But I agree with you, asking for the phone number and telling me this app is secure is ridiculous. Let me register with something less intrusive, if I want to go the phone number way, then let me use that. Give me an option.
But I agree with you, asking for the phone number and telling me this app is secure is ridiculous. Let me register with something less intrusive, if I want to go the phone number way, then let me use that. Give me an option.
If I told my mom to install some app and we'd connect to each other using some random IDs, we'd probably still be using SMS.
Can someone explain how this is possible? How does my phone know when to notify me that a friend has joined signal?
Edit: apparently it's "private contact discovery", I need to give this a proper read later.
This is surprising to me, since it was my mother's generation that got me into Skype (where you have to manually add the other person by their username), almost twenty years ago.
(Even worse, not long before that you had to manually punch the other person's "ID" into the device every time you wanted to talk to them!)
Can you trust your information stored at your messaging app's servers stay secure forever? Can you trust that company to never get compromised? So yeh, they go through all the hassle of making things "secure" but attach everything to something(phone number) most of us can't get without revealing our actual details. So yeh, its ridiculous to go through all this hassle to make things private and secure, but force people to use something that de-anonymizes everything about them.
I don't write anything that would be interesting to the NSA, I'm not a target for them, so I don't care if they see I use Signal.
BTW, say you have an anonymous Telegram username, I'm pretty sure it's trivial to find your name from the content of your messages. Or just from the metadata.
Security and privacy are not the same thing.
Among many other differences: security is a binary (can an attacker gain access to information) but privacy is a spectrum (what kinds of information do I want to leak).
Only if you're looking through a very narrow lens.
There are a range of potential attackers out there with different motivations and resources available to them. The question you have to ask (for each attacker) is whether the value of the thing you are trying to secure is worth more to them than the cost it would take them to break your security.
In aggregate, that looks a lot like a spectrum of security, with different people being secure against more or fewer different attackers.
Maybe you're saying that some information is more sensitive than others, which is true, but some security failures are worse than others (e.g. denial of service vs. remote code execution, or ability to forge messages vs. ability to decrypt messages).