and Google, but it was worth it -- look we have 40 million users now!"
There is nothing wrong with reducing user's privacy in order to get more market share. But let's not claim that this was for users' benefits.
You have to remember, signal is about E2EE security for EVERYONE, not just nerds. There will imperfect solutions along that path, which also means things like no federation. Signal is very much about being effective vs about being 'right' and ineffective, because when you are king, you can start being right and effective.
Signal can operate using its own contact list, without accessing your phone's central contacts.
Next time when Facebook pulls something user-hostile (e.g. monetization with ads, yet another privacy policy change for the worse, ...) some people will simply install Signal. If they use phone numbers as (an) identifier, two people who do this independently can immediately switch to Signal.
If A convinces B to switch, and C convinces D to switch, B and D can now talk to each other, reducing the pressure to keep WhatsApp as more and more of your friends are reachable on Signal. Even if you're using WhatsApp in addition to Signal, with phone numbers as identifiers, you're no longer contributing to the network effect that makes it painful for your friends to switch from WhatsApp to Signal.
Given that network effect is what makes or breaks messengers, phone numbers as the primary identifier are the only reasonable choice.
In my opinion with or without FB putting anything more hostile people are moving, in drones, to Telegram. I see regular people (non-tecchies at all) in my friends' circle joining Telegram regularly.
I'm not saying TG is better than Signal but I think TG's userbase is many orders of magnitude bigger than Signal's.
As an aside, the idiom is "in droves".
In Switzerland for example Threema is popular. In many countries you still can't really exist without Whatsapp. In China, Wechat. In Taiwan I believe you use Line if you want to have any friends (or reach businesses). In the US, iMessage with a fallback to SMS is popular, while it's rare in Europe because the SMS fallback would bankrupt you due to per-SMS charges.
> They don't want phone numbers on the merits of phone numbers.
I thought they were pretty vocal about wanting to use phone numbers to save people from the pain and despair of having to enter their friends' usernames into Signal, a pure UI concern.
The server needs to store each pair of communicating parties if it wants to announce presence information like AIM did. But that's unnecessary for a phone-based messenger - everyone is always "present" at all times.
https://signal.org/blog/private-contact-discovery/
... Signal began by using the social graph that already lives on everyone’s phones: the address book. Rather than a centralized social graph owned by someone else, the address book is distributed and user-owned. Additionally, having the social graph already on the device means that the Signal service doesn’t need to store a copy of it. Any time someone installs or reinstalls Signal, their social graph is already available locally.
;)