> Part of this is that the rest of the argument is often implied
To be fair, there is a lot of compression in language. I am often accused of being overly verbose but I only object to the adverb. We're both verbose here and inference is still necessary. I believe there was the necessary information to make the inference jump. Screenshot was an explicit illustrative example where I think you can sufficiently assume that I'm aware of mechanisms to copy the data or at least could infer that the existence of such mechanisms would be unconvincing. I will still stand by the stronger claim that we can assume that an average person is aware of screenshots or some copy mechanism as usage is quite prolific.
> The question is, whose security?
This, is a great question and the one I'd rather have. There is certainly arguments for both sides. I think the argument you are trying to make is about protection. Such as if someone sent you something that constitutes harassment but then deletes it prior to you using this as evidence against their abuse. I agree that that is of concern. But I am a firm believer in Blackstone's Ratio and subsequently my preferred mode of failure for the judicial system is to bias towards failing to prosecute criminals (false negatives) rather than biasing towards prosecuting law-abiding citizens (false positives).
> the other user often has the incentive to take action to defeat this, because their device is acting against their interests in favor of yours.
I do not buy this claim. I have no incentive to make or use a Signal fork when friends default to disappearing messages. The incentive only exists if I am suspicious of an adversarial reasoning for their data retention policy. In fact, in today's age, one could argue that this policy could imply reason to trust over reason to suspect as it implies that they are operating in an environment where they are unable to leverage my data against me (such as creating a LLM that speaks like me). I think there is a lot of nuance here that can't be easily dismissed. I think, like the former issue, that position is going to be more dependent on one's preferred mode of failure rather than preference of normal operation (which is likely not severely affected). I'll mention that we can use Reddit as a natural experiment, where users have actually a large incentive to edit their comments to make the person they're arguing with look foolish or naive. In practice, we see editing being used at far higher rates for resolving types/grammar or means of increasing clarity (like adding links), and often volunteering what content was modified. There's sufficient evidence for me to believe, on average, people value their own integrity over incentives to manipulate the conversation.
> Everything is always stochastic because there is a 1 in 2^256 chance
My preemptive response was more about that you must not just account for the brute force calculation, but the implementation. This is why I mentioned how statistics captures uncertainty. The tool is quite powerful in even fully deterministic frameworks because infinite resolution does not exist. We're both on HN so I think it is fair to assume we are both familiar with many examples where highly encrypted data was accessed and when implementation was performed by experts or those we'd expect to be experts. Something something weakest link.
I will claim that all security is stochastic and there are no (epsilon = 0) guarantees and I will make an additional claim about the former being unobjectionable (self-referential stochasticism intended)
> Whereas the ability of someone to screenshot
This may be where we've speaking past one another. I think we have different conditioning in how we're optimizing here. I place little weighting to the desired condition. I am more concerned with utility focused conditions. While I recognize that the search function is used (and even use it myself), generally we're just hoarders. The vast majority of text, pictures, and other data we generate serves little utility beyond a small temporal window. FWIW, I do advocate for Signal implementing an archival/favoriting mechanism (currently I forward messages to Notes To Self, which is analogous to a screenshot ;). Maybe I am jumping the gun here though and we will find future utility in that data. I could in fact want to train a LLM to act as me. Or maybe I want to build a classifier to search the internet and locate all posts that have a high likelihood of being written by me regardless of the username I used. But I think the bias should be to act conservatively and collect minimal information. Without a doubt that information does represent a avenue for abuse, so without an intended usage it does not warrant archiving. If we're going to get into legality, data often belongs to the person that generated it. As an example, a photographer can take a picture of Taylor Swift and because she is a public icon she can be sued for posting the photo on her instagram (I'm sure this would change if she was not a public icon).
So to be explicit on the conditioning: I do not see that allowing one to delete or even nuke chats would result in a meaningful difference in a standard setting. I do recognize there are special circumstances where this can be abused and used against you. But I also recognize that there are special circumstances where this can be used in your favor (e.g. suppose you are a political dissident in an authoritarian regime. Your friend sees you picked up by police. Your friend can nuke your chat, which can serve to protect both of you, as it is clear that authorities will be unable to copy the phone's contents at time of arrest). So the optimization objective is different. I do not believe my optimization objectives (which consider threat models not faced by a typical American or even likely typical human) would meaningfully decrease conversational utility. I want to stress that I am only proposing the capacity to destroy information, not any specific data retention policy. My concerns are about being able to adapt to the dynamic environment as I do not have sufficient a priori knowledge to predict who may be a future adversary nor what type of data makes me vulnerable and the potential damage. "First they came for..." is of concern as we do not need technology to change for vulnerabilities to rapidly change.
> There is also the potential to mislead a naive user
I agree and actually acknowledged this point. The acceptable level of users misunderstanding features is non-zero. I believe a warning contained in the deletion dialogue is sufficient to met an acceptable threshold. Do you disagree?
And I must be clear, I do not believe there are many people that would put in the effort to fork, log, or screenshot messages were there a standard policy of auto-deletion. While it isn't hard to screenshot, the task is tedious in the environment. I am sure you do not log HN, Reddit, or other forums that you may chat on. I'm sure there are many methods of communication where logging is trivial but you do not implement it. Certainly this is true for all code we write hahaha
> What you could do is make support for the feature optional.
I do actually advocate for that position despite actually believing the capacity to disable does substantially decrease utility. The proposal was rejected by the Signal community while there was strong support from other users on my side. But it is a concession I am willing to make for the same reasons I request the feature in the first place: something is better than nothing. I'd strongly advocate for the feature to be enabled by default (referencing aforementioned low rates of abuse), and that the mechanism needs to be configured beforehand. I would oppose a system that requires confirmation from the non-issuing side as this undermines the main utility that the functionality provides. I assume default applies to any new chat, configuration can happen at a per chat level (with consent), and again the default falls to enabled as this is what I believe provides the higher level of security and privacy.
So if you want to convince me, I'd say you would need to focus your argument on topics such as how the feature provides little to no utility, not to just the average user (who I expect to never use it) but to those most vulnerable. Or address why I may have poor assumptions about rates of abuse. Or if you can provide some strong convincing examples of how no capacity to delete provides a higher rate of security and/or privacy (of course, weighed against counterexamples (everything is stochastic to me, you can use that in your favor), since I think we're both intelligent enough to recognize that there are examples for both directions and singular non-generalizable examples are insufficient. I will do my best to read examples as illustrative and attempt to infer additional scenarios that are similar). I am very open to being wrong and am certain there are aspects that I have not considered, but I do think I have strong evidence for my current position.
And lastly, I do appreciate the more nuanced discussion. I think more of these need to happen as I think many topics are much more complex than we like to think.