Signal Introduces Stories
signal.org
signal.org
When you create a story you can make it a group story or not.
If you do not make it a group story, reactions and replies to stories get sent to you over your 1:1 chats and not shared across other recipients of the story.
If you make it a group story, and share it with multiple groups each group receives their own copy of the story and replies and reactions can only be viewed by others in the same group.
After having been burned SO OFTEN by other social platforms embarrassingly notifying others when I did something I thought was a passive post, or leaking information from 1 of my subgroups with another I was very worried that would happen here, but great job signal team!
The only awkward part that I've noticed so far is if I have a contact in 2 groups that I create 2 group stories with, they now have 2 identical stories show up on their story board. It makes sense and I think the UI clearly indicates for which group replies and reactions to each story it would go to which is probably the safest (best?) solution, but I could see that getting a little annoying if I share multiple groups with a frequent story poster.
Sure, it takes N^2+N messages, but that's not exactly a massive overhead for text. Multimedia takes N times as much bandwidth as the 1-server, server-many model for the sender, but otherwise isn't terrible.
There is actually a way to do it, if you assume PKI (which signal provides) and that all messages will be delivered in some bounded time. It’s called the dolev-strong protocol and it guarantees that all honest members of the group will agree with each other. Unfortunately, it requires one round per group member and delivering all messages within a bounded time isn’t easy.
Which lets you know that Alice and Bob are in contention, which is probably good enough for most situations. "One of these three (or more if you have multiple groups of bad faith actors) sets of users are operating in bad faith" should be plenty of information for a user to make an informed decision. Even if that decision is "wow, how did I end up in a group containing multiple groups of bad actors, I should be elsewhere".
Consensus protocols are tricky, BTW.
A bad actor could screw with you in this naive implementation though
IIUC this is what iMessage does (at least when Messages in iCloud or whatever it's called is disabled), except s/people/devices: say you have three devices and someone sends you one message, the message is encrypted once per recipient device, and three encrypted messages get sent. Whether it's 1 person with 3 devices, 3 people each with 1 device, or 2 persons with one having 2 devices and the other a single one becomes largely immaterial.
In other words, it has a bad UX. Which was the original point about encrypted group chats.
If one app found a way to make a nice UX for it, all the others would follow. So in practice it seems perfectly reasonable to say "Matrix" when talking about the general UX found in apps implementing the Matrix protocol, doesn't it?
System level some use additional connections/recipients for spam/moderation and the moment you allow any invisible/visible group users in, there is a massive potential for an exploit.
Additionally you have the potential for forking off messaging to other users at the system level for either oversight or spam/moderation/other. Some of the compromised systems out there use this very well.
A sneaky way some of these "secure" messaging apps are also doing this is ghost participants in the chat that can essentially syphon off the messages even without a compromised client. The ghost participant is always under the guise of moderation or anti-spam or telemetry or some other proprietary shim.
> The code shows that the messages were secretly duplicated and sent to a “ghost” contact that was hidden from the users’ contact lists. [1]
Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats.
Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted content. This is also taking place in other client apps as well: VPN, password managers, extensions, wallets, even build systems and more. Many like VPNs have logs sent elsewhere but deleted locally -- access to entire machine and all network access. People are way too trusting of "secure" systems/apps that are very common today based on trust.
All of these apps/systems would pass code checks, reviews, security inspections and essentially be encrypted/"secure" though a copy is sent off to another area for review. At runtime the leak is in the direction of the data.
Then you also have governmental oversight that opens up holes that can be exploited.
On Ghost Users and Messaging Backdoors [2]
> to add a “ghost user” (or in some cases, a “ghost device”) to an existing group chat or calling session. In systems where group membership can be modified by the provider infrastructure, this could mostly be done via changes to the server-side components of the provider’s system.
> I say that it could mostly be done server-side, because there’s a wrinkle. Even if you modify the provider infrastructure to add unauthorized users to a conversation, most existing E2E systems do notify users when a new participant (or device) joins a conversation. Generally speaking, having a stranger wander into your conversation is a great way to notify criminals that the game’s afoot or what have you, so you’ll absolutely want to block this warning.
> While the GCHQ proposal doesn’t go into great detail, it seems to follow that any workable proposal will require providers to suppress those warning messages at the target’s device. This means the proposal will also require changes to the client application as well as the server-side infrastructure.
> (Certain apps like Signal are already somewhat hardened against these changes, because group chat setup is handled in an end-to-end encrypted/authenticated fashion by clients. This prevents the server from inserting new users without the collaboration of at least one group participant. At the moment, however, both WhatsApp and iMessage seem vulnerable to GCHQ’s proposed approach.)
[1] https://www.vice.com/en/article/v7veg8/anom-app-source-code-...
[2] https://blog.cryptographyengineering.com/2018/12/17/on-ghost...
What's worse, this even affects the few who try to introduce new things respectfully, because people are so in the "IF SOMEONE OFFERS ME SOMETHING IT'S JUST CRAP I DON'T WANT" mindset that they reject new things outright.
As far as I can tell, lots of people love stories.
Because it helps me convince new users to try it out.
I used to be able to tell people, "You can change your messaging app to Signal and it'll send secure messages to other people on Signal and you'll still be able to send text messages to everyone else." Seamless.
Now I have to convince them to use two different apps for messaging.
SMS sucks but it has a massive user base.
Their reasoning for removing SMS was that it was insecure and people didn't know when they were sending an insecure SMS or a secure Signal message. Loads of people suggested they just put SMS in it's own tab to differentiate them and that was dismissed like it was a dumb idea. Then they add "Stories" (a feature nobody is going to use because they don't have a user base for it) and put it in a separate tab.
I honestly don't understand why they think Stories, a feature that caters to social media users, is going to to be used by the new target audience (with the removal of SMS) of security conscious techies.
Last week I spoke to my 20-something sister and learned that it's basically a must-have for her friend group, who sometimes have entire conversations just with stickers shared in her group.
Had no idea, but in hindsight realized I'm no longer tuned in enough to know how people just 10 years younger communicate, let alone from different cultures.
My point is: 100% agree. Glad it's not in my face and not caring is the way to go. Being cynical about these features is probably ignorance
I still do not understand why everyone and their cat copied that from Tinder.
Creating custom sticker packs is also fun, including memes or cute cats.
But of course I don't speak for everyone my age, and it's different for each culture and personality.
> outside the US
that's a 330m-person population, which is also home to Signal. Not only do I get SMS from people like neighbors and so that I don't especially want to convert, SMS is used to send payment receipts/pickup notes in restaurants, 6 digit verification codes for many websites and so on. If you are outside the US and don't have to deal with SMS congratulations, but for the large number of people in a territory where it is still a key part of digital infrastructure, arbitrarily yanking the feature is a huge pain.
It has though. RCS has come along, which means that you might send an SMS to someone, and their response gets "upgraded" to RCS. If your app doesn't support RCS (and it's impossible to support RCS right now, because the APIs aren't available), you'll never see it.
The choice is between "Keep maintaining the functionality and have people get progressively angrier that their messages are going missing" or "drop it entirely".
I don't think they will.
But there's also certainly something to be said for deciding where to spend your time. Sure, getting regular SMS right on many different devices might be a difficult programming challenge, but if that means you can't spend time on making sure your service scales, or that people are able to hide their phone number, or... Then that's not laziness, that's making a hard choice.
MobileCoin which is Signals self printed crypto (think what FTT was to FTX) was released: December 6, 2020
Their trajectory a year or two ago is no different
People's Android devices can be opt in to receive messages via RCS based on phone number with either Google or their carrier. If the number is registered via Google, the number can be deregistered using a form. [1] For Verizon, it seems you can call Customer Support at 800-922-0204 to disable RCS. [2] Presumably other carriers have similar options.
Once RCS is disabled at Google/carrier level at the phone number level, other RCS compatible phones will fall back to SMS/MMS for delivering messages, which will cause the Signal app to be able to read messages via Android SMS APIs.
Seems like quite the hassle to set up an SMS app.
[1]: https://9to5google.com/2020/06/19/google-messages-disable-rc...
[2]: "How do I turn off Advanced Messaging" https://www.verizon.com/support/advanced-messaging-faqs/
https://www.verizon.com/about/news/verizon-google-messaging-...
https://arstechnica.com/gadgets/2021/06/google-enables-end-t...
Also, less super compressed images/videos. I get they have to save space but sheesh they look like garbage
To avoid compression you can send photos as a document.
I always wonder how non-HNers use such software, if even the dedicated people are struggling.
Not sure how much degraded battery affects it. I recently got my iPhone 8 degraded because of battery and honestly I didn't notice anything.
Even my old iPhone 4S is a little beast. I remember playing Asphalt racing game. It pushed it to 60 FPS and its graphics was stunning, better than need for speed. If phone can render AAA game at 60 FPS but struggles with some chat app, this chat app does not respect is users. I mean it's just a bunch of grey squares with some text and lame shadows. DOS on i386 could render it fast enough.
Sometimes I can't decide who's more crazy - me who demands adequate performance from simplistic apps or people who accept this state of things.
Ehhh that's a >5 year old CPU. I wouldn't describe it as "extremely powerful" even on a phone.
Anecdotally, going from an iPhone 8 to a 13 pro max was a night and day difference. Not just because the CPU was noticably faster, but because the 120Hz display makes everything more responsive. Sure you don't need that hardware for a chat app but unless some product guy forces the issue, devs aren't even gonna notice fps dropping below 120 because most of them don't use ancient phones.
Signal is still my slowest messaging app. It's not some subjective complaint about jank: compared to Telegram and Messages, Signal is much slower to load and share.
Aside: I asked - they, and their friends, don't give an f about twitter.
Every time you send you have to manually choose if you want higher quality over smaller size. You can't set a default option.
You can crop crop photos, but the crop handles don't work properly and often spring back if you only want to crop in one dimension.
There's an anti-pattern where there's a separate tool selection and tool edit UI on the screen at the same time, so if you are in a hurry and hit 'Save' without hitting 'done' (immediately above it) your changes are discarded.
But if you hit the discard button, you have to confirm it in a modal dialog. It's faster to discard changes by hitting 'save'.
There are pen and highlighter tools so you can draw on an image. but no shape tools, in case you wanted to blank out someone's face.
There's a text tool with some display options. But it's always in the middle of the image. You can move it around, but only after you have typed the text. You can pick color but you can't change the font. It's faster to make a meme online.
You can't use any text effects like italic, bold, or underline either.
Remember how there were going to be blurring tools built in so you could blur faces if you were an activist or journalist? Offered in Beta, never made it to production.
Well, you could just put a sticker over their face, using one of Signal's (extremely cringey) stickers, or by uploading your own. But you can't paste an emoji.
On desktop, you can drag a sticker over the photo with the mouse, and it gets a little '+' in a box to show you're copying the sticker. Then it disappears. Why? Because it was designed for a touch UI and only clicking on a sticker will actually add it.
These are just the problems with image handling/markup. I could make many more lists for other aspects of the app. The markup tools would be kind of superfluous, but it is useful to be able to do thm within the app...only they're implemented in a way that is a source of constant frustration.
If you bring this up with them on Twitter or so people will rush to say 'well Signal is for secure messaging, use an art program if you want fancy image editing lol.' The same people who rush to defend Stories and stickers as 'broadening appeal' while simultaneously saying 'nobody uses SMS anyway' even though SMS is ubiquitous in Signal's home market. It has degenerated into fanboyism at this point.
> Every time you send you have to manually choose if you want higher quality over smaller size. You can't set a default option.
I didn't even notice I wasn't sending high quality images. The setting they picked sends photos such that they look like original quality on my phone screen. If I want to view a photo on a high quality monitor or print it I'd send it some other way.
> There are pen and highlighter tools so you can draw on an image. but no shape tools, in case you wanted to blank out someone's face.
It's pretty easy to scribble it out quickly. I do use a separate app for sensitive redactions.
> It has degenerated into fanboyism at this point.
Fair criticism. My feelings about Signal are similar to my feelings about voting. It obviously sucks, but no one has figured out anything better after quite a few years.
I love this! I wish WhatsApp had such a toggle, since nobody in my contacts uses the "Status" feature so I just want to hide it somewhere.
I'm not sure if I'll use it much, but giving me a simple setting to decide for myself makes me much more optimistic towards this.
I'm guessing some folks won't like use feature because it's too "social media-y" (myself likely included) but as they say in the post:
- You can turn the feature off and you won't see other people's stories
- You can choose the audience and the max you can share it with is with Signal users in your contacts list
Thank you Signal team for giving the general public what they want and making it private.
WhatsApp did not really adapt it in privacy mind, to be fair. All metadata is unencrypted.
Meta harvests your contact information, intervals and time when you message specific persons. Often, this information is more interesting than the message content itself.
Pretty sure both work the same way regarding metadata. Think about it: if Signal didn't know that A was messaging B, how would they route that message to B's phone? A has to be able to find B's ip address someway. B can't broadcast its ip address to all the Signal users -- that would be a huge security hole.
It probably works like this: 1) A sends encrypted message + B's phone number to the server 2) server looks up the ip address for B's phone number 3) server routes the message there.
Also, both WhatsApp and Signal hash the contacts data the same way. Signal does seem to go a bit further, however.
WhatsApp's implementation: https://www.whatsapp.com/legal/information-for-people-who-do... Signal's implementation: https://signal.org/blog/private-contact-discovery/
They don't, that's covered pretty extensively in the many technical writeups of various Signal features. It's one of the main value propositions of Signal, that it doesn't work like most secure messengers especially when it comes to metadata.
There is no need for signal to know because their servers are not involved to transport the message but only ip routing infrastructure in between and of course the two parties. That's P2P
It means, that if the contact list contains numbers which have not accepted WhatsApp ToS, their content is stored only as hash. When the user starts using WhatsApp, their number and hash is being mapped.
Vaguely described as
> Each cryptographic hash value is stored on WhatsApp’s servers, linked to the WhatsApp users who uploaded the corresponding phone numbers before they were hashed so that we can more efficiently connect you with these contacts when they join WhatsApp.
Which means that WhatsApp knows the numbers of the WhatsApp users, and how they interact together.
Signal does not know numbers or how these contatcs interact.
It is described here [2]. Number is only needed for creating the unique hash. Server knows only the recipient, not the sender.
[1]: https://faq.whatsapp.com/423109552047857/?locale=en_US&refsr...
> It is described here [2]. Number is only needed for creating the unique hash. Server knows only the recipient, not the sender.
Signal does know everyone's numbers as everybody is logged into a Signal account on the server end (this is how your client fetches messages for your number). That same account and IP are also used when you send a message.
On top of that fact, sealed sender has been known to be broken for some time now: https://www.ndss-symposium.org/ndss-paper/improving-signals-...
In theory, B could publish a new public key as identity per target user.
I see two main problems: First, push notifications do require the server to actually identify the user and second efficiency: The client would like to maintain a single long connection instead of many short lived requests with pseudonyms.
Of course there would still be some timing patterns …
Worth reading.
And all the rest of the data too, for all intents and purposes.
After all it is Meta that provides the keys, operates the network, and controls the closed source apps. Also, it is precisely Meta's type of behaviour that warrants encrypting personal data in the first place.
1) Enable daily backups in Signal
2) Set up Syncthing to automatically send these backups to your laptop/whatever.
3) Profit.
Is there any solid evidence for this or are we just believing what Facebook says?
WhatsApp's APK files have obfuscated code. A few years ago they forgot to obfuscate a file and they got exposed.
Not to mention so many severe vulnerabilities discovered in WhatsApp every now and then.
People who really think WhatsApp's claims about E2EE are true and it's making them safer or private, are trusting Facebook too much.
Discovering you're not limited to sms was nice, when now you have to have an aside - "hey, have you ever heard of signal?"
1) Spam (~40%)
2) Transactional messages (~40%)
3) Conversations with old (45+) relatives (~15%)
4) Conversations with people I barely know (parents of kids' friends, people responding to a web market listing, that kind of thing) (~5%)
Google Messages (the default SMS app on newer phones) uses RCS if available and overlays E2E encryption on top using the Signal protocol.
Most people will use the messaging platforms that they need to have installed to get through their days. It's nice, ofc, to have friends who are privacy enthusiasts - but Signal main goal has always been to go beyond that group.
but you are right it doesn't have much use for children
Once my immediate family is out, I expect it'll be a domino effect with my extended family and friends -- those of us on Signal will have fewer and fewer reasons (ie, individuals in our graph) to use it. As much as I'd like this to not be the case, I think it will be. A smallish percentage of my contact list was on Signal, but every few months, another few people would join. I expect this trend will reverse.
my guess is that carriers/telcos offer unlimited SMS because they can data mine and monetize the shit out of it
also most people are still somewhere at the level of "the Internet is Google Chrome"
Will be a lot harder to tell people to switch now.
People have multiple apps for their social networks, and are completely fine with them. Snapchat, Facebook, TikTok, WhatsApp, Telegram. At the end of the day, I think it's just an excuse. They don't want to install Signal because they follow what others do, and it seems like others are not on Signal.
Instead of saying: "Install Signal, it will be your new SMS app", if you said "What? You don't have Signal? That's the new thing man", I'm sure they would try it. Then realize that they don't have contacts there, and uninstall it (because they reaaaaaallly need to save those 6MB badly on their phone, for some reason).
People don't use what's best, people use what other people use. They don't want to think.
It's similar to how it's good if more people use Tor for all kinds of activities as it doesn't immediately label you as suspicious just because you use Tor or Signal.
edit: ah, they announced recently that they are removing SMS support in Android. The reasoning is solid IMO, I've accidentally sent insecure messages before.
For anything else, using SMS is like using Notepad to write books. Many better alternatives have come through in the decades since that tech was new.
It feels very weird to have both a very good end-to-end encryption (the Signal encrypted messages) and a very bad system (SMS) together in the same app. People should just move away from SMS, it's not like it's hard.
All that being said...
I still trust Signal's Stories implementation over any other. While I believe they could have competed with SMS-capable apps like iMessage, Google Messages, and Samsung Messages, if pivoting into WhatsApp/Instagram/Snapchat/TikTok territory is what they'd rather do, then I believe they can execute it well.
Actually, there is an RCS API.
However, Google restricts its use to themselves and specific OEMS only. IIUC, that's currently only Samsung[0].
[0] https://www.xda-developers.com/google-messages-rcs-api-third...
IIUC, the RCS API is not part of AOSP[0], and as such, not part of LineageOS. As such, I believe the answer is "no."
Google has not provided any public API for RCS, and they control the ecosystem fully. If Google wanted other clients to use RCS as a platform, there would be public APIs that Signal, iMessage, Textra, Facebook Messenger and other SMS clients could integrate with.
Come to think of it, I'm having a very hard time coming up with any sensible use case for using Signal over text message. Presumably both sides still need Signal for the encryption to work, so what's the point? Might as well use the internet to send the message. The only scenario I can see it being useful is when you have GSM, but no internet connectivity, and that's rare these days.
Did they not see any value in signal over SMS? Didn't you have any group chats?
Thing is, I have all of 2 close contacts who use Signal. The rest use the default messaging app on their phone. So I already had to accept the fact that most of my texts were non-encrypted while I continued to try to persuade people to install Signal. Which was easier to do when it could conveniently replace their default messaging app and give them better security and privacy without any sacrifice.
But like them, I also have zero interest in using Signal to text all of 2 people and a different messaging app for everyone else. As much as I want e2e encryption for my texts, and would like SMS to be universally replaced by something secure, it's not like I text enough (or even use a phone enough) for my texts to be a particularly large attack vector in the first place. It would be way more useful to get MFA codes sent through Signal than it would to have my close contacts switch (and they're not going to anyway so what does it matter if I'm the only one who uses it?)
2) The inconvenience factor. I don't really like smart phones and would live without one if I didn't need one for very specific purposes. Being able to text close family and friends is one of those specific purposes. I have zero interest in having to juggle different text-ing apps for different contacts.
I should also add that I'm way more concerned about
a) spyware that comes pre-installed with phones that sends data to 3rd parties that have bought it
b) malware (I don't install many apps for this reason, and I like to use FOSS software for the same reason)
b) being in control of a device that I own (same reason I use Linux on my desktops and laptops)
I'm less concerned about SMS messages being intercepted, except for things like MFA codes. So of all the "contacts" that I would like to use Signal, it would be situations where the content is security-sensitive, which [unfortunately] currently accounts for virtually 0% of e2e encrypted messages coming into Signal.
Schedule time in your calendar for helping family with their "lost" SMS. At least at the moment, Signal seems to keep SMS separately from other apps. Uninstalling Signal will probably make any archived messages dissapear, at least temporarily.
No backups, no drag-n-drop or even pasting support for many things on Mac and iOS, no list of links in chats, no jumping to the context where a media was sent, such an non-native app feel overall are just top-of-my-head annoyances that make Signal a very mediocre chat experience.
Which is a shame, as I share and support most ideas and ideals of Signal. But I so rarely see Signal as a chat app improve, it angers me.
- [0] https://support.signal.org/hc/en-us/articles/360057625692-In...
Stopped recommending Signal because of this. Seeing stories, stickers, and crypto payments prioritized over basic data integrity makes me sad.
For a service like "messages that the receiver can read offline but the sender can later delete [or that auto-delete after 24 hours]," I'm curious to see how they handle the UI when the threat model is harder to defend against cryptographically, because it depends on software that isn't acting as a user-agent. Are they worried about people running rogue clients that save every message (or about screenshots?)? If so, how do you do a good job communicating to the nerdy/paranoid user that deletion is not guaranteed? Or does everybody already understand that auto-deletion is best-effort and shouldn't be treated as on par with the strength of assurance that Signal provides for privacy?
No, but this is what we should teach. Even "best effort" is misleading. Auto-deletion should be considered a UX feature that only affects your own experience, not those you talk to.
That said, in a high trust relation you can assume that auto-deletion is best effort, same as with your own devices. It should be seen as "this is a hint that helps your peer to delete messages, so that they don't stick around for everyone's sake".
The cool stuff about Signal is what happens under the hood. They don't want a special identity as a "private messenger"; they believe all messaging should be secure.
Getting that backup off the device is yet another manual process for most users they need to think about.
Compare this to Telegram: user doesn't have to do anything.
Compare this to iMessage: user doesn't have to do anything.
Compare this to WhatsApp: user just needs to click agree.
The last two even save backups in an E2E encrypted fashion unreadable by servers.
In any case, I actually prefer it the way Signal does because
1) I don't have to sign up for / rely on a cloud provider,
2) if need be, I can decrypt the backup on my own and export it to some other format.
> then they only do backup manually
Wrong. The backup can be done automatically (i.e. every day).
You might say 'but they don't want to make people less secure, people will get the wrong idea!' But they do this already, in ways that are much worse than allowing the user to make a security decision for themselves.
You can change a setting to prevent screenshots inside the Signal phone app, so you can't take screenshots. Your conversations are now secure, right? Nobody can take pictures of your disappearing messages! WRONG. You can turn on that feature and I can still take screenshots all day, including disappearing messages that you send to me.
Likewise, Signal can't tell if you're downloading pictures or copying text I send to you. You could be backing up everything - my only 'assurance' is that you probably aren't doing it because it's inconvenient.
You can change disappearing messages timer to anything you want! Great! But the change of timer is itself a message. So if we are arrested and police get into one person's Signal, they can see when disappearing messages were turned on and when the timer was lengthened or shortened. Sure, the messages disappeared, but what were you doing on August 23rd at 7:39pm that made you change the timer to 10 minute4s for 3 hours? We know where you were because of your phone's IMEI, I guess we will tell the court that you were trying to cover something up during those 3 hours and charge you with obstruction of justice.
I have asked them to change the latter behavior repeatedly, explaining why it could be a problem for users, and all I ever hear is 'good point, we'll look into it' even though there's no reason that information should be stored.
Your latter example is also a security concern they can’t address. A jurisdiction that allows a message about a settings change being used as a basis for obstruction of justice can rule the use of signal as the same (though I do agree that former is problematic on its face).
I dont know the ins and outs of the problems with backups, but it doesn’t take a phd in cryptography to envision a case where your settings about backups open all your contacts to automated dragnet surveillance. In that case it doesn’t make sense for a single user to downgrade everyone else’s security settings.
The disappearing message timer history could absolutely be mitigated by simply not retaining that information or timestamping it.
If you could export/back up single conversations, you would have much more granularity than exporting or backing up your entire message database. Other people could also get a message that the conversation had been exported. there are lots of cases where you might want to do this by mutual agreement, but it isn't possible.
C'mon, don't bs us :)
Example: I am running out of space on my phone. I look, and see Signal is taking 4gb of space. But I would like to preserve a lot of that media. So I buy a mini-SD card and install it in my phone. Yay! Now to turn on Signal chat backups!
Oh, but the backups are hardcoded to a location on your primary storage that you can't change. so even though I have 126gb of free space on the SD card I installed, I can't back Signal up to it and I am still running out of space.
My only option is to try removing every other app I have installed, and hope there is enough space reclaimed to perform a backup, which I can then copy off my system so I can reinstall my apps...WTF.
Meanwhile there is no way to back up a single chat. You can archive it, but that just removes it from your Signal home screen, it doesn't actually create an archive of any kind. And there is no way to back anything up on desktop.
This isn't a feature, it's an antipattern.
Backing up to the same device on which are running out of space is an extremely obvious problem, to which the solution is to just ask the user where they want the backup stored instead of deciding for them.
In the beginning, it might have been an oversight. Now moxie is just making seriously misleading arguments on behalf of people he doesn't know to make their service worse.
What are you referring to? An option to choose your backup location got added two years ago. It works on Android 10 and above.
https://github.com/signalapp/Signal-Android/commit/ee3d7a9a3...
This means:
* Backup must be automatic.
* Backup must be done off device.
* Backup must be common enough that messages aren't lost.
* Restore must be available to person of average technical ability.
* Restore must not require a person to remember typing in a 20+ character pregenerated number they probably lost in last 2 years of having Setup signal.
This is the bar other messaging apps have set.
It's also funny how demanding on use of phone numbers, shoving in crypto currency and demanding everyone to use out-of-date Electron app is somehow fine, but making backups user friendly is suddenly a massive "security" issue.
This is the BS security theater I despise at Signal. It's the software equivalent of having every single airplane passenger take off shoes.
That's probably your answer. I don't know anyone who uses a mini-SD card. The last time I bought a phone no phone I considered had an SD slot.
Nobody was asking for stickers, stories, or crypto. Those things aren't cool.
Ultimately there was no shortage of boring, cryptographically-secure apps. Signal is filling demand for an app that is both secure and fun to use.
Neither was signal taking your contact list and uploading a copy along with your name and photo and storing that data forever in the cloud. Neither was refusing to update their privacy policy to reflect their new data collection practices. A company that promotes itself to whistleblowers and human rights activists and then lies to them about what data they collect and keep is highly unethical.
None of this inspires confidence in Signal as a private/secure messaging service. I've moved away from it. I wish them luck as a social media platform.
It seems incomplete to not mention that that data is end‐to‐end encrypted, and that name and photo are optional.
I've tried snapchat and Instagram stories, and I hate that the messages disappear with time. It seems counter-intuitive for an asynchronous communication method, and that doesn't even count how it always feels like another FOMO marketing gag to keep you engaged with the app.
Just let people delete posts (and really delete them to boot).
Of course it still has all the usual social media failings where it is used to make the senders life seem more exciting and fun than it really is but I see the point of having the option.
I especially like signal’s groups implementation. I have a couple of large group chats where I am happy to share my day with people but it’s not important enough to notify everyone’s phone and it doesn’t matter if they miss it.
See - that's the part I don't get. Photos, to me, are not ephemeral. They are valuable, even if you don't think they are at the time. I've lost too many photos because I considered them to be ephemeral, and I regret that loss because I now only have vague memories of the events they captured. My only remaining memories of some of my oldest friends who are no longer with me are captured in those "irrelevant" photos.
Future you will thank you for keeping photos of your friends.
To use fear of missing out to cause people to check the app at least a couple times a day. It's an engagement hack, and the main reason I dislike this feature wherever it appears.
Of course, you could allow customization of the time interval, but that adds another layer of complexity, and other platforms that use stories have already pretty much standardized on a timeframe of 24h, so it's easier for platform newcomers to understand.
But hey, I'm an old, biased, grumpy man. They're taking away SMS (which was what allowed me to get it onto my family's phones) and shoving TikTok in my face instead. I'm displeased by this and looking for things to pick on.
I'm glad they're giving consideration to people here, but forcing this change on people won't cost them as much as forcing people to the cloud and dropping SMS support did.
still unsure how this decision made it through.
As a growing company, I don't know how they expect to get away by alienating their staunch userbase. Even Meta made concessions when Whatsapp userbase revolted against upcoming changes.
In the meantime, Google have revamped their messages app, which of course continues to support SMS.
Just for fun now I installed it to use as my default SMS app after this whole hullabaloo with SMS removal, I use Johann's fork, so I am just curious how long it will keep working as Signal messenger with no APK expiration. Though I am definitely not telling anyone I am using it, tried to isntall it on wife's phone, never received verifying message or phone call, no matter how much I tried and mind she has the regular phone with almost stock ROM, while I use Lineage with no gapps.
I will ditch it in a second, if there will be other IM with SMS support other than Facebook Messenger and Skype (Lite), ideally some Matrix client with SMS support, that I could promote even to my family.
- Edit previously sent messages like Telegram, Discord and Slack lets you do. I'm so damn tired of a big ugly "This message was deleted" if I try to fix a typo/DYAC
- A better way to sync up clients, so when I log in on a computer and verify with my phone, it lets me sync over some or all of my message history.
- A way to set the expiry time for your sessions. I appreciate that they want you to not stay logged in forever if you lose or forget a computer, but I'm so damn tired of having to re-log in on my desktop pretty much every time I try to use Signal there.
- Faster message import when starting desktop clients. Or smarter import - e.g. prioritize the top of the chats list and throw the rest on a background queue instead of hanging the UI until it's done.
None of these are huge, but they combine to make it just feel more annoying to use Signal than their competitors. I really like Signal in principle, but I wish I didn't need to give up UX and QoL-nicenesses that I've gotten used to from other apps in order to use it.
Linked devices expire after 30 days, so you might be right at the edge:
https://www.reddit.com/r/signal/comments/t6i2ez/when_do_link...
Personally, I would like a long press / long click option to switch to "send and enable disappearing messages." It's a small thing, but it would make it easier to move back and forth between archived and unarchived conversations.
Also no text formatting, how come I can't just use markdown in 2022?
I'm in groups with a whole lot of other people including a few who keep up with modern social media stuff, use TikTok, use Instagram, et c., and zero of them use the Status feature or Stories or anything but messaging. For us it's just ICQ/text with better media embedding (but still really bad, somehow). Some of us regularly use similar features, but only on other platforms, never on WhatsApp.
Is that unusual, and these are in fact much-beloved features by a good chunk of the WhatsApp user-base?
Also, why does a secure messaging app need stories? Is this part of a trend to make signal more like social media, or to balkanize the web?
I think Telegram has something like this because often on the desktop browser I'll want to follow a link to something and it wants to open it in telegram. No thanks!
From my experience, they are a non-optional part of socializing. By my estimation, my social and professional networking has materially suffered by not using Instagram or a Snapchat for most of my life. I wish this were not the case.
Stories are popular because a lot of people have uses for them, but it's hard to articulate why they're useful. I'll try to explain:
A website/blog wouldn't be better, because (1) a tiny fraction of people know about RSS, (2) a tiny fraction of people know how to make their own website/blog, (3) a website/blog is not as well-suited for on-the-fly updates like stories, and (4) absent RSS, nobody will check all $n$ of their friend's personal blogs as often as they open their messaging app.
Furthermore, (1) stories are not crawled by default in an easy-to-access way (like Google or the internet archive), (2) the 24-hour time lock leads to different kinds of posts
I've found with experience that whenever you share something, it needs to be deliberate to chosen people, otherwise it deteriorates into popularity seeking and least-common-denominator feel good spam. I much more prefer the "take photo/video or find a meme, send to specific people each time" flow. With snap, it takes a few seconds to choose, because contacts are sorted by recency. This is the only part of snap I'm using, and it existed before stories.
Signal ended up somewhere inbetween, where you have to create a story (an imo unnecessary layer of i direction) and then add people to the story, which is minor from a tech perspective but huge issue for UX. It increases the friction for this flow.
I must not have much of a social life then, since I've apparently managed to go 9 years without having anything to do with them. Maybe I'm just getting old.
I feel like this should be a priority over more features because it's been asked for for ages and they say they're working on it.
Anyway, good luck getting Signal to federate with you until you have enough of a user base that they're losing users to your backend. They have zero reason to want to do this, and it introduces some privacy issues (what if your server doesn't respect deletions, etc?).
XMPP is just SMTP and some protocol addons on top. SMTP is just FTP with RFC 469 and others. Etc.
I haven't used but it is supposed to be a hardened version of signal.
Not that it supports SMS, but it _is_ a fork that uses Signal's servers.
After thinking about it, I actually don't mind it.
I am in a big (~15 people) group chat with my family. Often times someone will spam the chat with vacation pics or something they cooked for dinner. I don't particularly dislike that, but it seems like posting those pictures to their story would be a much better way to share. The audience would remain the same and it would still be private. The viewing process would just be much better.
The main problem is, and always has been, getting a bunch of iPhone users in the US to use any messaging app besides iMessage. Let alone having them post to a story within that app.
and the ever growing backups(!)
First of all, the older I get, the more precious memories are because frankly, I'm forgetting more and more and it terrifies me. I don't understand why something that was worth sharing today needs to be gone tomorrow. What if I was busy that day? What if I want to see it again tomorrow? What if I'm at a party three weeks later and want to show somebody your funny puppy photo?
Second, if you think about it, it's often the most casual, lo-fi and accidental shots that end up carrying the most authentic value. Quick snaps that you don't know are "last photos with" at the time. People pass unexpectedly; too bad all of the pictures of them were set to fucking evaporate.
Third, if something is truly not photographed with enough intention or effort to keep it around for more than 24 hours... was it really worth sharing in the first place?
Finally, it's super weird to me that people don't assume that anything downloaded or displayed can be captured. In fact, having something set to self-destruct in a day probably means that people are more likely to save a copy locally than they would if you just left it there.
Being able to interact with my remaining non-signal contacts was huge. Really going to miss it. In contrast they are now adding a feature I do not care about at all.
I'm glad that dropping SMS means nothing to you. But "i don't see how you can known signal in anyway" for dropping a feature sounds disingenuous.
It seems to me like this improves OPSEC for very privacy focused Signal users, but increases the barrier to entry for "casual" users who may not care enough to use a separate app for certain people, but may be convinced to use Signal for SMS.
All that said, I'm not sure how any of that actually plays out in the real world, or if there were that many actual users doing just that.
Lots of reasons recently to develop deep distrust for Signal leadership, and start calling into question whether the app is still legitimately private.
How about when Signal started storing people's contacts, their name, their photo, and their phone number in the cloud ignoring cries from their users that Signal should provide a way to opt out and bringing up security concerns, then refusing to update their privacy policy to reflect the new data collection meaning that for years now they've been outright lying to people about what data is being collected and how it's used. That was when I moved off the platform.
If you want private/secure consider looking elsewhere.
Already on it.
Just such a shame that after years of trying to convince friends and family to use signal, I now have to convince them to use something else.
Oh well, that might just be the natural circle of life.
This is the beauty of Matrix - you can change your client, or even your server and keep all your contacts!
They started storing user data in the cloud and never updated their privacy policy even though it's been brought to their attention. (https://community.signalusers.org/t/can-signal-please-update...)
The very first line of their privacy policy reads: "Signal is designed to never collect or store any sensitive information" which is a total lie. For someone like a human rights activist or a whistleblower a list of all their Signal contacts is absolutely "sensitive information". It really used to be true that they didn't collect and store anything, but it hasn't been the case now for years!
If this is the first time you're hearing about the data Signal is collecting and storing in the cloud that should tell you all you need to know about how much they can be trusted.
> RCS is coming, and it doesn’t play well with Signal.... and Signal can’t add RCS support because there’s no RCS API on Android. Honestly, the days of any third-party SMS app are numbered.
https://community.signalusers.org/t/signal-blog-removing-sms...
>There are three big reasons why we’re removing SMS support for the Android app now: prioritizing security and privacy, ensuring people aren’t hit with unexpected messaging bills, and creating a clear and intelligible user experience for anyone sending messages on Signal.
https://signal.org/blog/sms-removal-android/
So I think this "myth" will probably persist for a while.
Even if Android saw 100% adoption for RCS I'd still want to message my apple people via sms.
It doesn't look like it has anything to do with Signal's direction in particular, but rather the changing environment they're in. (Specifically Android/Google making things harder.)
Having SMS support as a workaround was huge for signal usability for me. Taking it away burns so much good will.
Could you provide a link? All I can find with DDG is a reddit post and irrelevant stuff and I don't feel like using Google.
> tor which is openly a project of naval intelligence
Again, do you have a source?
That's the first time I encounter these claims.
It's not like that with signal.
Not to mention that WhatsApp, even after having so many vulnerabilities and backdoors, is very functional.
They obfuscate the code but it's clearly to stop hackers from hacking WhatsApp users.
One key aspect to consider, however, is the fact that at the end of the day the feature requires code in order to work. Code can contain flaws. When working in encryption it's usually the less code the better, as it limits the attack surface.
It begs the question, just like with the introduction of their payments feature, whether the additional amount of code, which could realistically introduce new flaws, is justified by the benefit it brings to a platform that's main focus is private, encrypted communication?
To put it differently: Will citizens, dissidents and journalists in authoritarian regimes be benefitting enough from this feature to justify the additional attack surface its code has introduced?
For all the people still complaining about the SMS thing: I get it, at the same time, I don't. When I first installed Signal I was surprised and annoyed it wanted to be my default SMS app. What does SMS have to do with encrypted messaging? I immediately saw people would use Signal, send SMS, and assume they were securely messaging. Now Google is pushing https://en.wikipedia.org/wiki/Rich_Communication_Services which Signal can't implement.
The official announcement back then did not provide enough context, this here does https://community.signalusers.org/t/signal-blog-removing-sms...
Are they supposed to 'keep' people esp non-techies from using RCS 'by default' and make them use SMS? The app that cares so deeply about encrypted communication?
My thinking: integrating SMS into Signal was a dubious move to aid adoption. I could make the reasonable argument it should've never been done. With the arrival of RCS and SMS falling by the wayside more and more, it just can't be justified any further.
Sucks for adoption? Maybe. But honestly, Signal can't want people to use SMS, right?
While I agree with most of what you said, it appears you are implying that RCS provides a security guarantee somehow that Signal is impeding. RCS is badly fragmented, mostly not E2E (except Google private E2E extension), and does not have Apple's buy in. Signal does clearly indicate that SMS chats are not secure.
Signal originated as ChatSecure- the encrypted SMS app.
This would be much more interesting to me with more options - namely: I'd like to be able to setup an untrusted client somewhere (Syncthing can do this, but its not a social app) which would archive the stream of content into a story in encrypted form for me, and let people with channel access recover it without keeping it fully cached on their phones. That way all those photos which I would like to keep would go somewhere where I could get them.
Obviously none of this is necessary, I do other things right now (Syncthing and not using inbuilt camera apps in applications).
We're back full circle. I wonder what's the new, next shiny thing that will attract people. Maybe Zuckerburg is not so crazy after all. If you've seen these TikTok videos 10-15 years ago, you'd think these people should be admitted to a mental institution.
I'd move to a forked client that supported that, TOS be damned.
Messages that self-delete after 24 hours is the opposite of what I want.
I know some people are not going to like it, but let's face it, this is a feature people use and now it'll be easier for friends and family to continue using Signal.
For example, I would like to be able to log into signal from multiple devices, which currently isn't possible.
So, I could imagine switching to something like telegram (even though less secure) or matrix (even though a little trickier for non tech users), both of which allow me to do this.
Personally though, I'm still using signal, donating, and have converted a few people, I'm just speculating here.
https://www.figma.com/blog/did-snapchat-succeed-because-of-i...
Main issue with current industry, is, the product changed eventually , but mostly for worse. As original makers have gone.
Universal solution, is, everyone should have ability to make their own social circle (think contact platform), with a federated protocol to connect with other's circle contact.
Everybody went back to WA after FB's stunt on retracting the privacy policy. I am back to square one on who all are using Signal around me. I don't think there is going to be a better chance than what we got with WA policy change.
Signal had the funding, they had the tech and folks. The momentum, people, media and even people like Snowden, Jack and Elon Musk were with us. They chose something completely different and irrelevant to what would've helped make Signal a standard. What is the point in having this now? Majority of the users who were going to use it are already back in WA. This feature will be used only by a minority.
Another fascinating learning from the whole journey was that a lot of "loud" privacy folks use privacy through obscurity (like security through obscurity) to keep themselves private. They jump ship when their tool gets popular. And these were the loud ones during the whole discussion in Signal forum with respect to Stories. With AI advancements and big corps, we need more folks in the privacy space using private tech. If we don't accommodate non-privacy folks as well, this will be a harder fight than it has to be.
Thank you.
If I am networking at a conference, I frequently exchange contact info by entering info into each others' contact app or sending each other a text. I'm sure I'm not the only one to do this.
It's one thing to tell two users that both parties are using Signal and in each other's contact list (contact discovery). It's another thing to encourage users to broadcast messages to all of them (via Stories, and the default share setting is all contacts)
In summary, while I'm neutral on the Stories feature, I think the implementation/rollout has been clumsy.
If you had asked your friends to get a Matrix client instead (eg. Element), at least you'd be able to move to a new client [2] if you didn't like the direction it moved in - and you'd still have your group chats and keep your contacts because it's federated.
Unfortunately you're now stuck with stories (or maybe crypto payments one day [3]) because Signal doesn't federate, and likely never will, and the amount of effort to ask your friends to move _again_ is just too big.
This is _exactly_ the argument I make when friends ask why Matrix over Signal. I'm exhausted of picking up and moving again.
[1]: https://signal.org/blog/the-ecosystem-is-moving/ [2]: https://matrix.org/clients/ [3]: https://www.xda-developers.com/signal-crypto-payments-featur...
Many people signed up after the new WhatsApp T&S debacle, but Facebook played it like a boss by delaying the change and draining the news cycle and they won.
Almost no body uses signal, I have chat group of my friends on signal, and I'm really thinking of moving it to WhatsApp, so they actually see the messages instead of it being 20 messages from me and 1 from the others.
Its not that they don't have signal installed, they just never open it, I use it as a video/voice call app and it works well, but messages? Its a PITA to get people to actually read them, especially since many of them are complaining of notifications not working.
I like the stories feature, especially because its totally encrypted, but its basically useless as almost no one in my social circle uses Signal.
Everybody wants to be Telegram it seems.
its mainly a Secure messaging app not an SMS client
And Telegram is the worst in terms of security and privacy.
I think a major contributor to this was that Signal got normalized early as the venue for a large group chat started by some friends who moved to my neighborhood years ago. Over time this chat became a sort of neighborhood forum where people advertised open rooms, traded goods and services, and exchanged news and gossip. And because it was on Signal, everyone installed Signal.
I know I'm in somewhat of a strange bubble, but I just want to underscore that this kind of world is possible. The adoption fight hasn't been lost yet, especially since some cracks are starting to show in the incumbents' moats these days.
Now I dread the day when they might decide to make it so that you won't be able to opt-out. Why can't we have nice things?
How many followers on Signal do you have?
I feel like it's just out-of-touch product managers who see everyone else doing the stories thing and blindly aping it cause it's the thing to do.
In reality, the only place people seem to use stories is Snapchat, Instagram, and seemingly some people post to Facebook stories but I think it's mostly cause of the toggle in Instagram to cross-post to there.
I was honestly excited when I saw the headline, not because I have any intention of using stories myself, but because my friends have repeatedly tried to explain to me why they use stories on Whatsapp and Snapchat, and I have some hope this will make Signal more attractive to them.
I feel the same way about stickers and the Giphy proxy, both of which are features I would never have asked for and was initially skeptical of, but that have wound up being widely used by most of my friends who use Signal.
As of now, Signal still has no concept of followers. My stories are at most only visible to all my contacts on Signal. In my mind this is a big difference between all the other major platforms with stories.
Though I'm not sure how many will actually use Stories. WhatsApp has something similar as well but I have never seen anyone among my contacts use it
Still really mad about them dropping SMS support. I'll be deleting it when that happens.
Did its SMS feature support encryption somehow? Because sounds like a bad idea to include unencrypted messaging in a secure app: it's a giant footgun.
'We're taking features away for your security' is a lowkey way of telling users that they're idiots who can't be trusted to operate their own devices. This is really pretty offensive to the people who have been evangelists for Signal for the last 6-7 years.
Settings > Notifications > Notify when... > turn off "Contact joins Signal"
Really, is it so hard to think about both sides of this equation?
I definitely do not expect Signal to drop encryption by default in any feature though. That's their fundamental value.
At least they realize we want a way to avoid stories.
I previously commented something much more negative and snarky. I regret it.
Please don't pick the most provocative thing in an article or post to complain about in the thread. Find something interesting to respond to instead.
I wouldn't write this today either - it was a much, much smaller HN and a smaller nerd internet. Although amusingly enough, the Rails release notes were edited after that showed up on HN but I don't think Signal is going to give you even that satisfaction, sadly.
> In the past years, stories have emerged as a new way to communicate, with their own unique purposes, norms, and idiosyncrasies. Ephemeral, low-stakes, and image-heavy, people use stories to share updates about their lives without the expectation of a response.
> Sometimes you just need a chill way to show your crush that you went to a very cool concert, without having to text them. Stories let you share your life with a select group of people in a way that doesn’t result in a new message notification. They give you a place to tell the kinds of jokes that work better in a sequential image or video format, and to share what you’re doing without the pressure of a conversation.
> Stories have emerged to serve these specific functions and others in the broader communications landscape, and many of us have integrated them as one of the ways that we connect with one another. That’s why they have a natural place in any messaging app, including Signal.
> Stories also happen to be one of the most common feature requests we receive from all over the world. People use them, people want them, so we’re providing a way to do stories privately. And without having to wade through a sea of ads.
Thanks for calling me out here. It goes to show that even when you feel very grumpy about a change, you shouldn't resort to unfair arguments like I did.
I would love to hear tptacek's views on this.
No, he worked on Signal for so long that he probably just wanted to take a break to work on other passions too - he's still on the Signal Foundation board (https://signalfoundation.org/)
> Why is a secure messenger adopting the appearance of social media?
I'd argue that Stories (or equivalent) is nowadays a standard feature in many messengers. To more directly answer your question no - Signal is missing a key aspect of Social Media: discovery. Stories is pretty much equivalent to share a picture to a group of people. You can also easily disable the feature in settings.
> Doesn't this work explicitly against the entire claimed reason for not having an account system?
I'm not sure specifically to what you refer to but in general: phone numbers is still the primary way to find new folks, but they're working on a username feature. They will still use phone numbers for simplicity as "account" but again, Stories is simply a new interface to share pictures with your contacts.
"Standard" implies a lot, and definitely there is nothing about "enabling two-way communication between willing participants" that requires "make available a video on the screens of my contacts in a non-directed way" to be part of the offering.
Signal is not social media. That is not its intention, nor its purpose, nor even its design. It is a messaging service. We already have a discovery feature in Signal: using your contacts, you can see who has Signal installed or not.
This feels like bikeshedding to the max, because it is.
I mean, it is now since they just added a stories feature. Sorry that your view of the product doesn't align with Signal's.
You're also using the word bikeshedding in a way unfamiliar to me. I use that word to mean intense debate about inconsequential changes that don't matter, like the right color for a bicycle shed. Which ofc is ludacris because there is no right or wrong color for a bicycle shed. In contrast to that, there are absolutely product decisions about the app that are material to its desired and undesired functionality. If signal decided to change the functionality of their product and stop encrypting texts, would discussion about that be bikeshedding? Why then, is this change in functionality not of similar concern?
Personally, I think call quality and server reliability with respect to private messages are more important for a service that is explicitly (and, until this change, exclusively) about private messaging, especially considering recent outages.
If Signal changed the encryption protocol to an insecure one, or simply removed it, then they are fundamentally altering the promise of the app vis a vis its core technology, ie, the essence of the provided service. Obviously that is analogous to the foundation of a house, not to the shed in the backyard.
Good point - I agree, should have phrased better.
> We already have a discovery feature in Signal
Another point I should have been more clear. I agree that contact discovery is ... well, discovery! I think what I meant is that right now you can only discover folks you already know (i.e.: have the number for) but you don't get recommendations.
So yeah... I'd say that one of the major points distinguishing Signal from a Social Media (at least one of the definitions of) is the lack of recommendations of new people to follow or things to discover. Signal in that sense is a communication platform.
[note I mean Signal the app not the company]
> bikeshedding
You mean if Signal is or isn't a Social media? Or it's run by the feds?
I mean I replied to the above company with a serious comment but I thought the original one was not particularly useful to any discussion around Stories per se.
* Doesn't require users to provide a phone number.
* Doesn't use centralized servers.
Hopefully Session will stay legit for a while. Just when I get most of my contacts to use Signal, Signal moves to embed a cryptocurrency in the app and starts pushing Storytime.
https://github.com/opendocument-app/OpenDocument.droid/issue...
Per F-Droid's definition of "the upstream source code is not entirely free":
https://f-droid.org/en/docs/Anti-Features/#UpstreamNonFree
This seems to be a case of "damned if you do; damned if you don't". Session relies on Firebase to get faster notifications from Google servers. This can be disabled in the applications preferences but changes the behavior from push-notifications to polling Session's decentralized messaging network, which makes messages notifications slower.
https://getsession.org/faq#push-notifications
For the sake of clarity it would be nice if instead of making such a vague pronouncement, F-Droid would specify precisely what about the upstream source code is not entirely free.
https://forum.f-droid.org/t/the-upstream-source-code-is-not-...
Edit: whoops - this one was the earlier post. We'll merge everything back hither.
Edit 2: je suis idiot. Will fix.
Edit 3: I think this is correct now
And then once those people drop it, you have to do so as well if you want to keep talking to them.
Any day now (for the last 5 years)
I think that "only criminals use this app" is always going to be used on anything that uses encryption by folks that are against encryption (usually governments for some reasons...). SMS or not is always going to be there. I don't think that having secure communication apps intentionally offer insecure communication is the right way to solve this. SMS was a legacy feature for Signal that just got removed now.
> adding stuff that has absolutely nothing at all to do with messaging?
Stories?
> Did a federal agent start running the show with the sole mission of destroying the entire app?
I just replied to another similar comment, not sure if it's the same person or not... but then I'd say...
Use Telegram! It's unencrypted by default! Use WhatsApp - unfortunately encrypted by default, but at least Meta will collect so much more metadata than you can keep track for. Use iMessage - It will upload your encrypted chat and the decryption key to Apple servers for you.
My point saying "it's the feds running it" without proof like that is not the most constructive conversation - Signal is by all accounts one of the most secure and private (not necessarily the same as anonymous) messaging apps out there with no clear competitors at the same level of privacy and security.
You mean the messaging service with no SMS support and an assumption that criminals are the main users?
Signal was great because it gave encrypted messaging to people who didn't know they needed it. When you take away SMS support, the only people who use it are people who know they need it.
They can paint that thing in whatever color they want. I'm still not using a messenger with an algorithm developed next door to the NSA headquarters.
OTF gave Signal 3 million USD: https://www.opentech.fund/results/supported-projects/open-wh...
The OTF was created in 2012 as a pilot program of Radio Free Asia (RFA), an asset of US Agency for Global Media (USAGM)/CIA, which is in turn funded by US Congress. The algorithm for signal/whisper was developed next door to the NSA headquarters in Hawaii.
All of this is public information at the moment.
Don't know if ALL OTHER messaging apps are better, but would at least prefer a messenger not sponsored/blessed by well-known spy agencies.
So far you have provided zero evidence for your statements and yet demand others for them.
Good approach.
Trivia: What percentage of open source end-to-end encryption algorithms were developed by coincidence next door to the NSA headquarters?
By contrast, I can't find any significant security criticisms about Signal's double-ratchet algorithm, nor anything that would suggest that some sort of bad actor is pushing it to become standard. It seems to me like it was widely adopted because it's a solid end-to-end encryption algorithm.
I also couldn't find where the algorithm was developed. If you have any sources for this I'd be glad to read it.