Signal is for everyone, and everyone is different
signal.org
signal.org
I really hope they reconsider their decision.
Security when possible, but with a trivially easy-to-use fallback was what let me get others on the platform.
I really like Signal, but it's a niche thing for me. I have two friends who use it, familie is all on iMessage or SMS and SnapChat, that's it. Signal would make sense for those on SMS still, but convincing them to switch is going to be an uphill battle. Those on iMessage, why would they consider using Signal, when everything just works.
The very fact that you're commenting on HN probably means you're technically-literate so probably it does not apply to you.
But I am also curious about that sentiment about not realizing iMessage isn't SMS that. I heard it repeated a lot. I have not met a lot of people that share this sentiment and have not heard of research around this specific topic. So I'd love to put some data behind it.
Disclaimer: I pay Signal monthly (happy to do it in exhcange for no-bullshit app)
https://en.wikipedia.org/wiki/Signal_Foundation#History
EDIT: Hopefully they made money on that scammy alt-coin too.
Imho Signal is great for novice users. I even have my mom on it.
Fun fact, they used to be. When I started using Signal that's how it worked.
Sadly that's exactly what every phishing attack wants you to do.
If the only thing keeping Signal on your phone is supporting SMS then you don't need Signal.
They're basically kicking me out as a happy user. I would love to continue using Signal, not sure what the motivation for this change is in the first place.
First thing, I am not an activist like Moxie. I think end-to-end encryption is a good thing, but it is not on top of my list. My primary reason for choosing a messaging app is to actually be able to message people, then there is the app general quality (fast, light on resources, stable, with the features I need, ...), encryption comes third. Signal had all three, SMS is almost universal in my country, it looked like a decent app that holds it own against dedicated SMS apps, and you have encryption as a bonus, nice.
With SMS gone, it lost #1, I don't have any friends who are on Signal that can't be reached by other means, so that's enough to let it go.
So I exported my SMS, and for some reason it exported it all as both SMS and MMS, making a huge mess that took a while to fix. In the process, in order to recover my data, I took a peek at the code, and while not terrible, it wasn't the best, for example, I stumbled upon some dead code. So with data loss involved, #2 is seriously compromised. Other issues include Signal "eating" SMS, not allowing them into their standard location (probably deliberate, but a negative for me), and for the final releases, SMS acknowledgment not working. I had trouble importing SMS at first too.
And finally, while it has top notch encryption, and probably a good choice for targeted individuals, I consider the "X is on Signal" notifications questionable with regard to privacy. Just because we share entries on our address book don't mean we want to get in touch. In fact what if the reason I have someone in my address book is to block him? I know it has caused major trouble to someone. Also, when I first entered Signal, I was greeted by a scammer sporting the Amazon logo. Not a big deal, not the worst, spam is almost unavoidable, but it is another thing Signal don't protect you much against.
With SMS support, I tolerated all these little quirks, it wasn't so bad, but without SMS, then it is out. And I am also a little pissed off for that export mess.
As for why I also deleted my account. It wasn't in anger. Problem is, what if I uninstall signal and if someone I recently texted installed Signal? Most likely he would send his next messages via Signal instead of by SMS. If I didn't delete my account, the message would have been lost in limbo. By deleting my account, they will know I don't have the app anymore, and if they really wish to contact me, do it another way (ex: by SMS).
On any given day, I'm likely to use Signal, Whatsapp, Facebook Messenger, Discord, Slack, Matrix, and IRC. I'd like to get my contacts off a couple of those, but mostly not because it would reduce the number.
We are not used to companies being that nice to their user base when their business plans change.
Not dropping SMS would mean people getting annoyed at signal silently losing messages, as people use it to send SMS to which the recipient responds over RCS.
The "world" does not include iOS. In the USA, that's 55% of mobile phone users.
With that in mind, lets go back to their reasons here https://community.signalusers.org/t/signal-blog-removing-sms... :
1. RCS is coming, and it doesn’t play well with Signal. I once had a situation when I was sending SMS to one of my friends via Signal, but I wasn’t seeing any of their responses
Same will happen for iOS users. If Google/Android breaks SMS that badly for everyone I'll be dropping Google's Messenger. I expect most people would.
2. Proper SMS/MMS support is hard.
No, I've done it, it's not hard. There aren't that many API's, and they've been stable for yonks. Yes, it may cause support issues. In fact I generated one. I sent my wife an SMS, and it didn't arrive. I posted a support question. Moxie(!) responded: we just use the Android API to send the message. I looked at the source. He was absolutely right, of course (why did I doubt it). It was a Samsung bug in the end.
3. SMS/MMS has plenty of it’s own bugs.
Really? You are claiming the most used messaging platform on the planet is so riddled with bugs you can't support it.
4. Spam.
What? I will still have SMS. Everyone will. We will all continue to get the get the same spam. It will just come through another app.
5. Finally, Signal having SMS support gives a lot of people the wrong impression of SMS. They think that because it’s Signal sending it, it’s actually secure.
This where it clicked this was a marketing post.
After reading all that I still don't know what engineering justification is. I presume there is one - maybe it's the level of support calls. Hell maybe they plan to introduce a paid version that does support SMS. If they do and it's a few bucks a year, I would pay it and say "nicely played boys".
How such an obnoxious and intrusive set of features continues to exist baffles me. One would think that a self-proclaimed pro-privacy app would know to leave the user alone and to respect the user’s choice.
So no, Signal is not for everyone. Signal pretending to be for everyone is disingenuous.
You're a bit disingenuous in the way you seem to be handing out unwanted and unwarranted moral guidance based on simple questions people ask.
These kind of shenanigans are a good indicator of whether a product team is worth trusting or not, and whether they have any faith in their product decisions or not.
I miss the old internet where you only needed a username and a password.
> As stated in the article, not everyone has access to a phone number and not everyone can maintain the same phone number.
The article does not say that. I would argue that having a phone number is a very basic thing, and if you don’t have it, you are unlikely to have access to the Internet either. Phone numbers are a nice way to ensure you’re a human.
Requiring a phone number means it's not for everyone, period.
There was a post a few weeks ago about how homeless people struggle to retain their phones, going through a new phone every week [0].
Personally, when I travel, I don’t always have my US phone number available. If my phone is stolen while I’m abroad, I can’t get a new phone or recover my phone number until I return, which could be months later.
Signal is not for everyone and them claiming it is makes me trust them less.
Edit: Just tried it again, and I cannot register on Linux without a phone number. Here is a screenshot: https://i.imgur.com/WcnHBx1.png
I wish signal did something similar.
Edit: find the numbers here: https://fragment.com/numbers
It's probably affiliated with Telegram, I'm not sure.
Yep, but it doesn't have to be a real, publicly routable one. You can get one from Telegram without having to provide government provided ID like I have to for real phone numbers. See sibling comment.
But stories ffs. Having stories in a privacy oriented chat app feels like building an electric hummer and calling it climate friendly. The whole "stories" ux is short-video attention bait for viewers, and "get more data online" bait with addictive reward for uploaders. Just zoom out and look at what you're doing, perhaps some stuff is plain user-hostile ux and should not just get slapped a "organic" stamp. And yes, perhaps some users will have grown into the habit of using this thing. Maybe this isn't a reason for accepting everything.
edit: i get it, i'm screaming at clouds, at this point it's pretty clear that signal's position is quite consensual in its social-media and tech establishment critique. For one they actually are part of it and second they market themselves as "mainstream".. But still, every time they blog on how they're such good guys i'm getting triggered. It's nice they exist but they bow down to so much.
Unfortunately the 24h expiration period made it unusable; most of us have pretty good habits around screen time and frequently missed expired posts.
This sounds particularly tone deaf with them removing SMS support despite relatively vocal opposition. Signal made a one size fits all assumption, taking an extreme position that their users are just too stupid to tell unencrypted SMS messages apart from encrypted Signal messages, and so in the interest of "protecting the privacy" of their users, many are going to drop Signal entirely instead of enjoying the benefits of gradual encryption that Signal provided.
In my experience convincing friends, relatives, acquaintances to give Signal a chance only worked because it wasn't just another useless app on their phone that they would have to use just to talk to me, it was a useful replacement with clear benefits - they could use it to talk to anyone, but we (and anyone else they convinced to join) could enjoy encrypted conversations, inside of the same app.
Everyone IS different, that's why Signal is not for everyone, not anymore. It's just another app in the sea of communication apps and I don't see myself or any of the Signal contacts that I've onboarded sticking around.
I was fooled by the relatively open nature of the client, but ultimately it's still a closed, private network.
If your social circle allows this, push for a true open network.
They tried to justify their stickers, infra and stories but radio silence on MobileCoin.
That is literally why. They want you to remember the pin in case you need to recover your account.
Requiring a phone number means it's not for everyone, period.
How about a truly free, distributed network: Matrix?
How much are you paying for WhatsApp, Telegram, Signal etc?
For example: most people want to be able to back up and/or transfer messages to a new device (which can happen every few years) or sync to another device such as their desktop so that (gasp) they can see message history when corresponding with someone.
Probably half a dozen times in the last 5-6 years I have lost all my Signal messages.
Most recently, I did a full, encrypted backup of my iPhone to my Mac (which has FDE via the T2 chip) prior to doing a device wipe because it was starting to feel sluggish. All the devices involved have the best security of any handheld/portable computer commonly available and the data was DOUBLE encrypted on my Mac. Every other app's settings restored fine....but not Signal. They exclude their data store from the backups so I lost numerous messages, photos, etc from a couple of friends. Those messages are gone forever.
I can't use Signal for any transactions with other people, even something like a simple Craigslist deal, because there's no way to export messages to provide them as evidence, other than to take a screenshot. So Signal is also useless to lawyers and business executives, too.
When you ask them why they don't support the various things like exports and syncing, there's a lot of general, paranoid hand-waving about how if you're a reporter or human rights worker in a third world country those features could be abused...like said reporter or human rights worker wouldn't simply be tortured until they unlocked their device...also ignoring that it should be perfectly possible to allow the user to choose (gasp!) whether they want to enable such features. Ie: let them decide for themselves what their risk profile is.
You know why their claims are bullshit? Because they've never implemented a duress password that unlocks the app but only shows messages from, say, friends but hides messages and contacts you don't want people to see.
When I mention syncing people start shrieking about cloud storage this and that...which you don't need to sync two devices, as demonstrated by syncthing, magic wormhole, and a slew of other programs that are device-to-device with, at most, a zero-knowledge coordinating proxy, which Signal already has.
So can I please be allowed to back up / export my messages and call history? Can I please see my message and call history in the desktop app? Would you please support backing up my message history to another device with the best fucking device security in the world, that is double-encrypted?
You can totally back up and export your Signal messages on Android. You export to a file (encrypted with a generated pin), copy that file to a new device, and import that file into Signal. I've done it several times and have never lost a message.
And I don't want it only as an encrypted blob to bring back into Signal though of course that option should be available. I would actually like the abilityt o export it in a format of my choosing.
I don't think so. At some point I setup my Signal to send backups to (I think) the "/Signal/Backups2" directory on my phone. My phone doesn't support SD cards, so there may be some quirk with those, but I definitely had some control.
> And I don't want it only as an encrypted blob to bring back into Signal though of course that option should be available. I would actually like the abilityt o export it in a format of my choosing.
That's a nice to have, but it's totally reasonable for them not to support a bunch of random formats someone might like, but hardly anyone would ever use.
If you want a different format, just write a converter. It wouldn't be very hard. The backup is literally an encrypted SQLite DB, and there's a command-line decryptor available (if you have your key).
The backup is literally an encrypted SQLite DB
I know this, but they don't exactly make any effort to tell you. While I agree that they can't support every possible format they could certainly offer CSV, JSON, and SQLite.
I've done it several times without problem. I had something like 40k messages, so it does take awhile, but has a helpful progress bar.
About 2 years ago, it was much more painful involving a back and restore, which I got working, but was kinda painful.
You require a phone number for your service to be used. That is a clear compromise on privacy, and you have no intention of changing it. Spammers can easily use my number to send me garbage. (Edit: you also require that users have Google Play or the App Store.)
You are anti-diverse since you are hostile to desktop users. Also, you are pro-harassment (Edit: people here think harassment requires intimidation) because you teach people that no doesn't mean no; I say no to donating and you keep asking me.
My entire extended family uses Signal, and I didn't even onboard them, my 69 year old mother (a retired special education teacher) did, because it uses your existing contact list to message people. I didn't need to walk people through account creation, we didn't need to exchange usernames. Even my 92 year old grandfather was able to get Signal to work. He's not great at typing on a smartphone, but he's figured out video calling, opening pictures, and voice memos.
I think that's a decent audience to shoot for.
Huh? Signal desktop has all the features of the phone, as far as I can tell.
Very strange definition of diversity!
> Also, you are pro-harassment because you teach people that no doesn't mean no; I say no to donating and you keep asking me.
If this is what you call harassment, count yourself lucky in life. :)
This is incorrect. You don't need Google Play to use Signal on Android. You can download the APK from https://signal.org/android/apk/
Then verify with SHA256 and you're golden.
https://signal.org/blog/building-faster-oram/
> It lays the groundwork for the introduction of usernames and phone number privacy which will offer new privacy controls around your phone number’s visibility on Signal.
and
> Usernames have been one of the most requested features throughout Signal’s existence. Making usernames and phone number privacy a reality in Signal is a massive technical undertaking. It’s something we’ve been working on for a long time and will continue to work on for several more months or longer before it’s ready.
If Microsoft, Google, and Amazon wanted to, they could just refuse service to Signal due to this and cut them off their services for facilitating that since they are centrally using their services.
If they can do it to Parler, they can also do it to Signal as well. Easy.