Removing SMS support from Signal Android (soon)
signal.org
signal.org
As an android user myself, I much prefer having SMS built in because I use the search feature often to look back through all my SMS/Signal chats. I also regularly forward an SMS message to a Signal user, or vice versa. I'm already starting to feel like those iOS users who told me "I don't want another app"...
Signal seems to be trying to move further and further from "my preferred way to chat with people" and closer to the chat equivalent of "that protonmail account I only log in to when I need secrecy".
I obviously love having security on messages in transit, but I also like being able to keep my message history around and search my conversations for something that happened a year ago. It seems like Signal is on a trajectory to turn everything into disappearing messages. Are they the "safe for activists" communication app, or the "let's try to make as many as possible safer by default" app? Feels like they don't know.
And on top of it all the messaging is just frustrating. "we've taken away an incredibly useful and heavily used feature so we have development resource to better implement shitcoins and such" is such an irritating defense of the decision that I disabled my monthly donation.
Does anyone have recommendations for a good default SMS app on Android?
These are reasonable issues and concerns, so I don't follow why you would question all of the other decisions they make.
They could just show the literal word "SMS" in the send button.
I think that would be more obvious than wha they do now (button being grey instead of blue with a minimally changed lock symbol [1]).
[1]: https://support.signal.org/hc/en-us/articles/360007318911#an...
I guess that's just a pipe dream though.
rcs support works well, the emoji reactions are good. the web ui for it is pretty alright. I use the quick responses and scheduled send from time to time. and it cleans up my 2fa codes automatically.
Also, it now sends emoji reactions over sms which is a nice little graceful degredation from sms.
Really convenient to be able to respond to texts without having to take out my phone.
https://www.androidpolice.com/2020/10/29/it-looks-like-pulse...
QKsms is open source but abandoned more than a year, so I guess Simple SMS at Fdroid should be ok, it's from the guy behind Simple Gallery
Personally like TextraSMS. Has a free ad-supported version, but I paid to remove ads when it was on sale several years ago (maybe $1).
4.4 stars. I believe it's $3 or $5 to remove ads now.
https://play.google.com/store/apps/details?id=com.textra
Also surprised me the other day when a friend used an iOS reaction, and it applied it correctly on my end.
> Added support for Reactions (also known as Tapbacks) received from iOS Apple devices.
https://play.google.com/store/apps/details?id=com.microsoft....
I've used other tools in the Simple suite and I love them.
Although I like using F-Droid, this app is also available on the regular Play Store as well.
Do I? Not being snarky here, I just really don't understand why I need WhatsApp.
No one I know uses WhatsApp to communicate with me. No business I deal with uses WhatsApp to communicate with me.
In fact, I'm not sure what value WhatsApp provides as I've never used it.
I'd appreciate it if you'd elucidate on your point. Mostly because if you're correct, I'm obviously missing something extremely important.
Almost everyone I message with defaults to WhatsApp, or even insists on it. A few also have Signal or Facebook Messenger or iMessage.
SMS is only for notifications and such. Even some businesses default to WhatsApp.
There was just an article that said that 88% of teens have an iPhone. That means that almost all of their communication is encrypted.
I mean in context of signal we don't just talk about some form of transport encryption but e2e
I'm mainly concerned about SMS spoofing and mass surveillance. iMessage protects against that. The only way the government can read your messages is by serving Apple with a warrant to obtain your iCloud backup.
If I had a lower risk tolerance, I would disable iCloud backups to improve my security.
I would argue that if you are relevant enough apple and sms are both equally easy to get for them.
If we talk here about signal, I don't think the alternative should be iMessage but telegram etc.
In terms of encrypted messaging, the popularity in my friend group is:
1. iMessage
2. Signal
3. WhatsApp (only for talking to non-US people)
4. Matrix
Meanwhile if my counterparty and I have communications in Signal that we want to preserve at scale, it's impossible to do so. A simple example would be that I have years' worth of conversations with my wife that I can't easily back up any where. We could export every picture and video by hand and screenshot or copy the text of every message, but that would be extremely time-consuming and tedious.
That's the basic problem. The data is already only semi-secure in that it's subject to exfiltration without consent. It's just inconvenient. And where parties do consent, it's very inconvenient because it's many many hours of work; in the end, it's just more security theater.
This is one of the problems with Signal having a bit of confusion about what exactly it's use-case is. There are plenty of cases where locking down the ability to save/view/export messages are valuable, and Signal provides tools to be able to do that. Making that the mandatory case though means that it's harder to adopt as a general-purpose communication platform.
The need to decide if the goal is still to get as many people off of SMS/facebook-messenger as possible, or if the goal is to provide extreme security to dissidents and protestors, or if they're going to spend the effort to be able to do both effectively and let you choose which conversations or messages get which level of protection.
It's like when Signal asks you to put in your PIN, but it's the same PIN you use to unlock your phone. There's a different Signal PIN, but that functions as a check for when you install Signal on a new device. Your regular PIN is just a repeat of your phone PIN, and thus adds exactly zero security.
I do like Signal and I think they have done a lot of good. I do think they have a lot of valid criticism against them but also I think a lot of people aren't providing useful criticism (it is a shame that's happening here, on a forum that should be filled with tech experts). People also aren't realistic. A 25 person team working at a non-profit aren't going to have the same development capacity as a 250 person team.
[0] (maybe go to the bottom) https://community.signalusers.org/t/usernames-in-signal/9157
These are purely my observations of the discourse around Signal and should not be taken as a universal truth. Only my subjective reality.
I'm not aware of any major vulnerabilities in Matrix (but I'm not following) closely. I'm also not aware of any in Signal, which I know is frequently audited. There is an SGX attack, but it is often blown out of proportion (highly technical attack that requires an unlocked phone to be in the physical hands of the attacker).
Telegram gets a lot of shit because they prop themselves up as a privacy app but aren't. The default is that things are not encrypted. They use a proprietary encryption scheme. They store user data on their servers. These are not the marks of a privacy app.
I explained how imo Signal has burned the goodwill of a some of its early adopters. Meaning not recommending it to my friends and buying my mom an iPhone. Now there's an argument to be made that it's not very smart to dismiss the app, but that's what happened.
I'd be very surprised if they manage to salvage its image at this point
To be clear, Signal allows you to backup and restore back into Signal on android, which is great. What I meant is that it would be helpful to be able to export that content out of signal and keep an accessible searchable archive off of the device.
> but instead the Signal backup just keeps getting larger and larger...
One begets the other.
> I'd love to be able to move it off the device
If you don't want infinite history, set a conversation length limit. It is in the storage settings.
If you want to backup messages on iOS go complain here[0]. For Android, you already have this ability.
[0]https://community.signalusers.org/t/ios-backup-keeping-messa...
My ideal solution would be to export any message older than a month to an archive on my NAS, ideally in a format that the app could search on request. Keep my history, keep the on-device space nice and small.
I take advantage of the Android backup feature, and the backup syncs over to my NAS via SyncThing automatically, but that's only useful for restoring a brand new phone up to the latest state.
I'm confused at what is stopping you from doing this?
> ideally in a format that the app could search on request.
Are you not able to import these backups into the desktop client? IIRC it is just reading from a file structure. I don't see why a small script couldn't resolve this. Obviously you wouldn't be able to search on your phone, but you said you didn't want that data on your phone anyways. If you did want to search on your phone from your computer's storage, I think you're asking way too much of them (and in danger of asking them to store data for you, which they never will do). But this is hacker news, and I don't see why you can't hack together that tool in a weekend. Probably just a few beers on a Friday is enough for it tbh.
As far as I know the backup is encrypted.
> Are you not able to import these backups into the desktop client?
No, the desktop client is not standalone, and ONLY syncs with the a phone to get content. Moreover, if you don't use the client for a period (2-3 weeks in my experience?) it de-syncs that desktop client. Re-connecting that desktop to your phone will only sync messages starting as-of the connection, so there's no way to get the desktop app to pull your whole history. (This is another gripe I have about their sacrifice of actual usability for security that only helps a few very specific use-cases.)
You're probably rigth about hacking something together. Someone has created a library [0] allegedly for decoding the backup files. Friday night is D&D night though, so I haven't had the chance. :-)
I agree that there aren't really any great solutions. But the alternative is that Signal stores your data. I think this would make a lot of users very upset and compromise part of Signal's core mission.
This is one area where, and I know what you're going to say, but Matrix actually does really well. My data, on my server, in my house, not tied to any specific single device I own but distributed across several and backed up in an encrypted manner.
But you've got me thinking about the data export option. Saturday is coming. Hmm...
I'm actually a fan of Matrix. I just see Matrix and Signal as different tools. You're probably aware of it, but if not, there is a Matrix bridge for Signal.
> But you've got me thinking about the data export option. Saturday is coming. Hmm...
Hey, I'm really hoping it works. Let me know how it goes!
'I'd take a decent "export my chats" option' is a very simple statement. There is no way within Signal to just export a whole conversation to a file.
You can on Android and Desktop. On Mac see ~/Library/Application\ Support/Signal for your data. The only issue is with iOS which I agree is an issue, but does not seem to be the parent's issue.
That's why I wrote 'within Signal.'
As a simple example of how this could get messy, suppose I wanted to back up all my Signal messages, install a different operating system, install Signal there, and load up my old messages. I do have the IT skills to just find the database file and move it manually, but I'm only confident about that because I know its an SQLite database, where the keys are stored etc.
It's still an IT problem I would prefer not to have, vs the simple option of 'Do you want to export this conversation, with all the security implications Y/N' or 'Import this previously archived conversation?'
If this "accessible searchable archive" is stored "off of the device", how exactly would the device access and search the archive? Facebook can store your Facebook Chat history on their servers no problem, but E2E encryption makes this much more complicated for Signal!
It's not impossible, Apple does it with iMessage, although that was actually a pretty recent addition despite all of Apple's resources!
Exactly. I'm saying you can't have both low storage and full chat history. These two cannot work without a storage server. I have suggested a method of using the desktop client as the storage server but I agree that there is no great solution.
> It's not impossible, Apple does it with iMessage
That does come with significant tradeoffs though. Now we have to trust Apple that they haven't taken our keys and that they still aren't handing over this data. It is a tricky situation.
Because the in-app option to clear them all does not free the space.
Your only way of saving things is to either manually save every picture and video, or manually highlight and copy the text in your conversations. The latter defeats any security arguments (other than of inconvenience) but also throws away useful information like timestamps of messages.
My Signal database takes up many GB on my phone, and it's constantly complaining about running out of space. Much of this is the years-long record of conversations with my wife. I'd like to back these up, but I can't. Are you gonna tell me that I shouldn't be using a secure messaging app to communicate with my own family members?
Not “delete all my chats/delete an entire thread.”
Settings > Data and storage > Manage storage > Keep messages
then choose from the listed options
Those two groups of contacts then got mixed making it much harder to see who's on Signal and who isn't.
Back then I thought that was deliberate. It would be surprising to me, if the desire to avoid that self-inflicted confusion would have contributed to the decision to discontinue SMS support.
I couldn't care less about this.
I can't understand who and why anyone cares about SMS these day, besides receiving government emergency notifications.
Regardless of that, you can still always receive SMS for the 3 outdated services that still use it.
(As my friend used to ironically say: "Is your grandma so senile that she can't type `configure; make; make install`?")
I don't even open the SMS program if I get a code. I type it from the notification area. I certainly don't have to answer to it.
That's not true at all. I assume that besides Signal you use WhatsApp, though?
And yes, WhatsApp is prevalent here.
I merely describe the current status in Germany.
I've onboarded friends and family, too, ensuring them it should be set as their default messaging app and that it _just works_. Unfortunately, people in the general population seem to have pretty much zero tolerance for any friction whatsoever. If they have to use 2 apps, they'll just end up communicating with me in the clear using their "default SMS" app on their phone. That's what this is going to result it...a reduction in overall message security due to people defaulting to what's easier...which is to _not_ have to remember which app to use for which "send a message" purpose. Fuck.
I understand the argument about people in markets where SMS is expensive getting screwed sometimes when they don't realize they're sending a message over SMS. However could that not be fairly trivially solved for with some UI notification or app setting that warns you about this and allows the warning to be perm-disabled if the user doesn't care!?
I think the real reason here is this desire to transition the service into supporting usernames, which is a topic that's been discussed before (and is explicitly mentioned in the post). Right now the service is tied to your phone number. After this change I suspect it will not be or not need to be.
This is very, very unfortunate for those of us who've convinced a ton of non-technical friends and family to use TextSecure->Signal over the years...
However, if "dropping support for SMS messaging also frees up our capacity to build new features (yes, like usernames)", I think it is something I would not miss.
Besides, I agree with them on the point that SMS leak metadata.
SMS does leak metadata but guess what, that leakage is going to continue because people aren't going to just cut off their SMS-only-using friends and relatives. Now they'll be leaking Metadata from an even less secure app, so the user is in no way better off.
Exactly right. In fact, I will be doing this too. Right now, I use Signal as my default messaging app, and messages go via Signal to people who've registered their phone number with Signal without me having to do anything to effect that. When Signal stops working as an SMS client, I'm not going to look up which of my contacts wants to use Signal and which can only use SMS - I'm just going to use my default SMS app for everything except the couple of group chats which are on Signal already. Messages which would have been opportunistically encrypted are now going to go out plaintext, because the friction to find out who uses Signal and who doesn't is too high.
This already happens with iOS, because the Signal app doesn't work as a default SMS client. People who use Signal and Android reliably send me messages over Signal, whereas my contacts who use Signal and iOS mostly send messages over SMS unless they're directly replying to something I've sent them over Signal.
And even if I wanted to do the work to send everything over Signal to those contacts, how am I supposed to remember exactly which of my kid's friend's parents use Signal and which don't? Fuck it, the juice isn't worth the squeeze, everything is going over SMS.
I'll just have to hope that Google figures out a way integrate a seamless, opportunistic end-to-end encryption protocol into the default Android messaging client, since Signal is deliberately dropping the ball here.
Gutted. I will end up switching to a different provider. Absolutely don't know if I'll be able to convince family and friends to switch again.
I don't really see Signal as a useful tool for my uses after this change. I liked the SMS and encrypted messages in one place thing even though some friends rarely check it. For those friends I send SMS through Signal. There are certainly issues with group chats and media but nothing bad enough to consider using two apps. Now I have to look for a new tool, and figure out what to do with certain archive conversations I'd like to retain.
>Now we will get neither
Correct me if I'm wrong, but:
- If you and your counterparty are both using Signal, nothing about the security of your communication changes.
- If your counterparty was not using Signal, your messages were over SMS/MMS and therefore not encrypted in the first place, and so once again, nothing about the security of your communication changes.
Are you seeing something I'm not?
I have (iOS-using) friends I have convinced to register their numbers with Signal...but they never check Signal. They do check SMS.
This actually drove me away from using Signal for SMS on Android, because I couldn't send those friends SMS messages through Signal. They could only go out as Signal messages, and my friends never checked them.
Fortunately, I only have a handful of friends in this category, and virtually everyone else I talk to does use and check Signal, but it's a usability problem both ways.
This is what Google's RCS implementation is, to my understanding.
Although the end-to-end bit might be a bit on the squishy "kinda-maybe-sorta" side, rather than Signal's enforcing of it.
There's an overwhelming mountain of evidence that says that ends poorly.
As far as instant messaging services are concerned, I have let go my earthly tether; entered the void; empty and become wind.
This is actually a complaint of mine. I've regularly had Signal send secure messages to people who have tried Signal in the past, but have since uninstalled the app (or in iOS's case, they 'offload' apps when you don't use them frequently which silences notifications). This results in me thinking my messages are sent only to find out that they'll never read them. I then get frustrated and have to go back and re-send the message via SMS.
Here's how I've convinced my iPhone friends. I tell them if they actually want to send pictures and videos to me that aren't potato quality they can either switch to an Android, email me, or use Signal. At this point Signal is more like a cross platform iMessage. This tends to move people over because Apple's walled garden makes group chats infeasible with mixed devices.
We don't seem to have this problem so bad in the UK/Europe. Most people I know have WhatsApp and/or Telegram, and FB messenger, and Signal (in my friend circles); all alongside SMS. I have very few iMessage groups, and use it mostly for 1to1 SMS with people I don't know well.
(The only reason I use signal is to talk to my girlfriend. The only reason we use it is early in our relationship I was going through a phase where I adopted annoying privacy tools. I wanted to abandon it, but after years of using it she's developed positive emotional associations between our relationship and signal, so for non-technical reasons she likes to keep using it just to talk to me)
It took me a long time to find this comment. The number of SMS messages I never received was ridiculous. I still use the app all the time, but would never use the integrated SMS messages ever again.
Their underlying reasoning is correct. SMS sucks, really really bad. They're a secure communications channel. People see signal and think they're secure. Signal has no business supporting SMS. The on boarding has reached critical mass, the neyworke effect is here. If you're smart you'll abandon SMS altogether forever and just tell people to reach you some other way, not ditch the actual, over the internet encrypted channel.
My elderly mother pushes one button to text me and everyone else anything else is a show stopper, End of story.
The people you want to send you SMS like companies that need your phone number can't do SMS, and the ones you'd rather message you elsewhere sometimes insist on SMS. It's annoying.
They will no doubt stop checking their signal messages from me same as iPhone users often do and I will have to change to insecure messages for all my messaging.
This will break their trust in my recommendation, as much as it will break my trust in signal.
I get the reasoning over this, but I think they fail to realise that interoperability is the most important feature. I will have to stop donating to signal over this change, it will be useless to me...
I'm dreading the day where I lose or break my iPhone and thus lose my Signal chat history. I've been using Signal for years, but this makes me still prefer other messengers when starting new chats, even if Telegram (for example) is not e2e encrypted.
(Unfortunately, I've long overcome the "I don't want another app" thing and just installed all the messaging apps. Although I kind of want to look into setting up Matrix bridges and merging everything into Element.)
I hope it's communicated well to users who aren't readers of Signal's blog. I have relatives who use Signal, and they rely on its fallback-to-SMS feature, possibly without fully understanding it. I'll make sure they understand and are aware of this change, but others may be in the same position.
https://community.signalusers.org/t/dont-want-pin-dont-want-...
Even when security concerns were brought up:
https://community.signalusers.org/t/proper-secure-value-secu...
Because Whatsapp and Signal are walled gardens. (Everyone knows why IM>sms)
Until next year?
https://www.europarl.europa.eu/news/en/press-room/20220701IP...
"... those designated as gatekeepers will have to: allow third parties to inter-operate with their own services, meaning that smaller platforms will be able to request that dominant messaging platforms enable their users to exchange messages, send voice messages or files across messaging apps. ..."
(I admit that I actually edited that original comment, since the link I initially included was more speculative, talking about a law that was expected to pass, and being much more vague about when it might enter into force. The page at the updated link is more definitive, but not as narrowly focused, so I'm glad you managed to isolate the relevant section.)
This is why we need at least open source clients that can be forked when these decisions are made.
Taking that factor away - allowing people to mess it up - makes it easier for developers.
Rock solid and both works and looks great right out of the box. So customizable that using literally anything else feels like using a Fisher-Price computer for toddlers.
Windowing rules for one. Simple example: Firefox picture-in-picture. On KDE I have a windowing rule so that if from any firefox window playing video I hit the picture-in-picture button the picture-in-picture window becomes a certain size, goes to a certain placement on my monitors, stays on top of all windows, and is visible across all virtual desktops.
Ability to control the layout of my virtual desktops is also incredibly useful to me. (I use a 3x3 grid, so switching from my "main" task in the center to any one of 4 sub-tasks up-down-left-right is easy, and my universal tasks (chat/email/etc) go in the 4 corners.
KDE puts you in control, and gives you a LOT of control. IMO GNOME feels much more windows/mac in it's design philosophy. "We know best, do it the way we let you."
And as far as an API, yes, also that. With the Plasma desktop plugin Firefox remembers which virtual desktop each window is supposed to go to, so I have no issue rebooting with 5 or 6 different windows open.
I apologize if it sounds over the top, but for my use-cases at least the level of control and "just does the right thing" really do stand out above the alternatives.
I am very intentional and active when it comes to what has push notification privileges. I factor that into my app use consideration. I have multiple email accounts in two different email apps, each that send me notifications. I have Signal, Discord, iMessages and SMS. I have a few Google chat apps. I used to have WhatsApp and Wickr and Telegram. I have Skype, Teams, and two Mattermost servers.
It’s exhausting to constantly switch between these, so over the course of a few years I’ve been very clear in where people can expect to reach me reliably. If you need or want to chat with me on Discord, Skype, or Google whatever you need to send me an iMessage, SMS, Mattermost, or Signal message. Sending me a message anywhere else will get you a response only the next time I open that app. That only happens when someone specifically asks.
I’m OK with having 63847394038 chat and video calling apps, but I’m not OK with being instantaneously notified by an infinity such apps. I can’t be that available.
It also puts a spot-light on the "your phone number is your username" policy. This made perfect sense when you are using Signal for opportunistic encryption of texting. It is much less justifiable when using it as a Silo'd app. I really hope they change that and give people who were waiting for that change time to join before killing SMS support.
That’s a major boost for those that might not particularly care about encryption to look for specific messaging apps, while still helping by building out the network slowly over time.
This became much more of a problem for me after they rolled out their shitcoin; suddenly my techie friends were just not responding to messages, and Signal as my main SMS app was not falling back to SMS for these folks.
I’ve only done the switch from iOS to Android once and I remember it was a pain for a few days until everything realized I didn’t have iMessage anymore.
The user cannot just log out of Signal and have the app on other people's devices automatically fall back on SMS the way it works with iMessage?
Logging out might not even be enough, depending on the logic on Signal’s side. Do they use active devices, or just that an account exists?
For two weeks, messages will be shown as sent but not delivered, and after two weeks Signal will not let you send messages to that number until it reconnects to the Signal servers.
For comparison, Apple automatically sends all SMS messages via iMessage opportunistically, and if the user then switches to another phone, all SMS messages from iOS users will be silently discarded in perpetuity. This is a big problem because the recipient has no idea that they're missing messages, and also if they no longer have access to an iPhone, there's no way for them to deregister their phone number from iMessage.
https://selfsolve.apple.com/deregister-imessage/
They will also deregister you automatically after some period of time. What you described is the situation several years ago, but it's much better now.
In that case, Signal's current behavior would be comparable to Apple's, if Apple also deregisters you after a period of inactivity.
I'm willing to bet that this decision is just jumping the gun by a month or two since usernames are around the corner (code exists, just not enabled. Can be used if built from source).
Though I haven't had a hard time converting (Android) users by using another app. Especially people that already use WA. The "other app" just comes off as normal. Apple is a different ball game because the walled garden, but that's also the weakness because you can't send photos/videos in group chats with mixed devices (but Signal can).
But I actually like this decision. It makes things less confusing and accidental use of unsecure SMS impossible. The downside is if you still use SMS you have to keep 2 apps, back them up separately, etc.
> "Why do I need 3 apps (Android Messages, Signal, Whatsapp)"
"You need Signal to talk to people on Signal, WhatsApp to talk to people on WhatsApp, and Messages to talk to people on SMS." Seems more straightforward than "use WhatsApp to talk to people on WhatsApp and Signal to talk to people on Signal or SMS; just pay attention to the color of the send button".
I feel like I'm not leaving Signal; Signal is leaving me.
I don't know anybody else who uses Silence so I could exchange encrypted messages with them.
Oh well. Maybe somebody here could resurrect this?
I learned to stop trying to improve the technical lives of other people after Dropbox's decision to restrict free accounts to three devices resulted in a shitstorm of angry and confused messages from half the people I know.
But I have to admit your perspective calls to me. I can imagine it would feel quite freeing.
I’m in a minor mess of a situation with my dad’s phone and computer because I’ve tried to be helpful. Now he resists help and that makes both of us frustrated.
I had recommended signal to others, but thankfully I've already warned those same people against continuing to use Signal years ago. Nobody was mad at me for Signal's actions and changing your default SMS app isn't hard anyway.
I don't think you have to stop recommending things to people just because situations change. Hasn't everybody had some service or software they depended on go from great to shitty? It's just the nature of using someone else's stuff. At some point they get greedy or busy or decide to pivot into something different from what you want and you have to find something new. Isn't everyone used to that? Why would they blame you?
>This is an unofficial, FOSS-friendly fork of the original Telegram App for Android.
Anyway, there is no need to worrying, MOSSAD watch as all.
Messages that I would have sent via SMS currently will automatically get sent via Signal if the person I'm sending to has started using Signal without my knowledge. This has happened in several instances where I was pleasantly surprised to see a friend had started using Signal. Now that I'm forced into a separate SMS app, this will no longer be a possibility. I certainly won't be firing up Signal to see if a contact has joined before sending them an SMS.
Apart from that, your use case has another possible issue. If a person stops using Signal, your messages will go to the void until Signal actually removes the user and your client switches back to SMS. This has caused a lot of confusion for some of my friends when I switched my signal account to a different phone number.
I think it's more reliable to use Signal for Signal.
Bingo.
My launcher (Niagara) does that already to display notifications in popups connected to app icons.
Notification processing is one of Android's greatest features over iOS.
Anyway a normal person already uses multiple messaging applications: WhatsApp, Telegram, Facebook Messanger, Instagram direct messages, the good old email, SMS (I guess somebody they are still used reading the comments), adding Signal it's not that big deal.
So when apps like viber, WhatsApp, etc came on the scene, people jumped on them quickly and completely stopped texting.
This was before they even had voice calling.
With voice calling, it is also popular, as you can call someone irrespective of what country they are in and not worry about roaming or international call charges (even though in the EU now we do not have roaming charges anymore).
Some people even use WhatsApp for normal calls over normal cellular calls!
Signal was always one of those "win-win" apps, get more security when it's available and I don't have to worry about adding to the giant bucket of messaging apps.
They were a paragon of putting the user first and I was a strong supporter... but now... Why not Telegram? Or anything else?
I don't need the security, it was nice-to-have. Having to switch between Signal and other apps is a heavy amount of friction.
Telegram is absolutely the worst when it comes to privacy, it has access to everything you do and say.
If you want a master app, have a lot at matrix.org with bridges.
In reality almost no one bothers with secret chats (no syncing between devices, no backup and no group chat possible). Instead everything is stored online without E2E encryption, i.e. perfectly readable for the service provider.
Sorry, but "everything" != "almost everything". So it's false that "Telegram has access to everything you do and say".
False, I use them.
Really? Telegram never said that they don't store your messages on cloud, they said that they do not sell your data or share it with third parties for profit.
Telegram has received a very good score on PrivacySpy (https://privacyspy.org), in fact better than any other messaging app. Telegram is good from a regular privacy perspective unless your threat model involves fearing cloud convenience.
Even FBI's leaked documents confirmed that Telegram does not ever share user data easily. [Source](https://www.securitynewspaper.com/2021/11/30/leaked-fbi-docu...)
If you're someone who requires spy-level opsec, you should be using Threema, Session or Speek. Maybe even a self-hosted XMPP instance.
Telegram is good at what it does and it states it very clearly. It does not lie about the things it does and it is open source. All while not selling user data, not manipulating user behavior through algorithms or censoring media by calculating hashes and providing what's arguably the most feature rich messaging app on the planet for free with a verifiable source code.
Also, be careful with what you're suggesting. Not only have Matrix servers been hacked twice but matrix also leaks metadata. If you're seriously suggesting true anonymity (not consenting privacy) then Matrix is not a good option.
Yes, really. You don't even argue against it.
> pp. Telegram is good from a regular privacy perspective unless your threat model involves fearing cloud convenience.
Telegram stores almost everything online without E2EE.
> Not only have Matrix servers been hacked twice but matrix also leaks metadata.
Even Signal leaks meta data.
> If you're seriously suggesting true anonymity (not consenting privacy) then Matrix is not a good option.
Out of Matrix, Telegram and Signal, Matrix is the best option. It is the only one not making you share your phone number giving you anonymity up to your IP address.
and yet I just did. Can we please stop confusing privacy and anonymity?
Your claims about Telegram being bad for privacy are baseless. Your concerns about messages is valid but it in no way compromises privacy because:
1. No telegram employee can read any messages. They use distributed key generation to encrypt data on servers which means no single server has access to decryption keys and all the servers are in different jurisdictions.
2. They do not sell message content data. If you can prove it, you can go ahead with a lawsuit and win a hefty sum.
3. They do not compromise security. They do not use E2EE by default. Their threat model and vision for a messaging platform is different than yours.
4. Telegram has never given message content for a court order. As mentioned in the privacy policy, they give out only the phone number and IP Address only in case of terrorism or child abuse and only when there's a court order from a country of a higher democratic index.
5. If you truly believe Telegram is bad for privacy even after all the evidence from FBI itself and PrivacySpy giving it a higher score than Signal, then please go ahead and sue them because surely they can't have a good privacy policy and bad privacy at the same time.
This is wrong. First, reported messages (via id) are read by employees. Second, regardless of your claims, Telegram can easily write a service which has access to plain text messages.
> 2. They do not sell message content data. If you can prove it, you can go ahead with a lawsuit and win a hefty sum.
How about you prove your claims? I hardly can bring them to justice when even the police doesn't have immediate access to them.
> 3. They do not compromise security. They do not use E2EE by default. Their threat model and vision for a messaging platform is different than yours.
Actually, they do by not using E2EE by default and providing bad encryption possiblities.
> 4. Telegram has never given message content for a court order. As mentioned in the privacy policy, they give out only the phone number and IP Address only in case of terrorism or child abuse and only when there's a court order from a country of a higher democratic index.
no idea about that
> 5. If you truly believe Telegram is bad for privacy even after all the evidence from FBI itself and PrivacySpy giving it a higher score than Signal, then please go ahead and sue them because surely they can't have a good privacy policy and bad privacy at the same time.
Since when is "bad for privacy" a reason for suing? The quality of a privacy policy doesn't have anything to do with privacy itself btw.
> and yet I just did. Can we please stop confusing privacy and anonymity?
I didn't, did I? please explain
These are again baseless claims. If you think MTProto 2.0, an encryption algorithm that has been audited multiple times by independent researchers is 'bad encryption', I'd like for you to prove it. Obviously, if you can prove it's bad, you could let Telegram know and win a bounty.
> How about you prove your claims? I hardly can bring them to justice when even the police doesn't have immediate access to them.
The burden of proof is not me as I did not make any claims, I simply restated what's on the Telegram website.
Even the FBI, Iran or Russian government couldn't bribe them so I do trust Telegram to not backdown on their statement and philosophy about not selling or using userdata for profit. https://twitter.com/durov/status/912812889236475904
> Second, regardless of your claims, Telegram can easily write a service which has access to plain text messages.
You do know even Signal could add a keylogger service to read message content right? I don't suppose their Google Play Store version has reproducible builds. See how easily arguments like these break down? You can almost assume anything and claim almost anything. As I said, these are baseless claims and assumptions. I'm only interested in the objective truth at the moment, not assumptions or guesses.
> Since when is "bad for privacy" a reason for suing?
You're suggesting Telegram's privacy policy is in direct violation of their privacy practices which is illegal. This is a huge claim, if you can prove it you should sue them, I'd honestly do that if I were you.
> I didn't, did I? please explain
Privacy is about choosing what to share, not about sharing nothing. You seem to lie more on the anonymity side of the argument than privacy rights. You're fighting for anonymity, not privacy if you claim malicious intent on Telegram's part because as I showed earlier, their privacy practices and security are totally A OK.
Currently Matrix is operating in a way that larger instances aggregate private messages from bridges in plain text. Those messages would have stayed encrypted and secure if people didn't use Matrix.
That's not true in general. For most if not all messengers (at least encrypted ones), there is the option to use Bridge-to-End encryption on the Matrix side, which doesn't give the homeserver any possibility to inspect messages let alone aggregate them.
So if you run the home server somewhere untrusted, but the bridge in your home with E2EE enabled, the decryption AFAIK happens in the bridge, and the home server doesn't see anything.
But its definitely better than falling back to SMS and maybe better than having all chat apps installed.
(Even though I still think Element isn't good enough)
> Signal was always one of those "win-win" apps, get more security when it's available and I don't have to worry about adding to the giant bucket of messaging apps.
Same here. I see no reason to continue using Signal if they do this.
Now? Delta chat is looking plenty fine for doing private group chats.
My threat model is not nation states watching my metadata, I have horrible opsec for that. My threat model is discord and whatsapp etc. tossing me and my chat groups off a cliff at their sole discretion.
Signal gave me control over chat groups, and integrated with SMS as a bonus. Now? If I'm gonna have to deal with a separate SMS app anyways, I might as well use delta chat where I know my messages are automatically backed up in my email account.
If this were an in-depth announcement with a long and well-structured technical justification attached, I could understand. Though I suspect I'd likely disagree with the decision, I could probably accept it as a simple different of opinion if the arguments were evidently well-thought-through and considered.
This blog-post is so lightweight. There's no technical analysis. There's barely any justification. Yes we know SMS is insecure and yes - it seems plainly obvious that having them in the same UI could pose UX challenges & user confusion issues. So improve the UX and clarify the distinction. Did anyone in Signal consider the userbase or the advantages of this feature at all?
Definitely the end of my Signal usage anyway. It's my main SMS app: my primary motivator is SMS UX, the ability to securely message a tiny subset of my friends is a very nice but ultimately non-vital bonus. Having a separate app for those people isn't worth my while (they're on other platforms I use more).
The migration off it will be an unwelcome pain...
... confirmed by Signal in their discussion thread:
"... and Signal can’t add RCS support because there’s no RCS API on Android. Honestly, the days of any third-party SMS app are numbered."
I guess I misunderstood RCS. I thought the whole point of RCS was to be used on Android and to allow disparate third parties to use it as an open standard.
Where is the RCS API if not on Android ? Who is supposed to use RCS ?
Most people simply lack the technical basis to understand the security implications of sms. And for Signal to be a secure messaging system by default SMS needs to be removed.
Signal's primary feature is encrypted messaging. You don't get it without at least seeing the word "encrypted" somewhere.
My point is that all of this is orthogonal to whether Signal can successfully make UI show users when they are sending encrypted messages vs unencrypted SMS.
Most of the confusion you are citing is about whether an app does encryption or not, and that is a totally distinct problem domain.
Firstly, the messaging decision is presented to the user before an action (send SMS/Signal). It's capable of blocking and takes place as part of an active use flow where the user is trying to complete a task. With browsers, the differentiation in UI is displayed after a user action. It doesn't block and the user doesn't require interaction to achieve any goal. Why on earth should they pay any attention to it?
Secondly, the UX for messaging is an equivalent paths binary decision: you're asking people to choose A or B. There isn't an inherent default so a user doesn't start out with a bias toward one or the other. They can easily be required to read to proceed.
With browsers it's a yes/no binary decision: the default (yes) is insecure (for an insecure website). It requires no action from the user. The secure option (no, leave) asks the user to do something. It's a choice between inaction (insecure) or action (secure). That's heavily stacked.
Lastly, even the context surrounding the apps themselves is incomparably different. One is a security upgrade of an application everyone's been using for decades (often unknowingly; "the icon for the internet"). The other is an app people consciously download and install explicitly for security reasons (regardless of whether they understand those security reasons it's at least the motivating factor).
https://community.signalusers.org/t/signal-blog-removing-sms...
Wonder why the blog post omitted all of that and focused on nonsense instead?
Hopefully this even frees them to do things we've wanted for a long time... like not being tied to a phone number and offering better features than RCS/iMessage. Maybe even having multiple independent profiles/pseudonyms for compartmentalization.
That's how Signal could be growing the base and interop with SMS/MMS/RCS cruft on one platform will always lack the killer feature and be irrelevant to the other platforms. If Signal were better than SMS/RCS/iMessage people will just use it for those reasons in addition to the security and privacy.
And having just installed the beta and used the SMS export and allowed it to purge all of SMS content from Signal into Google Messages it actually sort of is nice that the app is now ONLY the "Signal" context. I'm... actually pretty okay with SMS belonging to the "Stuff that Creepy Companies Like Google Know" context.
Basically this just does what Signal already does in iOS: it must compete with the native messaging client. Google is already playing RCS as SMS upgrade and Signal is making the correct strategic decision to not make a play for RCS. SMS support is just going to lead to whining about lack of RCS. The bottom line is both Apple and Google are out to kill SMS. With SMS gone, Signal can just move on to feature parity with iMessage and beyond while leapfrogging whatever messaging clusterfuck Google keeps producing. Google can have SMS for all I care. We can't have iMessage on Android, but we can have Signal on both Android and iOS.
And fragment the market even more?
I found two top-level comments linking it, upvoting those might help:
I think this is the crux of it. Your primary motivator may be for a better SMS UX. But Signal's primary motivator is to provide universal secure messaging, but your typical use of Signal doesn't do that. So it's no surprise that their plans mismatch your expectations.
All centralised & protocol-locked messaging apps are subject to network effect. People moving away from Signal doesn't help the goal of universal secure messaging, regardless of whether those people are you or I.
That said, it seems they're between a rock & a hard place here since Google are defacto deprecating support for 3rd-party SMS apps.
Of course, they didn't bother make that argument.
And in the SMS domain Google Messages really does get annoying with the whole Google Messages vs iMessage and how nothing Google is doing with RCS benefits anyone except Google. As Google continues its war on SMS and force migration of everyone to RCS, Signal users on Android end up being the red-headed step child. That also is a good technical/strategic argument for ditching SMS.
But, again, not one that they even bothered make.
And there's always been the "tied to a phone number" issue that's been the #1 complaint about Signal. And once untethered from SMS who cares about phone numbers anymore.
Once again, not even a case they bothered to make.
This is an incredibly bad reason to remove SMS support. Sure, the fact "plaintext SMS messages are inherently insecure" is true, but the implication is not "remove SMS support".
Most people are motivated strongly by convenience. Signal is convenient because of its use as a drop-in replacement for your existing SMS client, so people use it, which increases their personal privacy and security. Removing SMS support will directly and substantially reduce Signal usage, and therefore both of those things.
The solution to "SMS is insecure" is pretty obviously "make a warning message telling users that", which also solves their second problem:
> This brings us to our second reason: we’ve heard repeatedly from people who’ve been hit with high messaging fees after assuming that the SMS messages they were sending were Signal messages, only to find out that they were using SMS, and being charged by their telecom provider.
...and the third problem:
> Third, there are serious UX and design implications to inviting SMS messages to live beside Signal messages in the Signal interface.
This is ridiculous. You're not making a paid product where if your app doesn't look perfect people won't use it - you're making a messaging app, and slightly ugly workarounds are perfectly OK.
> It’s important that people don’t mistake SMS messages sent or received via the Signal interface as secure and private when in fact they are not.
THEN DESIGN THE APP THAT WAY. IT'S NOT THAT HARD.
This post is a travesty, and the reasoning contained inside is completely insane.
Wikipedia says that Moxie is still on the Signal Board of Directors, but I find it hard to believe that he would let something this crazy go through.
IIRC I read (some years ago) that Moxie wasn't really convinced that SMS support should stay in Signal-Android, either.
I agree I can see him being at least OK with removing SMS but it seems at odds with what I felt was his overall view of "get the most people the most security we can" and by extension increasing the number of people using secure messaging services to normalize it so simply using encryption isn't seen as an outlier. The latter part is closer to moot now more than ever before with WhatsApp being E2E by default and Apple having huge marketshare in some markets with iMessage.
Whether Signal can catch up to its open and closed source competition remains an open question, and I don't think features like Signal Stories are going to be what helps them start nipping at the heels of the other much larger competition.
You're right:
https://github.com/signalapp/Signal-Android/issues/6134#issu...
As a side note, I'm on the beta, and recently got "Signal Stories". This immensely annoyed me, and had to dig through to remove it (since it wasn't obvious). After the whole crypto thing and these decisions, it might be time to find another secure messaging app.
I'm not sure exactly what is exposed in the framework API regarding RCS, and how it compares to the relative ease of receiving SMS and MMS messages.
Honestly, it's kind of hard to blame Signal and/or Google if carriers are involved here. I mostly use Signal and Element, so if those two had a single client, that'd be fine. But, I think Signal probably still favors a centralized system, and they have added ongoing call transfers from and to mobile/desktop, and now Stories and the money transfer (not a fan), so I suppose it's up to the users to choose.
[1] https://www.sammobile.com/news/google-messages-rcs-integrati...
I've always wondered how companies become so blind to what their userbase actually wants and needs (looking at the majority of the rest of the comments here that seem to echo my sentiment as well) that we end up in situations like this. I guess "you die a hero or live long enough to become the villain" applies to apps too.
Literally the only reason I recommend others and use Signal myself?
Seriously, Signal doesn't have the userbase to drop SMS support. All my Signal contacts use WhatsApp or Telegram that I already have installed. I use signal mostly as a SMS app, secondly as E2E communication. It will be easier to uninstall Signal.
This messaging seems a little tone-deaf, given that there is no way to export SMS messages from Signal. Apparently it's possible, using a third-party piece of software, to decrypt your backups and extract the messages, but that's not exactly a reasonable thing to expect people to do.
One of the reasons I liked Signal was because it was easy to get normal people to start using it, because they could just set it up as their SMS app, and continue life as normal, just getting the benefits of encryption for any of their contacts that were also using Signal. Now there's not notably any reason to use Signal as opposed to, say, Matrix.
I also think it'll hurt the value proposition when getting people to join signal. Not overcomplicating the messaging scenario was a big winner to do that.
A user already has:
- Telegram
- Facebook Messanger
- Instagram that has direct messages
- the good old email, or better, many of them
- Microsoft Teams for company communications
- Discord for communications with group of friends
- the old SMS (that I didn't even know that in some parts of the world were still used, since I receive them only for 2 factor codes, notifications about my card transactions, and spam)
Adding another app is that a big deal? By the way I don't use Signal, but not for the reason of not having another app on the phone, just because I don't know anyone that has it and actively use it.
Hell, even my aunt that doesn't know nothing about technology has WhatsApp and had me install Telegram because the church opened a channel on it!
Also use DMs on Twitter relatively frequently.
Personally, I use only two of those apps you listed for messaging, and for all the others, I say, "Sorry, I don't use that one."
That's why it was a huge advantage that, on Android, Signal could replace a SMS client. You weren't adding _yet another_ messenger to the list, you were replacing the SMS client with one that could send secure messages. That made "switching" to Signal (which, ofc, was not a switch at all for my friends who use SMS) much easier for me. I could continue texting my friends and seamlessly switch to secure messaging if they ever got signal.
Contrast this with my friends who kept their old SMS client who reliably forget to check / use signal and generally tend to go back to texting me in a few weeks. Even if you send 0 signal messages for a long time, by switching you SMS client you are already setup to receive them and will habitually open an app that supports E2E encryption.
For example - Facebook Messenger also supports sending and receiving SMS messages - likely because they've done the research and found it drives adoption.
I'm glad privacy is becoming mainstream but dislike lowering the bar for adoption to where it profoundly affects users.
That's what is nice about signals implementation is it stands. It supports acting as the SMS default app on android and defaults to signal when it can.
Sure they handle SMS, but the real problem here is that Signal is just another walled garden: they have an overtly negative stance towards alternative clients, while also having very bad support for anything besides android/ios: they have a bad desktop client and they don't have a nice library. Altogether this means that Signal is overtly and willingly against things like Pidgin / multi-protocol clients or overlay, which is what the users want (ie not caring about protocols).
Signal doesn't want to deal with SMS anymore, which from an engineering and high-stakes security pov is a completely valid decision. Yet if it had clean and open local API or a simple and portable client library, or had a stable server API, then someone else could provide multi-protocol clients, tailored to each platform in a secure and stable way.
Now to my actual question: How is Beeper compatible with the ToS of platforms like Instagram and Facebook that, to my knowledge, don't allow their users to use 3rd-party apps? Case in point: I recently wanted to use a FOSS 3rd-party messaging app for Instagram and my account got promptly banned.
Question 2: Do you support full message backups in a well-documented format?
Anyways e2ee and sms doesn't mix well
From my perspective (and I am NOT speaking for anybody else) this is an improvement. I already have multiple messaging apps installed, and when I click send on a Signal message I expect it to go end-to-end encrypted or not go at all. But I am not the only user profile.
There, points addressed. Can we move on?
It already is opt-in.
And to your main point, I hadn't even considered before seeing this comment thread that anybody felt differently, let alone so strongly. Really illustrates how differently people think about the same app.
What a laughable, out of touch suggestion. Did anyone at Signal actually ask the community what they thought about removing SMS support?
Seriously, this decision is going to kill Signal app. It will halt the majority of growth as evangelists such as myself can no longer recommend it with a straight face. Signal is supposed to enhance the messaging experience, not replace it.
I think Signal thinks they can take on the WhatsApp market, completely misunderstanding why that market didn't choose Signal in the first place. The products serve two completely different user needs, and are highly geographically segregated.
What the heck is going on over at Signal Foundation?
It's absurdly short-sighted to call SMS legacy.
That is hard to swallow, being able to quickly send a message through SMS to the same receiver in emergency situations* was quite handy.
*like when you're at a protest and the tower is overloaded, or you're on a remote location and you see that the Signal message doesn't get through because of lack of 3G/LTE connectivity.
With the SMS integration it was pretty easy because it would just switch over if the other person had Signal or if/when they signed up in the future.
What's the workflow now? Manually ask them on SMS if they use Signal? Just try it and see if it works?
This sounds like one of those "Don't Worry! Rejoice! We're breaking your things!" announcements that hasn't even thought about how people use Signal IRL.
I'm going to stop my monthly subscription to Signal Foundation.
https://news.ycombinator.com/item?id=33181636
I have instead come around to support this move 200% and have instead doubled my monthly subscription. The explanation at the blog post is an abomination, however.
Leave SMS and all its shitty successors for Apple and Google and carriers to kill/maintain.
The blog post needs to be shelved and redone as every listed reason feels post hoc while the reasons listed at that link ([1] for anyone who dislikes friction) are grounded in reality and show Signal being proactive.
[1]: https://community.signalusers.org/t/signal-blog-removing-sms...
If User A (who uses the signal app) regularly communicates with User B (who doesn't), then this change might encourage User A to ask User B to join signal. It makes a stronger network effect, and will increase viral growth.
However, I think the Signal team is misguided, and in fact they will just lose users who don't want one more app to manage.
Conversely, the inconvenience of having multiple messaging apps could cause User A to stop using Signal. Look at what happened with Hangouts when they dropped SMS support.
Now that it's just some random chat app with its own protocol I could not be more allergic to their brand.
Hopefully they didn't need my user type for their flywheel.
https://community.signalusers.org/t/signal-blog-removing-sms...
> So I guess the TL;DR is: SMS is on it’s way out in general, and in a world where Signal supports SMS, all of SMS’s shortcomings are often attributed to Signal itself, all while confusing people into thinking their SMS’s are secure.
I was responsible for roughly a dozen Signal converts. They will all be uninstalling when this takes effect. It seems like everyone else in this thread is saying the same.
Prepare for a mass exodus of users.
None of us want to be responsible for training/tech support for how to use 2 messaging apps for non-technical users
Most people in my social circle use Snapchat or iMessage for "texting", for reference.
I noticed this when I got a new phone and hadn't yet enabled signal to handle SMS and opted to stay with it because of how many conversations I had that were auto-E2E, where before they'd just been text messages. I still prefer signal for the people I know use it though. In short you can still use the signal (protocol at least) on messages, so I can understand why signal would do this.
The big loophole is:
* The messages can be forced to be sent unencrypted if one or other end of the connection doesn't have data connectivity.
* The conversation backups are cleartext, so if either you or the other party has backups enabled, the e2e encryption is kinda pointless.
It seems Google is going to let it die to move people to Google Messages.
https://community.signalusers.org/t/signal-blog-removing-sms...
I did not need emoji's, groups, gifs and all the other neat stuff that signal has introduced throughout the years(to varying degrees of success). I had been using it, while none of my friends were. What I did need was a single messenger to handle sms/mms with the default being secure when security was available. I have multiple friends now using it and sadly will revert back to a 100% insecure messenger for my phone for 99% of my messages. The new one will do everything better than signal does except security, so it will have some benefits.
I will be on the lookout for a replacement. I hope signal continues to bring security for entities that need it through the future. I have not looked at tox in a while. I'll check that out again.
Pretty weak reasoning to me. Just do what Apple does and color sms messages some other color or whatever. Problem solved.
This is gonna make me drop Signal. I use it as my default sms app and have been very happy with it, but most of my conversations (although most actual messages are Signal) are still over sms so it'll have to go. I can't be bothered to roll a bunch of different apps.
Still, I'm grateful for the work the Signal team has done over the years. Sad to see us part ways!
It's not like I wouldn't still want to message him, right?
Convenience is extremely powerful in getting the layman to adopt this kind of tech, and I feel like it should be prioritized.
To me this feels like signal not understanding that their intended userbase and their actual userbase are very different, as I can't imagine the number of people that use signal solely for it's e2ee is comparable to the number of people that use it as their sms app.
Aside: Funny how quickly the wheels fall off as soon as Moxie leaves. (https://signal.org/blog/new-year-new-ceo/)
I had no idea signal even supported SMS, nor do I know anybody who uses SMS
I found it useful to have all these messages in a single place, although this change probably won't inconvenience me too much. However, I don't see any benefit.
SMS is typically used for notifications-style messaging (or spam), so the impact of this change is probably minimal for a lot of people there. Even chat-bot/support style messaging in the B2C space are moving to WhatsApp (or equivalent).
In fact, I hope getting rid of SMS support adds some capacity to the team for features/fixes I care the most about.
oh well
https://community.signalusers.org/t/signal-blog-removing-sms...
No doubt they are in a tough spot. Some users will not accept this feature omission. But if what they claim is accurate, the insecure nature of SMS, along with Google's hoarding of their internal RCS APIs makes it tough to be a messaging provider on Android.
I have been using Signal for years. The ability to make it your default SMS client is one of the major drivers of adoption; if someone agrees that privacy matters, and you can point out that the transition to Signal is frictionless and offers all the same features as their existing SMS app, then installing, trying, and liking it become easy. I've brought hundreds of people onto Signal, and being able to give a simple 'yes' to questions about whether it handles SMS is almost always what 'seals the deal.'
Signal is saying that mixing non-secure and secure messages in the same app might cause confusion and security fails, even though the difference is very clearly signalled.
Their argument is bullshit. If users go back to separate messaging apps, chances are those apps will look much the same as Signal (which itself copies the look and feel of the iOS messaging app quite closely). There's a much bigger security risk from users forgetting that they are not in Signal and carelessly pasting & sending information that was supposed to be private or disappear.
Additionally, it creates a bunch of new security risks, allowing third parties who gain possession of a phone to distinguish between conversations that happen over SMS and conversations that happen over Signal, drawing inferences that there is something untoward about the latter.
I cannot understand the constantly changing, er, signals coming from Signal. One month they want to be just like every other messaging app and they're pushing features that hardly anyone has asked for, like sticker packs or crypto payments. Other times they say users are too paranoid for not wanting to expose their phone number/pop up messages about who in the user's address book has installed Signal. Today they're saying that wanting to use Signal for all your messaging needs is somehow anti-privacy.
I find myself wishing it cost money or a small annual subscription so I could vote with my $, because the Signal foundation seems to spend more effort on telling its users that they're wrong than on listening to them.
[1]: https://community.signalusers.org/t/signal-blog-removing-sms...
It was seamless and I didn't see much of an issue with it.
I guess Signal is going to become that app that is only opened once a month or so. No more donations from me.
That's something a simple UX change could improve and does not justify something so radical. There's probably another reason they are doing this, these are my best guesses:
- Feature parity between Android, iOS and Desktop
- Moving towards Signal accounts tied to usernames instead of phone numbers
- Developer resources (unlikely, since this feature has existed since the beginning and probably requires less maintenance than other features, but I'd pay for a subscription if they kept it)
Whatever the real reason is, make them say so, the reason given is extremely flimsy. If they go through with this it will put lives in danger for people like activists, journalists, and anyone crossing a border who depend on their SMS messages being encrypted at rest (despite SMS not being end-to-end encrypted in transit). Using Signal instead of a different SMS app also prevents other apps from reading your SMS messages. Test this out - switch your default SMS away from Signal and sign into an app requiring SMS verification, and that SMS is probably readable by the app without any interaction on your part.
Cue the Apple-ish response of them saying they're listening while not taking any of their users' valid concerns seriously at all. Very disappointed in them.
So this is now a lie. This decision absolutely goes against how users actually use the software. Tone deaf and insulting. More cases of Signal saying "we know better than you. You're using it wrong. Do what we say.
This announcement totally squares with my experience trying multiple times to fix their MMS implementation. It was at that point that I stopped using Signal for SMS, since I knew it wasn't important to them
Changing the Send button's icon to "SMS" or a color/border change ala iMessage are ideas off the top of my head and I'm sure they've got designers significantly more talented than I am that can think of better ones. We've seen very little iteration there that's indicated the significance of that problem...and frankly if they highlighted this as a tactic vs endless spam texts more people would be receptive to this news. As it stands I think this is going to significantly reduce their number of casual users. In fact I'm willing to bet that the cohort of users who are used as justification are the least likely to convince their contacts to switch to Signal.
Don't get me wrong, their real desire to increase the amount of people sending secure messages via Signal alone + resource mgmt in the face of a recession are valid. But acting as a unified messenger (with better link unfurling, threaded replies, and reactions after Google killed Allo vs the default messenger that spent years getting them) was the trojan horse onto many of my friends' and colleagues' phones. Now that there's parity I can see more people just opting into the default messenger/FB Messenger + Whatsapp combo because more people exist there and we're all just lazy.
This decision is idiotic and will cause a mass migration off the platform. Why not take a better approach and work on a better UX to make it clearer when a message thread is secure or not?
Ok I get that on Android the situation is such that, as a message provider, you don't give away "metadata" ie who is texting whom, keeping that data either for yourself or the highest bidder. WhatsApp, too, fuss about e2e encryption while conveniently not talking about the value of "metadata" for ad targeting and even want to aggressively grab and upload your contacts at every turn (despite it being illegal in EU to share PII without explicit and documented and revocable consent of all individual phone number holders stored in your phone book). But why does this change come only on Android? Would it be suicidal for signal to drop SMS/MMS when the default messaging app (iMessage) does fall back to SMS/MMS on iOS as is well known?
A messaging app should have one clear behavior per interface. This was "maybe secure, maybe not". I have an SMS app for that (well, VoIP-sms, because I'm weird).
Can you say more about what's confusing about this for you?
and the workflow when adding someone is different (waiting for approval or not).
Not that anyone really uses SMS anymore in [nearly everywhere].
It made it amazingly easy to get started yourself, and also convert others.
Why on earth would they decide to give up that advantage?
It would make more sense if there was one codebase that supported all apps. And then I could make a "silo" for each use case. I would make one icon for activism, one for work, one for friends. The first one must use E2EE, the second one must use my company's Rocketchat, etc..
It's a pity Signal doesn't allow third party clients. I really hope somebody makes a rouge multi protocoll app, like Pidgin used to be. I bet a dedicated small team could make it in a year.
Matrix Bridges might also be a good option.
So instead of working on RCS, we got mobilecoin, stickers, gif search, and now yank out legacy SMS support so more "features" can be developed?
As an early adopter of TextSecure, through CyanogenMod integration, to Signal and everything in between, I have the t-shirts and all -- I am done with Signal.
But like many recent developments, I'm just left dumbfounded by their high-level decision making. I've stopped recommending signal to tech persons for a while. I don't want yet another messaging app either. Matrix is serving me well.
Is anyone NOT inside Signal happy about this decision? Please comment if so, and why.
Dropping the Chrome Extension was a major quality of life dip for me, made Signal far less usable across systems. Their insistence that they didnt feel it was up to their desired quality offered me no comfort; it worked, it was easy, and you tool it away.
Signal refusing to allow scripting, or an API, or any option at all for expanding user agency sucks.
They have voice messages but to my knowledge you cant preview the message at all. I dont even know if you can abort sending it once you start?
This company had such an early lead but they keep doubling dowm on the most detached, conceited ridiculous plans, few of which benefit the user. It's embarassing. It'd be so nice if there were some mandatory protocol in telephony that let people declare other systems they support; add someone's phone number and see their XMPP, email, irc, and mumble contact info. It's absurdly difficult for people to make known their contact info; Signals sms integration was a killer feature that seamlessly put them atop the telecomm heirarchy, but here the stupid fools are, killing that killer feature & what got them this marketshare.
> The most important reason for us to remove SMS support from Android is that plaintext SMS messages are inherently insecure. They leak sensitive metadata and place your data in the hands of telecommunications companies. With privacy and security at the heart of what we do, letting a deeply insecure messaging protocol have a place in the Signal interface is inconsistent with our values and with what people expect when they open Signal.
They do have a point though. SMS is insecure, unencrypted and leaks highly sensitive metadata anyway and it needed to go from Signal. You already have the system SMS app for this to use.
To hear that people use it in group chats is mind boggling to me.
Rest of the world is more diverse, so iPhone users don't get to force their default on everyone (as it's crappy if you don't have an iPhone). Also Google constantly fails to build vaiable, cross platform alternative. Therefore everyone is used to having a few apps.
Basically situation in US is what you get if you allow entire nation to be put in walled garden.
Also it's absurd, that instant messaging, that had zero meaningful innovation over last 20 years, still isn't over open protocol and we tolerate that's used by corporations to pressure customers into their ecosystems.
personally I jumped the boat when they made app unusable with PIN code nag screen, which they backpedaled from after uproar but it was already too late for me and my extended family where I pushed Signal, there were message delivery issues, horrible downtime in Europe because US admin was taking sleep, but the unavoidable nag screen was the last drop, the later news about shady crypto and other stuff just convinced me this app ain't worth a dime, which this SMS announcement just confirmed
if you wanna alternative IM app use Element (Matrix), unlike Signal it doesn't require phone number, it use decentralized network and you can choose from whatever app you like, never understood why IT skilled people pushed Signal after Element became already quite user friendly
Basically no-one does all of that in one app, so using Signal for Signal messages is normal for those people.
I have telegram, signal, whatsapp and Element on my phone, this is why the new digital markets act is going to be revolutionary, especially with bridge friendly platforms like matrix.org.
For one, commercial services will go through SMS to contact you. Delivery people asking if my mailbox can fit parcels won’t be through Whatsapp or Messenger.
Then you’ll also want to compartmentalize and limit how some people can reach you. That means if you’re already giving them your phone number, you don’t want them on the other messaging services as well.
Life is complicated, and there will be endless use cases for the baseline, default messaging platform.
This is not true at all, at least for Czechia. The number is going down but it's still in billions (for a country with population of ~10.5M). Quoting from the official annual report:
> In the number of SMS messages sent from mobile networks in 2018, CTU estimates - in the context of the increasing popularity of OTT messengers (e.g., WhatsApp, Facebook Messenger, Viber, etc.) - a slight decrease relative to 2017, approximately by 2% to 8.21 billion SMS messages.
https://www.ctu.eu/sites/default/files/obsah/stranky/284221/...
It feels like I just got my friends to put letters in envelopes instead of only using postcards. Now we all have to drive to two different post offices - one for letters and one for cards - because the original office will stop delivering cards. Everyone is just going to go back to using postcards.
>Dropping support for SMS messaging also frees up our capacity to build new features (yes, like usernames) that will ensure Signal is fresh and relevant into the future
I don't buy this.
First this wallet thing, now no SMS? Why not try to figure out a way to use encrypted SMS?
What do you purists use to talk to all the random people around you? Do you reply "I'm sorry, it's too insecure for me to answer that, you'll have to install Signal first" messages when more distant colleagues ask you if you're at your desk right now? Do you teach your grandmother to use WhatsApp so her birthday greetings won't be intercepted by the NSA?
(Admittedly, the email situation at work being utter trash may be coloring my opinion here.)
This one app nonsense is asinine. You’ll never get global adoption of one thing.
Do you not?
I've had Signal since shortly after it renamed itself from TextSecure to Signal, and I never bothered using it as the default SMS/Messaging app, because back then it was a bad SMS app. It felt like it paled in comparison to what the default Android Messages app could do. I didn't want to get the false impression, either, that my chats were encrypted when they really weren't, just because they shows up in Signal.
So I kept the two separate. I assumed pretty much everyone else did the same. And yeah, there's the occasional oddity when someone texts me over SMS instead of using Signal when I know for a fact that they have both, but most of the people doing it are using iPhones, so I have to assume it's the same experience for them as well.
What's weird is that in the numerous Matrix vs Signal comments that populate Signal and Matrix submissions you rarely find SMS support as an Signal advantage over Element/Matrix.
Most people I know didn't like Signal taking over the SMS when they accidentally opted in.
"My bad, this easy SMS client I got you to switch to is going to stop supporting SMS, and we're going to have to export all your old texts or they'll be gone forever."
i hope they reconsider this decision; i have been using the product since textsecure and I would hate to stop doing so because they no longer support out-of-network communication.
What people know that Telegram isn't end-to-end encrypted, but think SMS is?
I'm willing to wager it's not as big as you're trying to imply.
Beyond that, the minority in group 2 that use Signal are most likely to be using default settings. SMS handling is a non-default option. So you're left with a very tiny minority.
Group 1 makes up the vast vast majority of the userbase (and most likely 100% of the evangelising userbase)
(Also: if things are unclear for non-technical users, that's a UX challenge, not an absolute)
> If you want to keep them, you’ll also need to export your SMS messages from Signal into that new app.
So that means my text messages will be removed from my Signal chat history? Put differently, considering how many of my contacts over the years switched between using Signal, not using Signal, and using Signal again, this means that parts of my conversations will suddenly be gone and conversations might suddenly be incoherent?
I have trouble expressing just how angry I am about this change.
https://community.signalusers.org/t/signal-blog-removing-sms...
Still a bummer that support for SMS will be removed but now I'm at least a tiny bit relieved.
Reason 1 and 2: Users can be confused by whether a message is SMS or Signal and this is bad for security, backed with "there's only so much we can do on the design side"...really? At what point do you sacrifice the convenience of the masses in order to get through to people who don't understand that a message that says "SMS" on it is sent over SMS? Hell, turn SMS bubbles bright red or something, that would be better than removing the feature.
Reason 2: Users can be confused by whether a message is SMS or signal and thus end up incurring charges - I thought about this for 5 seconds and came up with a solution - ask the user whether they ever want to send SMS through the signal app when they first open it and respect that preference. Make it a setting. Boom, if you are using signal you know you're going over data. Or is the response to that that users are too dumb to understand it? I'm positive there is a good solution here.
This decision just doesn't make any sense and it's probably obvious to the people working on signal that it doesn't make sense, I wonder what the decision process looked like here.
This is a terrible decision.
It took significant effort to convert close friends and family to signal and was only palatable due to it becoming the default messaging app on Android.
Not only will I be likely to field a ton of tech support once this occurs, I'll also likely need to recommend a completely different app.
Looks like I might just bite the bullet and buy iPhones for my immediate family (without icloud imessage backup)
I'm tired of explaining to my relatives why they can send their picture to one person but not to another, or why it requires wifi for some contacts. Mixing two incompatible messaging standards communicating via two different channels in one app is confusing for many people. Sure, it also has advantages and I think you could make it work, but the app actively asking users to make it the default SMS app is not a great idea.
> "We’ve heard repeatedly from people who’ve been hit with high messaging fees after assuming that the SMS messages they were sending were Signal messages"
> "We can only do so much on the design side to prevent such misunderstandings"
It sounds like they are trying to protect users from themselves.
Now I am faced with a decision: * Do I keep signal around, for that one to two messages a month I receive? * Or do I get rid of it, forcing my contacts back on Whatsapp/regular SMS?
To be perfectly honest, I am thinking about just gettting rid of it. No need to keep yet another communication channel around when I can't get rid of the other ones anyways. :(
The only way they have a hope of putting this genie back in the bottle is to provide a loud, strong, clear mea culpa, stating that they were categorically wrong to propose dropping SMS support, plus a strong promise that they will continue supporting SMS for the life of the product. Maybe something along the lines of, "if we ever propose dropping SMS integration again, you can consider that a warrant-canary type of alert".
Dropping an insecure messaging system is far from being a warrant-canary type of alert, though.
These protocols are insecure, not private, and fundamentally incompatible with Signal's mission. Supporting them at all, while highly convenient, is a queer oxymoron for an app like Signal. We have to rip the bandaid off eventually.
There's no chance I'm going to get her to install Signal, she doesn't need it, her circle is almost all blue-bubble iPhone users who don't value anything Signal adds over what iMessages gives them.
This doesn't kill SMS/MMS. Not even a little tiny bit. All it does is make MY life more irritating because I have multiple apps that I have to deal with now. The way to kill it is to make something better that people WANT to use, that offers the extra value to make it worth the effort.
This trend of siloing functions into seperate apps is confusing and frustrating for regular users, especially elderly users like my mother "Just push this button you can text and call me and text any of your friends"
(How many current users will it drive away? Or cause to use Signal less than before?)
(How many new users will Signal acquire, because adoption network effects weren't working as well as possible, when messaging with non-Signal friends was too convenient, but now Signal users are more motivated to prod their non-Signal friends towards Signal?)
And who's going to pick up the users that Signal loses?
The result of this change is that we will stop using signal all together. They've accomplished the exact thing they said they want to avoid.
Rip. This is definitely going to make it harder to get signal adoption. My partner will surely stop using it too now and I'll have to convince my friends to migrate to yet another platform.
In my friend circle, at least, it's common for people to go in and out of using Signal. They might have had it on an old phone and forget to install it on the new phone. Whatever - life happens.
Signal can't know if someone who used to have their number registered with Signal has stopped using it. Signal will still display them as a user and accept messages. It's been invaluable for me to be able, if I message a friend after a break in communication, to send a signal message...and then, if I don't get a response, a SMS message. If they respond to the SMS I can see in our history that they had signal and switched at some point. This change takes that away and will make it must more difficult to deal with inconsistent adopters.
The only possible benefit to this would be to break their dependence on using phone numbers as the way to sign up for accounts and possibly provide a reasonable way to export message data.
Otherwise it just feels like the wrong decision and a reminder that Signal is not a community driven project but subject to arbitrary changes and provides no way to fork or disagree with the project lead as can be done with most free and open source software.
The user enters the relationship consensually, but the choices about the service's operations are done without the user's consent.
In this case, the user's only choices are to either abandon the service, or to put up with the changes they did not consent to.
In the future, with data portability being common and table stakes for most services, I think there will be a third option: seamless transition to a different service, preserving all data, metadata, relationships, and user accounts.
This is already possible with existing, established technology: private keys, hashing, and text files.
We have a bright future to look forward to, where this type of change will be perceived as old-fashioned and barbaric as surgery without anesthetic.
Really? More used than WhatsApp, Telegram or iMessage?
> ...
> Now, data plans are cheaper and far more ubiquitous than they were nearly a decade ago
I'm curious, are these guys lives in a bubble or what? I think they should try to travel around the world a bit.
> we’ve heard repeatedly from people who’ve been hit with high messaging fees after assuming that the SMS messages they were sending were Signal messages, only to find out that they were using SMS, and being charged by their telecom provider.
So in essence, they fuc*d up UI/UX and now the simplest approach to fix would be just to remove it. Sounds like a brilliant idea from an MBA guy or whatever-evangelist-title-is.
Is it feasible to fork the app?
I will be recommending against using Signal for any reason whatsoever to unless this decision changes. If it goes through, I'll move myself and everyone to something else. The options for e2e encryption are many today and I already have to have a bunch of these apps, so Signal becomes pointless. If they do this, they'll do worse later. Better to get out now at the "first" red flag.
That said, I also want to use signal without my phone. Things like usernames would be great.
That said, part of me thinks that’s an engineering problem, not a UX problem. Why are engineering problems being pushed into the UX requirements?
If they manage to make the UI and feature set as complete as iMessage, it would convince people to switch to Signal much much faster than Google's pity RCS bashing of Apple.
Just a week ago I replaced the sms app with signal for two people.
This was the main reason why I just installed signal and still use it vs telegram because of this exact feature :-(
Come on signal what ya doing stop!
4.4 stars. I believe it's $3 or $5 to remove ads now.
Heck I can't even use Google Messages in my phone without gapps.
I'm happy we have an available secure chat for people that need/want it, but I'm more than happy to keep it relegated to niche uses until it gets more user friendly.
I do think Signal deserves a lot of criticism but I'm always amazed how a forum of programmers and highly tech literate users just trashes a small team of hackers fighting against big tech. They are open source. We are the ones that can help them. There are plenty of custom builds out there (that do access official Signal servers) and you can build this feature back in if you want. I don't think it is a problem if Signal decides it has more important features to support with their tiny team. But if you want more features you got to donate either time or money. This is "HACKER" news, so get hacking.
"From the beginning, the team behind Signal put people and their needs at the core of their commitments. They understood that iron-clad security is fairly pointless if people can’t use, access, or feel comfortable with it. In other words, if my friends won’t use a messaging app, it doesn’t work as a messaging app. It works as a thought experiment, at best. Understanding this, Signal’s developers and designers created an app that honors people’s needs and expectations, while maintaining strict privacy promises."[1]
I'll echo the other comments here talking about network effects, onboarding friction, and social capital wasted convincing friends/family.
Maybe I'll grab the source code, rip out all the Signal parts, and just use that.
Next step: Please stop using phone numbers as a user ID. I have lots of throwaway phone numbers, but many people don't want to leak their phone number to every single person they want to have an encrypted conversation with.
I assume you live in a place where SMS isn't necessary? In the U.S. it is.
Mine don't need SMS
> internet provider,
Also doesn't need SMS for me
> my bank,
F them, I use a throwaway Twilio number for this
> my elderly neighbor who can barely use a phone and I taught how to text,
I tell them to either e-mail me or stick a handwritten note on my door. E-mail is WAY easier to use for elderly people in my experience. You get nice big keyboards, big fonts, big screens, and it works on any device you own, not just one. But if they disagree they can still handwrite a note to me
> every restaurant I order online from,
I use a fake number for these. They don't need my number any more than I need their wait staff's phone numbers. Never been a problem. I just go pick up and say my name, no SMS bullshit.
> the plumber I just texted literally an hour ago
I don't text plumbers, I e-mail or call them
> bank I can't use VOIP numbers with them, not sure about Twilio.
> my elderly neighbor who can barely use a phone and I taught how to text You make the assumption that they even have a computer: they do not. They do normally just knock on my door, but they want to send and receive pictures to their family and other people who do not live close by.
> every restaurant I order online from I want to know when my order is ready.
> the plumber I just texted literally an hour ago He asked for a picture of the leak and to text it to him. He's reliable and has done good work before, I'm not going to switch just because he doesn't use email.
My point in all of this is that in the U.S. SMS is ubiquitous. As much as I would love to leave it behind, there are just so many situations where you need SMS.
Honestly not really, in the US. You can usually find ways around it if you tell the business that you don't have SMS. With governments I don't think they can legally require you to have SMS.
When they find out it's incredibly difficult to deal with you because of the design choices they made, it helps dethrone SMS, one business at a time. Vote with your behavior. Make them realize they made a bad choice by picking SMS.
I lost you there
I tell everyone I don't use SMS. The only ways to message me are e-mail, Signal, WeChat, FB, and Instagram.
E-mail is the best "generic" way to reach me that isn't tied to a company's platform, and a much, much better UX than SMS in almost every way, especially when travelling internationally with multiple devices.
I haven't for many years, for sending (except for one time I wanted to test a modem driver SMS function).
I regularly use Signal, Telegram and Google chat and used to use whatsapp until it was banned by my employer but the only time I ever use SMS is to receive automatic authorisation SMSs
- Setting up phone for relatives
- Replacing Android Messages with Signal
- “So this is the App to send and receive SMS, and you can also send me and many others secure and free messages on there”
My optimism for Signal becoming mainstream just faded...
If not: please Signal guys - that's just a step back. People who write SMS won't stop writing SMS, you just allow another party to do whatever is good for them. And searching through _all_ messages is really a big thing for some of us.
Why not just add some awareness items - visible eyes and ears and dollar signs, together with the information what information is given away and that this might cost money?
"We have now reached the point where SMS support no longer makes sense."
They should have let the users decide that
If Signal does enable creating accounts with non-identifiable user names instead of phone number, then it will be a great improvement and a protocol that can be used for activists.
This is a horrid decision. Everyone above already covered the reasons why better than I could.
I would drop Signal for that app, even if I had to pay for it.
I can see how this is a hassle to maintain though; just for example, my Huawei consistently resets the default sms app to the crappy stock one every time I use their "ultra battery saver mode" (which I otherwise like a lot) even though I explicitly included signal in the list of apps that are allowed to run in that mode.
So I can see how the ecosystem makes this an annoying feature...
A huge chunk of Signal users won't have ever used the SMS feature so why would they leave?
I find myself very glad to have focused my efforts on moving family and friends into the Matrix ecosystem instead of Signal. Not that Matrix is perfect, but I don't have to worry about the rug getting pulled out from under my feet. :(
But whatever. I only send and receive SMS very rarely these days, so I installed Silence on my phone. It's still annoying, though. Having one app for SMS and encrypted messaging was very convenient.
Now, if signal could get rid of the phone number requirement...
If I get a SMS in Signal and I reply with Signal, it sends a Signal message - not a SMS.
I think the only one that's totally anonymous is Wickr
Does anyone here have a good suggestion for an SMS app for Android?
They just keep on bugging.
All of my family use iOS though, so this is already their use case. I understand less code is more secure, and a unified codebase between devices is good -- heck. This might even lead to no more phone number requirement.
But this still stinks for my use case.
FWIW though, I was more upset about the cryptocurrency thing.