Keep your phone number private with Signal usernames
signal.org
signal.org
I hope moving forward we can have multiple usernames and profiles. This would greatly increase privacy since we may have different identities in different social groups. Even on HN a lot of us have multiple personas. I find one of the big challenges is actually handling these different identities as most software only assumes you have one. Though it seems to be common on social media like twitter or instagram. But bitwarden still doesn't know how to differentiate microsoft logins lol
Edit: I'd love in the future to also see things like self destructing or one time links. I don't think these should be hard to implement, especially if one can have multiple usernames. Certainly a limit like 3 would be fine with the numbers, right? Personally I wouldn't be upset if multiple names became a premium feature but I'd strongly prefer if it wasn't. I get that signal still needs money (https://news.ycombinator.com/item?id=39446053)
I do wonder how telegram and signal are planning to finance it long term. Telegram is adding absurd paid features like exclusive animations, which won't earn nearly enough to cover the costs.
I wonder where signal is about keeping the servers up, since they hate federation so much.
They also make it difficult to hide your pseudo identity from your phone contacts. I’ve had all the “discover contacts” settings turned off, and simply reinstalling the app caused people to be given my username without my consent. Settings somehow magically switched themselves back on and I couldn’t turn them off until after the damage was done.
There was no confirmation prompt. Pretty sure this happened to me more than once.
Please don’t ever compare Telegram with Signal.
While waiting to have it perfect you don't have it good either.
The real problem with cellphones is that a lot of privacy-threatening issues are literally one fat finger away. And clearly, that's a feature, not a bug. That's why I prefer to work and message on my laptop anyway.
but again, Telegram has been, in many practical ways, much more privacy-oriented than all the other messengers, exactly because you don't have to share your phone number to participate in groups and chats.
Such as?
> now you can’t restrict who can send you a message unless you have a premium.
And before that you just weren't able to restrict that at all, there was no such feature. They didn't remove this feature for free users - it never existed. They just added it right now only for paid users.
> premium users can bypass non-premium users privacy setting “last seen and online”
That is absolutely not what the feature is. If you hide YOUR OWN last seen time, you won't be able to see last seen time of other users, even when they have it public. Now, premium users will be able to see public last seen times of other people if they hide their own. But they obviously still can't see last seen time of people who set it to private, that would've been very dumb.
As someone who for some time created and moderated fairly popular chat (200+ people) for anti-war Russians, I have very long and complicated history of relationship with this service and have a lot of different grey-zone stories where it is hard to understand whether it is a mistake from users and whether it is a leak from the service.
Hence I have a little low expectation and overreact on their recent changes
I generally agree with you that Durov makes a lot of incredibly stupid decisions. I think pretty much everyone in the "Telegram community" (eg. channel administrators, bot/client developers, etc.) would agree that the changes Telegram is introducing are often bad.
The issue, though, is that there isn't any alternative right now - Telegram is the best messenger out there in terms of general usage. So while I do hate what they're doing sometimes, I still use the product and even pay for Telegram Premium. It's bad enough to be mildly annoying, but not bar enough to actually make people leave the platform.
Edit: just as I was writing this, Telegram introduced a new feature. I'm not sure if I love it or hate it to be honest, it's a smart way for them to save money, but it is pretty weird: https://t.me/tginfo/3942
Restricting of incoming messages existed (cloned from Facebook as usual).
Restricting of "last seen and online" existed in third-party clients. Later on VK started to actively destroy this functionality, by moving manual "is online" management from designated API into all data-fetching APIs.
Not to mention that VK and Telegram are now actively fighting with third-party clients. In which world they would not fight Ninjagram/AyuGram/Plus Messenger/other forks, which allow to add multiple accounts, hide online/reading (to some extent), show message editing history and so on?
This is a really basic security feature though that every single platform should support. If Telegram didn't support messaging restrictions before, that doesn't mean they're not currently gating a basic privacy/safety feature behind a paywall. It just means they should be embarrassed that they used to be doing something even worse, ie not even offering a basic privacy/safety feature at all.
Correct that this would not technically count as removing a feature, but I feel like that's possibly a distinction without a difference. I'm not coming out of reading this explanation feeling more charitable about Telegram's security or willingness to gate off security features. It's a bad look for a company to put basic blocklists behind a paywall, that is not a company I trust not to start degrading security for free users.
This could be a long conversation. The short version is there are plenty of articles online by marginalized groups talking about the consequences of having no ability to block arbitrary groups from harassing them online. If someone is calling that "just an annoyance" they've likely never been the target of an extended public harassment campaign.
A slightly longer answer is that the consequences to privacy and security are in a practical sense -- in the sense that someone coming into my house is a violation of my security and privacy. Privacy is not just about hiding information, it's also about why we hide information. It's about the ability to be private; to not be forced to constantly listen to a bunch of people shout at you. Similarly, security exists for a reason, we have security in our homes in the sense that people can't just walk into them and start yelling at us and harassing us. And DMs should be thought of as analogous.
Your DMs are not secure if you have no way to turn them off or restrict them.
> The ability to block users was always there and it still there for free.
If you recognize that is important to privacy and security to be able to block individual users, it's not too hard to recognize that the requirement to individually block users leaves a huge gaping hole in security for a network that supports open registrations.
I use disposable email addresses rather than just blocking individual spammers in my email client. The reason is because there are a near-infinite number of spammers and blocking them one-by-one is ineffective. Being able to turn off a leaked email address is much more valuable to me. It's something that actually cuts down on spam.
And the same is true on social media -- being able to go private and turn off messages or restrict messages to certain subgroups is critically important for people who are stuck in the middle of public harassment campaigns.
----
Regardless, the lack of a feature that is pretty much standardized across most other platforms, and that is pretty widely recognized as a safety feature -- it doesn't make me feel better about Telegram's willingness to gate these kinds of features behind paywalls.
You're saying that the ability to block users is free, but there is no bright line between blocking users and setting general messaging restrictions. That is the same category of safety feature. There's no reason to believe that Telegram wouldn't make blocking users into a paid feature in the future, especially since it has demonstrated that blocking/moderation/lockdown features are something it is willing to monetize.
I mean I'm all down with the idea of tech companies respecting our privacy. But here we are, complaining that corporations that are at least trying (and that are operating at a loss since their conception for our convenience) aren't giving us "Snowden hiding in Russia" level of security out of the box, for free, just because we deserve it. All while we could easily implement it ourselves for like $8 and with no online trace whatsoever.
It's like, Tails Linux exists, but FUCK GOOGLE for forcing me to Ctrl+Shift+Delete in Chrome if I want to erase a cookie. I'm so significant and certainly not a criminal, why do they hate me so much??
However, just because the government forces something for them doesn't mean we should just give up entirely for everything - the fact that the government knows your SIM purchase doesn't mean that random users on HN should be able to find it.
Having said that if you leave the country I am pretty sure that sim card and number would be deactivated after a few months if not connected. I am not sure how fast a number can be reused.
I could not hate the phone number requirement more, and it's one of the main reasons why I don't use these applications.
With one exception: I have an overseas friend who only communicates through WhatsApp. For him, I did go out and get a burner phone for this purpose. But the friction level of doing that is unnecessarily high and I doubt I'd do it for anyone else.
Telegram is good, as you mention, to be relatively private in groups/chats/channels without a need to expose neither your phone nor even a nickname (unless you live in autocratic countries — will come to this later).
But it comes with costs. First, their p2p communication is not e2e encrypted by default. Not to say that all comments/group chats are not encrypted too, unlike let’s say WA.
Second, Telegram API. It gives too much information. You can do a lot with it: read history, track changes of usernames, etc. For example, it is quite easy to obtain an internal user ID and there are black market services and databases where they promise to connect that ID with phone number if that account ever had privacy settings switched off in the past.
Claimed that they kind of scrape all accounts and pair ID for those where privacy settings set poorly. Even if you change it later — your internal ID and that scrape will state forever.
Third, Telegram was funded by Russian government since Durov had issues with SEC. He raised money from different Russian state-owned banks like VTB, issued bonds which are traded in Saint-Petersburg stock exchange, and even take some money directly from Russian government though a Qatar proxy-company. Not to say, that there are cases when TG was involved in criminal charges against people (the most famous one is story with Ryanair plane being forced to land in Minsk to arrest Lukashenko’s critique) and it was never directly addressed and explained by company how exactly those people was caught and how company protect against “SIM card replacement” cases (Signal at least inform me everytime my peer logged to new device).
Selecting between Signal with AFAIK no known cases of charges in dictatorship countries like Russia, funded by non-profitable charity, and TG without default e2e encryption, public API and Russian-state funding, is quite obvious for me.
https://en.wikipedia.org/wiki/Blocking_of_Telegram_in_Russia
When war started, and Russia banned a lot of services like FB, they created list of communication platforms they have questions about loyalty and cooperation with Russian government. TG was not on that list and through the whole war the only issue was about Telegraph — supplementary platform to publish long notes. AFAIK there was 0 questions or criticisms to TG in those 2 years.
As for me, it says a lot
But then “SEC-incident” happened. He and his brother wanted to build TON and fund it by kind of ICO (without naming it ICO). SEC decides enough is enough and blocked launch of TON with charging Durov for selling unregistered securities.
At the end, issue was settled, Durov returned all money and settle the deal with SEC, but it shrinks his finance by a lot and he ran out of money for TG.
Then he was seen in Russia and issued bonds for $1 bln. According to Russian financial press [1], bonds were underwritten by Russian banks closely affiliated with government or directly stated-owned (all of them are in sanctions list now), and even some money was invested by Russian Fund of Direct Investments [2]. Last summer he again issued bonds for TG for $270 mln. You can buy TG bonds at SPB stock exchange where they were listed 2 weeks after the issuing [3].
Surprisingly (repeating my comment below), around same time, Russian govt withdrew all their claims to Telegram and started to use as the official communication channel.
Not to say that other “transformations” happened like Duriv publicly denounce US declaring it is a “police state” [4]
All links in Russian, sorry:
[1] https://www.rbc.ru/finances/15/03/2021/604f11019a79478034130... [2] https://www.bbc.com/russian/news-56501991.amp [3] https://www.forbes.ru/finansy-i-investicii/424665-shirokiy-k... [4] https://te.legra.ph/7-prichin-ne-pereezzhat-v-Kremnievuyu-do...
My bet is that they have a chance for democracy only when Russia becomes a set of little independent states. As Russia in a nutshell, is just a Muscovy that occupied other sovereign states. It was exactly like they’re trying it with Ukraine currently, again. Again, as the previous one was in 1918, when Russia ‘incorporated’ other states, what we know as ussr.
E.g. the Russian Comunist party leader Zyuganov have said many times that he lost the 1996 president elections in a fair way.
Take for example France vs Russia. In the 2022 election, Macron managed to get just ~30% of the voters that wanted him as President. In the second round where only two options remained, only 58%.
Without any serious opposition (with the murder of Boris Nemtsov and jailing/deregistration of Alexei Navalny), the 2018 was again a landslide for Putin with 76.69% of the vote.
There are of course other easy ways to tell, but this serves as a pretty easy heuristic.
This is, of course, a gross simplification, of everything that makes up a democracy. For example, the US is at best a flawed democracy because of all the lobbying, money and gerrymandering (and things like the Electoral College).
Disclaimer: Not American, I'm a Kiwi, so outsiders view of US politics.
Telegram is mostly few-to-many.
For me, there’s two big reasons for this:
Signal chats are E2E at all times, while Telegram is only E2E when you explicitly create a “secret chat” with whoever you’re conversing with. I don’t fault Telegram too much for this, because they still provide the option to use E2E for everything, but Signal gets brownie points in my book because they just do it by default without getting in the way of the User.
Secondly, as far as I know, Telegram uses their own in house encryption techniques as opposed to industry standards. I am not at all knowledgeable about encryption or cryptography— I only know what’s required of me in my job (basically the bare minimum), and so I don’t actually know whether this is anything of serious concern. It could very well be that Telegram’s encryption techniques are just as effective as the established norms, but I do see the general consensus trending towards “roll your own encryption = bad, use established norms = good”, which is primarily what I am basing my opinion on here.
To further detract from my own point, it actually seems like Telegram might be using “established norms” for encryption nowadays anyways [1], although I couldn’t really tell from the brief description I read on Wikipedia.
Overall, I think Telegram is perceived as being less secure than Signal primarily because of the reputation Telegram has for implementing their own in house encryption techniques, even if they don’t use those techniques anymore— their name has become associated with their known history of using ad hoc encryption.
[1]: https://en.m.wikipedia.org/wiki/Telegram_(software)#Architec...
Telegram has e2e encrypted chats but only on mobile and not on desktop for some reason.
I use Matrix with e2e encryption, and my chats are synced just fine.
To be fair to Bitwarden even Microsoft doesn't know how to differentiate between multiple Microsoft logins. As of at least a year ago, you can technically have different logins with the same username/email identifier, and different login prompts will behave differently.
They also are real shady with yubikeys. You can't set them as default but you can set "security key." So the process ends up being it assuming you want to use Hello (which breaks my Outlook... wtf), clicking use another device, security key, clicking next, then finally typing in your credentials. The next part makes me real suspicious since all the other dialogues go to the next page without clicking next. Why just this page? It's some weird dark pattern bs.
I'd call it malicious, but I think maliciousness requires intent. A chicken running around with its head cut off isn't really malicious if it runs into you.
I’d call them bugs, but they’ve been reported and didn’t get fixed.
I didn't realize my comment rose to the top. When I had written this I had also written this comment[0] which was the grandchild of the top comment at the time. It has a bit more details on my thoughts/reservations of federation. tldr is mostly about avoiding centralization. This remains an open problem and I think it is far too easily dismissed. But federation isn't solving the problems people want it to if it's federated like email and web browsers. That's just mostly centralization with all the headaches of federation.
And to anyone complaining about lack of federation, what's stopping you from running your own Signal server? Sure, it won't connect to the official channel, but is that a roadblock? Even Matrix started with one server. This is a serious question, is there something preventing this? Because if the major problem with Signal is lack of federation, I don't see why this is not solvable building off of Signal and not needing to create a completely different program. Who knows, if it becomes successful why wouldn't Signal allow a bridge or why can't apps like Molly allow access to both the official and federated networks?
Why ? Have you tried ?
> Each version of the Signal app expires after about 90 days, after which people on the older version will need to update to the latest version of Signal. This means that in about 90 days, your phone number privacy settings will be honored by everyone using an official Signal app.
Which is also an example of a challenge for open ecosystems where everyone can create apps.
I understand that it doesn't outweigh the benefits to everyone, but it is a valid reason.
I have not investigated this at all, but I have enough faith in Signal/Whisper Systems to be optimistic.
That is a fine decision to make for a security-minded app, but signal has always presented themselves as a full alternative to SMS and other messaging systems where availability is prioritized over confidentiality and integrity. It should really be made more clear so that users are making an informed decision. They could also do wonders for the user experience by having the app inform the user of the problem and how to remedy it.
The problem something like this solves is to raise the bar somewhat and discourage a fraction of those who would.
Done right, that fraction will be significant.
The conclusion isn't that Signal should be closed-source, it's that Signal's servers should not trust the clients not to be tampered with. So after 90 days, they will remove phone numbers from the protocol for users who have hidden them, breaking old clients, which is fine. What is the alternative solution you're thinking of?
My mom couldn't receive signal calls on the backup phone I gave her. I had disabled auto-updates since apps break UI sometimes and she gets confused by things moving around.
When I visited, I opened the signal app and was told I had to update.
The Signal team is incredibly clueless and arrogant toward its userbase. It seems to simply not have occurred to them that many people rarely/never have wifi, may not be on AC power when they are on wifi which means the phone may not check for / apply updates, etc.
In the US, cellular is often expensive and slow.
In underdeveloped countries where software like Signal could be really important, all this is even more true.
We get shit crammed down our throats to protect the most obscure edge cases for the smallest percentage of the most vulnerable users - such as not being able to sync messages between devices - but then they pull shit like this which has a huge impact for people in rural areas and underdeveloped countries?
Refusing to deliver is inconvenient.
That is inconsistent with the threat model of a messaging system!
Inherently, a messaging system will deliver a plaintext copy of the message to the recipient(s). Wouldn't be much of a messaging system otherwise.
Once you sent something and it was delivered in plaintext to the recipient, the information disclosure risk is completely out of your control (and out of control of the application in use). The recipient is free to leak it however they wish.
If you don't trust the recipient to keep it private, don't send it.
No need to continuously expire apps in the absence of a protocol breach.
I have no idea if that's what they're concerned about - they may just be being arseholes in this case - but from the outside it seems like a legit reason to build in the capability for app expiration.
I disagree, the worst thing that a messaging system that aims to be "private" can do is to actually not be private. Sending to a known-insecure client is a violation of, like, the one thing signal claims to do.
> If you don't trust the recipient to keep it private, don't send it.
My threat model is some combination of "third party actors who I don't trust" and "second parties who I trust but who are non-experts"[1]. I would like Signal to protect me from the first (by not delivering things to known-insecure clients that can be middlemanned or otherwise discovered) and the second, by having privacy-respecting and mistake-preventing defaults. Things like disappearing messages and such. Keeping my trusted-but-nonexpert peers from making mistakes that can harm either of us in the future is a key part of my threat model.
For example, disappearing messages prevent me from being harmed by my friend, who I trust to discuss things with, not having a lockscreen password and getting warrented by the police. An outdated or third party client that lets you keep them forever, even if well intentioned, can break that aspect of the threat model. And yes, a peer who is actually nefarious can still do that, but that's not my threat model. I think my friends aren't privacy-experts, I don't think they're feds.
[1]: This is, for example, the reason that I think PGP is not a good tool. Even if I do everything right, a well meaning peer who is using the PGP application can unintentionally leak my plaintext when they don't mean to, because of the tool's sharp edges.
Mint will sell you a plan for 5GB of data for $15/mo. Its not that expensive to have a basic cellular plan. And that's assuming you're not poor enough to have your cellular plan almost entirely subsidized. And also assuming you're pretty much never anywhere with wifi.
In the vast majority of markets in the US it'll take a minute or less to download, it'll probably take more time unpacking on your device and installing.
There's cheaper per-gig plans in the US. Visible has unlimited plans for $30/mo which is cheaper per-gig if you use a lot but more if you're using less than 5GB anyways. And if 200MB/yr currently seems like an expensive amount of data to you, you're probably already using less than 5GB a month.
My understanding is that Signal (the app) is private, not anonymous, centralized, and closed.
The underlying protocol is open and could be used for an open ecosystem, but I didn't think Signal aspired to do that.
The important distinction is that it's not decentralized like XMPP or email, which is a conscious decision: it would become very difficult to change it to add new features and they'd be left behind by closed-source competitors (see: XMPP).
XMPP is underrated. A lot of people are imagining Pidgen in 2011, but the protocol has been extended, the actively developed clients are good, and it avoids the heavier parts of Matrix (both client and server side.) I wouldn't be surprised if Slack's replacement when Salesforce inevitably fucks it up will be XMPP based rather than Matrix.
Even if Google Talk kept XMPP, they weren't going to save it, cause nobody used Google Talk. Facebook was by far the biggest XMPP-supported platform (though it wasn't federated), and they stopped probably cause they didn't see enough clients. Even Slack supported XMPP for a while, did you use that?
https://github.com/signalapp/Signal-Android https://github.com/signalapp/Signal-Server
There are forks like Session which doesn't require a phone number to sign up
The status of open source, privacy respecting messaging apps looks really healthy to me, compared to where we've been over the past 30+ years (thinking starting with ICQ.) Signal was a big leap toward getting average people using much more secure messaging, although it is pretty clear even most 'tech' people don't grasp what is going on or why it is important to be able to use e2ee separate from a combined client+server provider.
In fact, in this thread they are discussing how you can, with Molly, use both the official and staging servers with the same number: https://community.signalusers.org/t/signal-fork-with-passphr...
A mod recommends Molly here: https://community.signalusers.org/t/how-to-use-signal-on-3-d...
A list of forks: https://community.signalusers.org/t/list-of-unofficial-forks...
And here's people arguing: https://community.signalusers.org/t/on-forking-signal/31651/...
As far as I can tell, Signal's policy is more "Do what you want, but server costs are high so we don't want to pay for your product. But if you do, here's all the code to give you a start." That's a very different policy from blacklisting.
And as I keep asking others, what's stopping everyone from making a federated Signal? If you can use the same account on both the production/official server and the staging server, why can't you on the production server __and__ a community federated server?
And if they ban you from the production server, so what? Now you're on par with literally every other federated service. Like what is Signal going to do? Stop open sourcing code? That'd be like trying to kill a mosquito by stabbing yourself in the heart. If they're willing to do that, I'd rather it be sooner than later anyways.
So I want a source because I just don't get what you all are complaining about. Is it just that someone else didn't make the thing you want? Sure, I get frustrated, but the comments more come off as Signal being nefarious and I just don't see Signal acting in any way malicious. In fact, hosting links to forks and being a common place for those forks to discuss seems like they are actively supporting them.
Moxie wrote several articles about this and expanded on this idea in his conference talks. You are very welcome to take the code and write your own messing system, but do not connect to Signal's servers because that costs them money and they will need to take action, sooner or later.
They were very clear that LibreSignal had no future. They have also been very clear that they discourage any non-official distribution of builds. They have repeatedly told the F-Droid project that they will not publish using their reproducible build system, and any user doing the same will be kindly asked to take down their copy. The F-Droid project has complied.
This seems to be a strange thing to discuss. If the above links are representative it may be a popular subject among a subset of users, which seems misguided. Signal does not wish to be xmpp or matrix and neither should they. It must be their right to decide. There are so many chat software projects. If you don't agree with the goals of one of them, you energy is better spent elsewhere.
Signal has consistently focused on helping /most/ users do what they want with the app without sacrificing security. This change - away from requiring phone numbers - helps plug one of the biggest criticisms, both on the security and product side. Nothing about their mission requires federation, so I respect that they haven't sacrificed their mission in order to do it.
And talking about that: does federation work properly yet? I used a third party provider and it made my life miserable.
I am all for federation, but in my experience the "federated" part of matrix was a lot worse than the jabber one they want to replace.
But yes, it's also very hard. The bitcoin protocol didn't start out that way. It took a lot of knocks and bruises to get to the point they could upgrade all the servers in the federation.
Interestingly, the method bitcoin came up with allows protocol changes to fail, meaning the bulk of the federation never takes them up. Everyone gets a vote, and it only succeeds if the bulk of the federation upgrades. Perhaps from Moxie's point of view that's unacceptable, as it means he is no longer the dictator of the protocol.
Nonetheless, it is possible to design a protocol so it can be upgraded relatively quickly. Even if you don't do add "quick transition" features to a protocol transitions can still haven. IPv6 will replace IPv4. But as Moxie says, it's painfully slow.
It's private, centralised and the network is closed (e.g.: non-federated), but the source code is public and open source. I think that for the server implementation they do code dumps every once in a while, rather than continuously keep it public.
You are right about that. There used to be an open source build called LibreSignal
Moxie Marlinspike made clear [1]: You may inspect the code. You are even allowed to compile it. You are not allowed to connect your self compiled client to our message servers. We are not interested in a federated protocol. Make sure your fork creates its own bubble that does not overlap with Open Wisper Systems. Stop using the name Signal.
[1] https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
Six degrees will still exist.
(funny weird thing is that with HD2's server issues due too demand, one way to harvest this would be to create a fake LFG host game and have tons and tons of accounts bang against your HellDiver-Pot - and get whatever you can scrape from that?
---
OK - I actually went down this hole the other daty... you look at the reddit thread on helldrivers for LFG - or the discord...
So on reddit, you just put .json at end of thread - DL the entire thread as json, now you have reddit id, location, play style, etc, details AND their friendcode on HD2... but since they can individually generate random friend codes on any game/system that allows such... you have a breadcrump (with enough attention span to just correlate all the shared info between these friend codes and data received...
still - even with random friend codes - six degrees is still available, easily.??
---
I deeply hope they do a Tech Talk on the post-mortem of this lauch success spiral - its fascinating....
But one thing I am really interested in, this is based on the Autodesk Engine, I know they co-dev-dog-fooded, but I hadnt really known of this engine at all... what little I do know, is that - its amazing...
But I'd really like to know more about the arch and overall traffic flows etc of this game.
Its beautiful see "problems" like this explode in like ~2 weeks.
What do internet traffic graphs look like since growth, per carrier?
They're currently at 394,686 players on steam alone - not including Playstation players. The servers are doing their best right now.
I apologize for not asking a clearer question. I was actually just interested in buying the game, but only if it has public matchmaking built-in for finding anonymous pick-up groups, instead of needing an external Discord server to swap friend codes on.
.>..x###.////3~~E`~,~X>>----- XXNXN x0x
then I know that youre solardev.. and we can be friends in future
(but this model is exploitable in ways, which is premise of many threads here)
At a minimum, the server would connect the tokens to players in a database. But usually I think they do more than that, such as hosting lobbies, punching through NAT, and in many cases, actually hosting the games themselves and being the authority for all the state.
In that case I don't see how tokens would save any load over matchmaking.
the additional telemetry data for such connections and also unknown tracking from the clients is what is load.
unless you know what is coming going from to each client, and reqs of that connection btwn clients on the DB... have a bad time?
--
Or am I an idiot.
Its a code, inviting other people to speak to you.
The former C++ programmer in me wants to call them "user pointers" but that would just confuse people who haven't learned pointers.
Wouldn't say it's "common", because IIRC that's only the case in Germany and Austria.
The French use « », Italians use ‘regular’ “quotes”, etc.
Strangely enough, this is the first time I see your style of quote, in two decades on the Internet.
,comma-backtick` whereas I wrote ,comma-apostrophe'
I copy pasted both btw. You see them both as '? I see GP as having ` and me having '
I'm pointing out that nsxwolf was wrong to ask about comma-backtick, because tcmb used comma-apostrophe.
This matches the German convention described on https://en.wikipedia.org/wiki/Quotation_mark#German.
tcmb: ‚usename‘
nsxwolf: ,comma-backtick`
stavros: ‚comma-apostrophe‘
godelski: ,comma-apostrophe'
Though while copy pasting I see tcmb and stavros as having the same character which is different from the longer character you pasted. Seems my clipboard doesn't like that character. I also seem to have crashed OSX's emoji and symbol tray. No longer pops up if I press the button (bottom left) or select from firefox but got it back by opening safari.
Fuck man, I do not envy you people working on ligatures. Or timezones. I'm always impressed by these random rabbitholes and complexities in things that always look very simple. It's beautiful in a weird way.
Everybody's arguing, then finally all is revealed, and I learned a ton of stuff along the way about German quotation marks and the subtle difference between backticks and opening curly quotes, and low quotation marks and commas, in the Verdana font!
(If this had been a serif font with actual curly quotes the differences would have been much more obvious...)
https://op.europa.eu/en/web/eu-vocabularies/formex/physical-...
My reaction to the article was that they're using a lot of words to explain this change. That suggested to me that maybe they aren't being completely candid.
I've never used Signal, because (a) I don't want to rely on a smartphone, and (b) I don't want to use my phone-number as my ID, because it's traceable. I can't work out from the TFA verbiage whether this change addresses my concerns or not. That in itself is concerning, to me.
Regarding (b), yeah that's still a bummer, though, depending on your country of residence, you can get throwaway SIM cards for free and use that.
Why is it so hard for Signal and Telegram to not require a phone number as an account identifier?
I don't need to verify anything by phone or even email. If I lose the password, the account is lost, so be it. I'll create a new one.
If I really want to, then I'll set up email/phone.
I had a spare SIM card that friends and family use when visiting from abroad. It's been unused for 90 days and has been deactivated. The number is lost, and irrecoverable. A friend had created a (second) Signal account with this number and can no longer log into new devices.
As a more mundane example: If I accidentally drop my phone into a river, the SIM is gone forever, and so is that line.
Sure, you can have a contract line which allows recovery. Depending on where you live, these can be several times more expensive than a regular pre-paid line.
Yeah, it may not work when you buy a prepaid SIM and decide not to use it for a long time, but for billed plans, it's impossible. I've been using the same cellphone number for the last 23 years. I'd got my phone stolen, I was able to reactivate my cell the same day with another phone.
E.g. in the US, Mint Mobile is $15/mo. and is prepaid in the sense that you buy blocks of months at a time. But if you lose your SIM they'll still send you another one with the same phone number.
So no, if you lose your SIM you don't necessarily lose your number, even if it's prepaid. That only happens if you're buying your SIM as an "anonymous" one-off purchase, which is not what most people do these days. Not to mention the increasing prevalence of eSIMs.
You lose your SIM? You go to a branch, verify your identity, and get a fresh new SIM for your line. There's no more straightforward and surefire way to recover any other type of account as of today.
Email isn't easier to recover at all unless you own and control it which nobody does.
In general emails don't just get removed and given out again if you don't interact with them for a few months. Phone numbers do usually after 6-12 months or even after 3 months for some providers.
You can prepay a domain for up to 10 years or more and always setup a email server when you need it so you essentially have full control, long term.
And don't get me started with possible SIM copy and stealing attacks. Things already pretty much solved with email and DMCA
As the owner of the same cell phone number for the last 23 years, proposing hosting your own email as an alternative to SIM cards that's available at every corner doesn't sound feasible to me at all. I don't even like cell operators, but that's just the way it is.
I've had a email startup (sold meanwhile, but still running) and seen all these mentioned issues and know very well how painful this can be, but far from impossible. There is a market for clean IPs for company infrastructure, that's a thing still as well.
Probably I shouldn't say email is much better. But phone numbers definitely are a very weak decision for any kind of security.
Given that Signal does not have access (by design) to much information about their users when they use the service, they can't really fight spam once accounts are created. You could do spam detection on the client and privacy-preserving voting in order to ban spammers, but the UX would be very poor and that opens a whole new can of worms.
Even if that leaks, the handle should be changeable, and the spam issue could be completely mitigated by having a tab for first time "message requests" separate from the normal inbox.
I can't take a private messenger seriously when they require an identifier that's linked to your government-issued ID in many parts of the world.
Well that's a whole separate rabbit hole.
Governments shouldn't be requiring something as simple as a SIM card and phone number to be directly linked to a government ID. The right to privacy is a hell of a thing and the only reason a government would require this is to be able to spy on or track everyone.
Even if they have a good reason for the paywall, it's so bizarre that they don't ask for $2-$5 donation via their own cryptocurrency MobileCoin as an alternative to providing a phone number.
In this case, its painfully obvious.
Then assumptions such as "it's Signal's mission to provide private messaging in the face of government overreach" suddenly become very dubious.
Switzerland surprises me a bit there though. Presumably the people approved that, I had a Swiss friend while living in the Netherlands and was surprised by how frequently they vote on seemingly minor regulations. I very much appreciate it honestly, both as a much more democratic system and as a way of making sure the government is both slower moving and checked by the people. I have to assume the Swiss voted to allow such a regulation, curious if you know more about how that was actually legislated though.
If we stop caring as soon as enough governments grab more power they'll just keep doing it. We don't have to overthrow the government for something as simple as ID requirements for a SIM card, we just need to stop using them when we don't accept the premise.
Granted that can be harder in some countries that, for example, use phones to pay for everything and don't use cash. That's just another example where people could have refused though, we can still survive without it even if life becomes less convenient.
I've received hundreds of spam messages on Facebook, but I only found out about them years later when I clicked on "message request" tab by accident, it's extremely effective.
It is easy to create a new email, but not so easy to create and keep a new phone-number.
Edit: this is not actually a serious problem for me, don't worry! Rather, I think it's funny. And honestly I kind of like having the numbers required, it's a good idea. It does remove a lot of the vanity from usernames.
Because friend codes were so popular on Nintendo.
Hey add me real quick, my id is 12716472-83647281746-8172649! Or use the hash code, 0x28A56ED9! Super easy to remember, way better than giantrobot22 or vel0city66.
- if we don't have usernames we don't have to deal with obscene usernames, trademarked usernames, impersonation claims, and similar
- if we don't have usernames and our generated friend codes aren't guessable, we don't have to worry about people getting random unexpected friend requests from people they don't know
There's also the "weedlordbonerhitler69" issue. A user name that seemed hilarious at 16 likely seems less hilarious at 26.
If users were identified with a hash derived from an input user name you could type in "weedlordbonerhitler69" and what would be displayed is a hash on the client side. The contact add UI could simply return the UID for the input username. So you could give out the UID or username and another user could still add you.
They're not going to get mixed up typing it in from me verbally telling me the name. They're not going to get confused typing it in. And even then, validate the user after, that's another feature of signal is in person/out of band validation of the ends. So start the convo the verify through a channel you otherwise trust.
> There's also the "weedlordbonerhitler69" issue. A user name that seemed hilarious at 16 likely seems less hilarious at 26.
And with their setup you can change it at any time, so once again not really an issue.
Unless I got the wrong end of the stick, that's exactly what they are not doing.
People need to get trained out of (even informally) assuming they can identify someone because their username looks familiar, and this is a great way to do it.
With notable exceptions, i’m sure, being username69 and username420 and a few others (a similar phenomenon happened in magic the gathering, when they introduced limited edition 500 print runs of cards with the serial number stamped on them, and the only ones you can really sell or command a good price for are 1, 69, 420 and 500)
Or tons of (mistaken) conversation requests?
... notes HN user jenny91
Sadly, from what I’ve seen in similar threads online, it seems the devs are opposed to backups in principle (they believe that chats should be ephemeral and backing up is antithetical to this).
"No one can read your chats, including you." — Signal
Still, I feel it's much more inconvenient than it really needs to be; the correct UX is a button press.
I don't want backups for IM. I don't want my counter-parties to have backups for e2e encrypted IM. I don't want IM to last. Why record every conversation on your permanent record? It's nuts.
For me, having a searchable record of everything said defeats the whole purpose if IM and e2e encryption. I'm sure the NSA like it.
Reasonable people may differ on it.
That's not your choice to make.
I don't want to be randomly assaulted on the street, also not my choice to make. Doesn't make it ok imho.
The encryption key is in cleartext on desktop and the SQLite db is right next to it: ~/Library/Application Support/Signal/config.json
For people worried about having not consented to other peoples backup. They could implement ephemeral-only chats, or backup-excluded chats where both parties have to agree to changes.
For me this is a requirement to call a service a private service because in Germany at least every phone number is connected with a persons identity. To get a phone number you need to connect it to an identity using a identity card
I'd be curious if there is a study that has looked into the thresholds for different use cases at which spam account creation drops to negligible amounts and how much price vs anonymity vs difficulty factors into it.
And yet many people seem to earnestly believe that a tiny token fee will be enough to deter spam, despite clear evidence to the contrary (see for instance how Twitter's "verification" fee has completely failed to stop bots from overrunning the platform, many of which proudly display their blue checks).
But sadly I don't have contacts either!
The reasons they need it aren't really that dubious to me: they want to create a service that actual people will actually use, not just weird privacy geeks who never gave up on PGP. Using phone numbers allows for the kind of user discovery that most people expect in 2024, and requiring them inserts a barrier to mass account creation that can keep spam accounts down to a manageable level (especially given the whole point is they can't do content-based spam-filtering in the way that makes email managable).
Personally, my understanding is they've always been trying to develop the maximally private usable chat app, which requires some compromises from the theoretically maximally private chat app.
[...] Selecting “Nobody” means that if someone enters your phone number on Signal, they will not be able to message or call you, or even see that you’re on Signal. And anyone you’re chatting with on Signal will not see your phone number as part of your Profile Details page – this is true even if your number is saved in their phone’s contacts. Keep in mind that selecting “Nobody” can make it harder for people to find you on Signal.
Can't hide it from some thought police which may or may not need a court order.
And then what's the point of the super duper encryption?
What Russian police would be able to see, that in a given time period of certificate rotation at most X people communicated to Navalny.
Signal has no access to metadata, including participants in a conversation. All they know is the date of account creation and the date of the last connection.
However, if they got access to Navalni's phone, then they of course can see everything Navalni can.
Aha :)
Do you people also want the relevant xkcd? The one about the wrench...
You may have confused this information with WhatsApp which indeed keeps a lot of metadata on each user.
To me, it's much worse. A non-profit doesn't have my data but Amazon (and NSA) does. With Amazon's scale, it must be trivial to identify everyone.
See also: https://news.ycombinator.com/threads?id=autoexec&next=394457...
They promise to throw this information away, which is nice but not possible to verify.
They also employ a roundabout way of encrypting this data, but as they rightly point out in their article that describes the scheme, encrypting or hashing phone numbers is not safe from a malicious attacker. The space of all possible phone numbers is so small that it could be brute forced in the blink of an eye.
You place all your trust in Signal (and Google/Apple) when you use them. That may be better than the alternatives, but it's still something we should be honest about.
That said, keep in mind that Signal and Google/Apple can also trivially backdoor your software, so unless you take specific precautions against that, the details of their middleman protection isn't terribly important.
Unsure why the downvotes, but I assume it’s from this misunderstanding of the Signal protocol.
If a person is a member of a terrorist network - or friends with someone who is - the fact that a warrant could force Signal to expose that link could mean that a court is then more likely to approve increased surveillance of your (non-Signal) communications because of that link.
On the other hand if you are a woman on Tinder and using Signal to communicate with matches, this doesn't expose you to the person you have just matched with adding your number to their phone book, uploading it to LinkedIn and then finding where you work (which is what you can do with a phone number).
My feeling is this is a reasonable compromise, but it is important people understand what it does and doesn't protect you from.
Why worry about nation-state level attacks when you can simply be hit over the head with a mallet until you give up your password?
We don’t insult each other here. Take the cheap potshots to Reddit.
>Why worry about nation-state level attacks when you can simply be hit over the head with a mallet until you give up your password?
Yes, that would be the point of obfuscation, as opposed to just encryption. End to end encryption does not prevent the $5 wrench attack, obfuscation does.
Well, an even better barrier to reduce spam would be Signal to require some official ID of people...
I'm not giving a chat app free access to all my contacts - and that includes things like Whatsapp
It's not a fair remark though, all it did was twist what I said into a inflammatory derailment.
The point is there are a lot of (usually technical) people who are too focused one aspect, but are missing the bigger picture. If you follow them, you'll probably get a communication app that only those people can/will use, which has deal breakers for mass-market adoption. And once that happens, those people probably won't use it either, since they want to communicate outside their group.
"not just weird privacy geeks who never gave up on PGP." is simply not conducive towards making your point. You can make your (otherwise solid) point and even win the argument on merit without this sort of thing.
What is the usability concern for no longer needing a phone number?
Do people really expect to still exchange phone numbers ?
Fundamentally I don't want people to call me nor SMS me (that's for spam only), most messaging services will allow contact exchange through a QR code inside the app, and if everything else fail an email address will be the most stable fallback.
Yes. This is the norm in the US.
In many countries SMS was either crazy expensive, unreliable, wall gardened to death (can't message people on other carriers...) and had no traction in the first place.
Then phone calls are also crazy expensive: I'm looking at the phone plans right now and the main focus is the data amount. Phone call options are either to only allow for super short conversations for a flat fee (less than 5min per call, for a 25% increase in the monthly plan) or 30 min to an hour of phone call for double to triple the price of the plans.
Moving to an alternative is just the normal course given these incentives, and that's what people did in droves (looking at Japan for instance)
Looks like you're thinking about key exchanges as opposed to phone number exchanges.
Ever heard of user nicknames?
Do not be sprouting on about things that you do not understand.
If you're worried about Signal's hosting provider seeing your device's IP address, use a proxy. Personally, I'm not, because there's no trivial way to go from "Here's some IP traffic" to "this human had a conversation with this human".
> See also: https://news.ycombinator.com/threads?id=autoexec&next=394457...
I also hand BitWarden all my passwords. Therefore, the government has them, right?
(But it's broken somehow:
https://news.ycombinator.com/threads?id=autoexec&next=394457...
)
If we take privacy issue, it can be divided into 3 segments:
* Privacy of user data. The basic level. When you use Google or Apple, they collect data. Even if you minimize all settings — data is still collected. This data is used to train models and models is used to sell ads, target you or do anything else you have no clue about (like reselling it to hundred of “partners”).
* Privacy against undesired identification. Next layer of privacy. When you want to have some personal life online without sharing much about you. Like Reddit, anonymous forums, or Telegram (to some degree).
* Privacy against governments. The ultimate boss of privacy. When you want to hide from all governments in the world your identity.
Signal was perfect at first layer strong but not perfect at 3rd layer (e2e encryption, no data collection to share nothing with governments who seek for data, good privacy settings, always tell you if your peer logged to new device to protect from cases when government operates with telecom companies and use sms password to make a new login), and almost non present at 2nd because they have no public features except group chats where you share your number.
Now they in one move close gaps at 2nd layer — you can hide phone number and stay fully anonymous, and strength their positions in 3rd layer, leaving the last piece open: government still will know that you have some Signal account.
As for me, this setup solves 99,999% cases for regular people in democratic and semi-democratic countries and address the most fundamental one: privacy of data and actions online.
Yes it is not perfect but barrier for government to spy on me is that high that I reasonably can believe that in most cases you should never be worried about being spied, especially if you live in some places which are named not as Iran or Russia.
The only scenario, in my perspective, you can want to have a login without phone (with all sacrifices to spam accounts, quality of peers and usual troll fiesta in such places) is when you want to do something you don’t want ever be found in your current country.
But in this case, IMO, Signal is the last worry you usually have on your mind and there are a lot of specialized services and protocols to address your need.
That isn't true anymore and hasn't been for years. Signal collects your data and keeps it forever in the cloud.
Just to be safe here's a copy/paste with the details:
This has been true for many years now. At the time it caused a major uproar among the userbase (myself included) whose concerns were almost entirely ignored. Their misleading communication at the time caused a lot of confusion, but if you didn't know that Signal was collecting this data that should tell you everything you need to know about how trustworthy they are.
Here's some reading from the time of the change:
https://community.signalusers.org/t/proper-secure-value-secu...
https://community.signalusers.org/t/dont-want-pin-dont-want-...
https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin...
https://www.vice.com/en/article/pkyzek/signal-new-pin-featur...
Note that the "solution" of disabling pins mentioned at the end of that last article was later shown to not prevent the collection and storage of user data. It was just giving users a false sense of security. To this day there is no way to opt out of the data collection.
My personal feeling is that Signal is compromised and the fact that the very first sentence of their privacy policy is a lie and they refuse to update it to detail their new data collection is a big fat dead canary warning people to find a new solution for secured communication. Other very questionable Signal moves that make me wonder if it wasn't an effort to drive people away from the platform as loudly as they were allowed to include the killing off of one of the most popular features (the ability to get both secured messages and insecure SMS/MMS in the same app) and the introduction of weird crypto shit nobody was asking for.
I use Signal because I am a "nothing to hide and I like to own my privacy as much as possible" type online person.
Signal == more peace of mind just generally in this online world we have.
Because of your mentioned points I would never recommend Signal, and rather point to Briar as a messenger and group/broadcast platform. Currently, it's still a little painful to use and e.g. QR Codes would already help so much with easing up the connection and discovery/handshake process.
But it has huge potential as both a messenger and a federated and decentralized platform.
This sounds like a bunch of bullshit.
But for solutions, can't you just buy a voip number? You just need it for registration and then can dump it. I'm sure you can buy one with cash or zcash if you're really paranoid.
While in the US I don't have to show my gov ID to get a phone number, I don't know anyone who buys a phone with cash except international students. So practically everyone is identifiable anyways. But I'm not sure this is a deal breaker since all I'm leaking is that I have registered a Signal account. AFAIK Signal only has logs of an account existing and last online with 24hr resolution (which avoids many collision deanonymization methods). Even paying with cash is hard as I'm probably caught on camera (but these usually get flushed).
So I'm legitimately curious, why is this a dealbreaker? It doesn't seem like a concern for the vast majority of people, and the problem Signal is solving is secure communication for the masses, not the most secure method possible with unbounded complexity. It's being as secure as possible while being similar in complexity to the average messenger.
No, how would my uncle in the countryside of Vietnam do that? He doesn't have a credit card -- not many here do. He doesn't speak English -- can you find a website that sells voip numbers in Vietnamese? Buying a voip number from a provider in Vietnam has the same exact KYC requirements as buying a SIM, so it is still tied to your government ID and registered forever.
Also buying a VOIP for 1 month costs something like $10 from a quick Google. Average salaries are like $1.50/hour. Nobody is going to pay an entire day's salary to buy an VOIP number they throw for a month just so they can register anonymously for chat.
So, not you can't "just" buy a voip number unless you're a rich Westerner. But who needs privacy more? People in liberal democracies or people in places like Vietnam (literally an authoritarian country where people are routinely imprisoned for speaking against the government)?
> I don't know anyone who buys a phone with cash except international students.
Everyone buys a phone with cash here because few people have credit cards, since there is no such thing as "credit ratings" and it is easy for people to disappear from their debts. There are more people in Vietnam than any country in Europe. We all use smartphones and messenger apps here, too.
Your uncle in Vietnam has a smartphone, no internet, no number, and NEEDS the signal app? He might need solar, electricity and internet first.
Phone numbers should have NEVER became an ID. Incredibly hypocritical of Signal to claim "privacy focus" when the lowest layer of the system is literally the least secure identification method we have.
I had two SIM cards dedicated to online crap - one for important stuff like banking, another for social media and such.
both have expired after ≈ 3 months of inactivity, when my 2 week trip unexpectedly took 4 months. those SIM cards weren't physically inserted into my phone - I used to do that once a month to call someone and get billed a few cents so it would remain active, until that trip.
there's no way to get those phone numbers back and it's been an enormous pain the dick. I hate this fucking system, but I hate the fact that fucking everything requires a phone number even more.
Personally, I am totally baffled by this.
Due in large part to C3's positive influence, Germany is at the forefront of privacy issues and legislation on so many areas, except for this one, which ends up turning into a massive backdoor in the whole edifice. Okay, we can't ask for a copy of your identification card... we'll just use a telephone number or SIM code or something trivially tied back to your IMSI (like an app store account or IMEI) instead. Because of the absurd 2017 law, these are equivalent to your government ID card.
I really don't understand why Germans put up with this while simultaneously pushing so hard for positive changes in every other aspect of online privacy. Especially when so many other developed Western countries do not tie SIM cards to identities: Netherlands, Denmark, Finland, Iceland, Ireland, US, UK, Canada, and many many others.
It's like a giant `sudo gimme-your-identity` backdoor in all the other data collection protections. And nobody seems to care about closing the backdoor.
Anyways - why does nobody care?
Simple: most don't feel this being an issue.
Some may even say that they "don't have anything to hide" and there goes the erosion of privacy, bit by bit - by the time someone notices "ok, this may become a problem" - it'll be too late :(
Sure, but what's incredibly weird is that many Germans do feel that almost all other digital privacy matters are an issue. It baffles me that they treat this one particular issue differently for some reason.
I wonder if this is some kind of mass-psychology exploit, like it doesn't occur to your average nontechnical person that the ID requirement makes your Apple app store account, and every app you use it to install, equivalent to your government photo ID.
Even if this is true, how does that benefit Germans?
Nobody's seriously talking about blocking all SMSes at the national border.
That's the entirely wrong cause and effect.
The obvious root cause are a world war and the DDR.
C3 is the catalyst that turned that caring into actual tangible results. Or at least a big part of the catalyst. Their level of political effectiveness is extremely unusual in the hacker world. I'm glad it has been a force for positive change.
That said, it has limits. And I have heard rumblings before about the telecom giants (DT) being an insurmountable political obstacle. So hacker culture has more political influence in Germany than elsewhere, as long as it doesn't upset the telecom giants.
Anyway, this thread is about Signal, and JMP numbers work with Signal, which is why I suggested it.
Even the one who want it seem not to know about “registration block” and “PIN” concepts in Signal, so I seriously question if they really want it…
https://www.reddit.com/r/openstreetmap/comments/96sbd6/comme...
I tested it and it works for me.
(area["ISO3166-1:alpha2"="my_country_code_here"];) -> .a;
node["amenity"="telephone"].
(area.a);
(._;>;);
out body;
I get 2 hits, one of which says all phones were removed in 2015.Guess I'll continue not using Signal or Telegram.
"amenity=phone" returns 15 matches worldwide.
"amenity:phone", "amenity:telephone" or "amenity=telephone" (no other filters) returns the same 2 matches.
EDIT:
Belgacom started removing them in 2013 in Brussels, and the rest of country followed suit. The Belgian regulator found it unnecessary to require them with the ubiquity of mobile phones.
https://www.bruxelles.be/sites/default/files/bxl/Com_.%20pre...
I see 740 phone booths in Berlin at least, as a counter example.
What if I lose my phone and want to login again on a new one. Don't they send a verification code to the number again?
Since we’re discussing not providing your phone number out of privacy/security concerns, I assume that “registration lock” and PIN are on the table, which would anyway block you from registering again using the same number after loosing your phone.
Hence, the situation is the same as with your mobile phone number: no backup, no luck.
"Usernames in Signal do not function like usernames on social media platforms. Signal usernames are not logins or handles that you’ll be known by on the app – they’re simply a quick way to connect without sharing a phone number."
Also, this is not finally the feature Signal users actually want - not having to sign up for Signal with a phone number and using a username instead.
This new "feature" does very little to make signal more secure or private.
> Note that a username is not the profile name that’s displayed in chats, it’s not a permanent handle, and not visible to the people you are chatting with in Signal. A username is simply a way to initiate contact on Signal without sharing your phone number.
Later explaining "you can have multiple usernames" is easier then trying to undo that conception. People are familiar with it. Your username is how you identify yourself on the computer in every context when it's not obviously your phone number.
Other services do this too. For instance, you can sign up for some services with an email, and that's what you use to sign in, and you might be able to find other people by email if they let you, but you don't necessarily get shown someone's email on their profile, just the display name in their profile. And (in a well-designed service) you can change your email address at any time.
Why are then not just random when you go to the share screen.
No real reason to let a person pick it
They don't. That's not what I intended to say, sorry for the miscommunication. It's just a common spam bot I see on things like Facebook, Insta, Twitter, TikTok, Reddit, email, etc. But Signal can stop you from sending 100 messages a second. There are other ways to fight spam without needing to know any of the users or contents of the messages. A lot can be done from the minimal metadata that's required to perform communications.
> Keybase doesn't use phone numbers, how do they solve "spam accounts" ?
I don't know but I'm not a security expert. So you probably shouldn't be asking me. But if you got any questions about ML I'm qualified to answer some of those.
I'm pretty sure a big reason Signal uses phone numbers is just because they built from Text Secure. It is also aimed at an audience less technical than Keybase's target audience. I mean Keybase is free and private but everyone still uses Slack or Discord. FWIW, Signal does write blogs about these things. So if you'd like to learn more I suggest reading those while you wait for someone much more qualified to answer your question. I think you'll get it answered much faster if you're less assertive. Or you could go the otherway and try the old tactic of confidently saying something outlandish and wait for people to correct you. But I think this is a more difficult method to get answers to a specific question. Your call though.
Spam is indeed a hard problem to solve, but the issuance of phone numbers is not designed to be used as human identification.
Not every app needs to cater to every single human and potential use case on the planet.
Agreed. I don't own a phone of any kind, and would love to use Signal, but alas I can't because you need a telephone number, or a level 65 Necromancer to do the magic to sign up without it.
* Magic: https://www.techbout.com/use-signal-without-phone-number-sim...
I hope it will allow creating groups without forcing members to have their phone numbers shared with everyone.
>Your profile name remains whatever you set it to.
This sounds unfortunate, but I guess there's no way around this as long as Signal insist on keeping phone numbers as primary identifier.
By "link" I mean they immediately know what person the username belongs to iff they already had that person's phone number because the chat that is initialized after they scan the QR code is just the old chat being continued.
Exactly. I think that's important to know before people start giving out their Signal handles left and right because they think they're anonymous now.
If you set your privacy to nobody and someone saves your phone number, to them it will appear that you do not have a signal account, even if they start chatting with you via your handle.
Signal v7.0.0 with phone number privacy - https://news.ycombinator.com/item?id=39413417 - Feb 2024 (107 comments)
It's interesting to compare this feature to Session, where you also have randomized identifiers, but they identify you globally, and there's no way to give someone a handle to you that isn't linkable to other conversations. It sounds like Signal now offers that, which is actually the first time I've been intrigued by Signal.
Heh, I donate monthly to the Signal foundation but still get the occasional notification in the app to do so. In some sense, I am paying them anonymously :D
Being a product < Being a customer
(I guess theoretically you could run something like PostmarketOS on a phone to run the desktop app, but you know what I mean.)
Do you know why this limitation?
What I'd love to have is the ability to connect my phone and my laptop to the same Signal account, have them automatically sync chat history between each other, and then in the future if I add a new phone (e.g. because I've upgraded) my phone can sync from my laptop and get all of my message history.
Whatsapp added this recently and it is very convenient. You can link a companion device in the same manner you sign into WhatsApp web.
A kind of hacky workaround (that I used to use for both signal, WhatsApp and others) is to set up a server with matrix bridges running and bridge your signal, WhatsApp etc. so then you can install the one matrix client on all your devices.
But as most apps do support multiple devices these days, bar signal, it doesn't feel like it's worth the effort. And I seem to remember the signal bridge in particular being a little buggy.
Also, WhatsApp recently added this feature, so the expectations from potential new users who switched is now there.
[0] https://community.signalusers.org/t/allow-android-ios-device... [1] https://community.signalusers.org/t/allow-android-ios-device...
It’s not clear to me if it’d be possible to prevent the “contact joined Signal” messages if someone else has the phone number in one’s contacts. That would be a huge thing.
For a little more historical context, with this change Signal has now solved the problems that became widespread during the protests in Hong Kong in 2019 — someone else (authorities) adding random phone numbers to their contacts list, opening a chat app (such as Signal or Telegram) and finding if that person uses that app. Telegram solved this swiftly by adding more privacy controls, [1] while Signal had other priorities.
I know this is great and groundbreaking seemingly. And that it was and more was already there in Telegram, for years.
This is just unfortunate if it has been implemented like Telegram and it seems it has.
I should be able to dictate that “if I initiated communication” to “username” or “from my username” my phone number should not be linked to it even though the other person has my phone number in their address book saved, because that doesn’t mean they are a friend or even if they are I might not want to know that or chat outside the username.
I will try to access the beta (pretty sure it’d be full by now) and test how it goes but I hope it has not been implemented like Telegram after taking all these years.
Though I like that they have essentially nuked vanity username rush and grab in the bud. Kudos.
Yes, agreed. This doesn't stop an adversary who knows your phone number and identity (such as a surveillance state) from linking communications under your username with your real identity.
It just means that people don't need to give their phone number to someone just so they can communicate via Signal.
I think this can lead to people having a false sense of security.
A free-to-use global communications platform that doesn't censor, respects user privacy from the ground-up, and is run by a non-profit foundation that is faithfully dedicated to its mission. https://signal.org/bigbrother/.
We should support it. If you haven't already, then consider signing up for a recurring donation to the Signal Foundation. I try to give what I can afford, because I believe that digital freedom is essential for the progress of all humankind, https://signal.org/donate/
Without such projects, our civilization will stagnate and die in darkness.
Edit: Ok, ok, I was wrong, signal does have advantages over whatsapp.
I'd get a chuckle out of comparing that with the privacy of Whatsapp.
FBI doc on what messaging apps can provide via subpoena pulled by a FOIA request...
https://propertyofthepeople.org/document-detail/?doc-id=2111...
> Message Content: Limited*
> * If target is using an iPhone and iCloud backups enabled, iCloud returns may include WhatsApp data, to include message content
Your own link does not say that. At all. It directly disputes that.
2. WhatsApp tries to get every user to accept the option to backup messages and photos to Google Drive, where they sit unencrypted and accessible by Google. Even if you reject that option yourself, your correspondents are likely to have enabled it (if only just to stop WhatsApp from nagging about it) and so your messages are available for Google to read. Example of why this can be bad: https://www.vice.com/en/article/zm8q43/paul-manafort-icloud-...
3. Google Photos asks WhatsApp users if they'd like it to back up their WhatsApp photos. Even if you reject that option, your correspondents may have enabled it and so your photos are stored online unencrypted and accessible by Google.
4. Why should we limit what Google and Facebook know about us? Google and Facebook influence our behaviour for the benefit of their paying customers. Their computer systems are too powerful for our minds. They work against us, not for us. Companies like Facebook will come to be seen like tobacco companies, except that the harm is as from mind altering drugs. There is a documentary on Netflix called The Social Dilemma which explains this well. The polarisation of societies and the spread of conspiracy theories are some of the effects. The only defence is to disengage.
5. Read about Chinese-style social credit to understand why you want companies like Facebook and Google to know as little about you as possible. This is a good overview: https://nhglobalpartners.com/wp-content/uploads/2021/10/chin...
WhatsApp provides an option (off by default) to encrypt the backup with a password so that it cannot be decrypted by Google.
WhatsApp requires you to give it access to all your contacts (your entire address book) in order to use it at all. This information is uploaded straight to Facebook’s servers where they’ll inevitably use it to place your WhatsApp account in a social graph so they know who you are based on your contacts. I found this to be unacceptable so I uninstalled it.
Given how tightly they control development, disallow third-party clients, disallow federation, disallow self-hosting servers, have a history if disallowing use without google play and have hid huge development features from the public (mobile-coin) despite being open source. etc;
The idea that it's a great undertaking of our time is so bombastic that it's guaranteed to be false even if you truly believe that they are completely altruistic (which I'm willing to believe but it's not coming easy to me based on the above).
"What's better"? Matrix. Which seeks to solve all of my points, the only thing lacking is market share which honestly is partially caused by these "easy to use" services which trade off everything else, which also consumes developer mind-share even if you're unwilling to acknowledge that. (devs are motivated to solve issues for friends, family and themselves if they are exposed more frequently to systems and services that are sub-par).
https://blog.koehntopp.info/2024/02/13/the-matrix-trashfire.... explains why Matrix is lacking market share, and I think Signal's decision to be aggressively closed is due to a justified fear of becoming that.
The mantra of every network that stays mediocre and never achieves critical mass
I've criticized Matrix before for their "protocol-first" approach and "too neutral" stance towards clients (which they've changed somewhat it seems; previously [1] was a table of clients with no clue what to choose, now it at least has "featured clients"). I feel they repeated the same mistakes as XMPP, which has not improved their client list.[2] Protocol nerds will say that's a good thing, but all it really does is ensure your protocol remains marginal because most people just get confused. People choose software, not protocols.
But you can write a high-quality client and a specification and allow people to write their own apps. IMHO Signal is needlessly restrictive. Sure, focus on your own implementation and the quality of that first. 100% the right decision. But there's no reason to not at least allow some things down the line. Signal is just a few months shy of their tenth birthday – they're well past the "ensure the quality of our official client"-phase.
Friend 2 insists on using their client because it has dark mode, and for the average user, what they see isn't "friend 2 is extra and has a broken client", they see "that app fails to send pictures about a quarter of the time, let's use whatsapp".
It complains that cyberfurz.chat is a "server with profanity in the name".
...why?
Signal is very much in the same area of: "trust us".
With a caveat that they also say: "here's a bunch of information on why you should: but you can't really verify any of it and we have proven bad faith before- also we have an army of people who will pile-on if you call us out for not being actually verified, so, just trust us- we are the secure messenger and all those scary things are just so we are easy to use".
Definitely not true. Facebook literally censors private conversations. You simply can't send certain text strings to your friends. That is far more dangerous than relying on a third party that claims to be protecting your privacy. Especially since all signs point to them being honest.
To be clear, this is in private conversations. Not just posting publicly on Facebook or w/e.
To their point, there are benefits to federated systems. But I've yet to see a federated system have moderate to large usage without becoming centralized. Think email. And until this problem can be solved you're still left with a "trust us" problem. There's no trustless system out there, yet. But hopefully it comes in the future. In the meantime, signal is the best if you also want to communicate with anyone that can't tell you if a stack is FIFO or LIFO (or even know those acronyms).
I truly believe they are altruistic, although it is unrealistic to expect that to last forever.
By the way, some of the claims you made about their "bad actions" are actually false. And Matrix is still incredibly annoying to work with for "normies" and only recently got first-class E2EE and retention policy, both things needed for a secure chat experience. And btw, those things aren't deeply supported in the ecosystem, and also it doesn't have client feature flag alerting (to allow good intentioned clients to de-facto report they don't support certain security features).
I do think Matrix (or something like it) is the future, but it's certainly not the present.
It's not just any open-source project.
It's a privacy-orientated open-source project.
They could at least BSL the server code and allow others to verify the server code and host but not compete.
This is exactly what they do (except they use AGPL): https://github.com/signalapp/Signal-Server
[0] I don't even use Signal. My tack is to isolate and contain my "mobile phone" device as much as possible (when I'm home it generally stays next to the door on a charger). Whereas Signal has been designed around that single device as a critical part of my life. When I can sign up using only a username, and use Signal from a native client or web browser without any sort of Android device in the picture, then I'll be interested.
While I think there are better services to be private and secure from a technical perspective, there's one killer security and privacy feature that Signal has that on one else does: usability. It's pretty hard to get my grandma onto Matrix, but it isn't hard to get her on Signal. The truth of the matter is that you can't have private and secure conversations if there is no one on the other side. So while I really do like Matrix and the like, I think of them as more alpha or beta type projects. I don't find that the bashing of Signal is helpful (like we also do with Firefox) because all it does is creates noise for people that don't understand the bashing is coming over a nuanced and biased point of view (we're mostly highly tech literate here on HN, it is a bubble. But people still read our comments that aren't). End of the day, if we aren't getting 1 click server installs (or literally everyone is a host), federated systems are going to become highly centralized at some point. PGP's always failed because the easiest way to hack a PGP email was to reply that you couldn't decrypt. It wasn't appropriate for the masses even when it wasn't difficult to use. Don't get me wrong, I love Matrix, but it's got a long way to go to get mass adaptation.
Fwiw, I remember a user awhile back offering a bounty for a decentralized pathway in Signal[0]. The idea was to create an AirDrop like system to help with things like local file sharing but then extend the project forward to create a mesh network. Seems like a reasonable idea to me. I think it may be more advantageous to try to push Signal in the right direction than rebuild from scratch. I'd highly encourage people with other opinions to participate in the Signal community because it is a crazy echo chamber in there and for some reason the devs treat it as a strong signal.
An analogy is the U.S. is a two-party system, but most would consider this significantly different than the one-party system in North Korea or Russia.
A federated system with a few large players is still much better than a centralized one.
Like I said, I'm all for Signal becoming federated. It's why I dropped that link to the airdrop feature request. I'd also be in favor of people running their own servers. I mean the server code is available, you just can't connect it with the main network. So as far as I see it, there's nothing stopping this from happening. I see a lot of people complaining but I'm not aware of any major roadblocks. That doesn't mean there aren't any, but I'm just not aware of any. And fwiw, there are alternative Signal clients like Molly[0]. So at least the app can be disjoint from the official ecosystem.
B) Network effects drive the value of tools that are networked. The forks aren't popular at all.
C) Signal is well funded and not in financial trouble, so they can sustain effort on development and infrastructure.
D) I suspect you already knew all this too. So why did you respond the way you did?
If I am working with a source who gets frustrated by the impenetrability of communicating with me because I insist they use matrix while they're not technical and likely impatient, then that person will be much more likely to use a fallback method such as SMS or email, and they'll do it without warning. It's legal risk, period. My job is to make sure that they can share information with me as easily as possible and during a particularly sensitive period of that person's life, usually. Matrix, as a sibling post highlighted well, is too difficult for this use-case. That is an enormous failure for a use-case of sensitive information sharing.
Matrix did an interoperability talk on FOSDEM (https://fosdem.org/2024/schedule/event/fosdem-2024-3345-open...) and it's basically confirmed (https://www.wired.com/story/whatsapp-interoperability-messag...) there was some experimental work done on connecting WhatsApp (and ergo every other Signal protocol compatible app) and Matrix.
> It is unlikely that we will ever federate with any servers outside of our control again, it makes changes really difficult.
> ... I understand that federation and defined protocols that third parties can develop clients for are great and important ideas, but unfortunately they no longer have a place in the modern world. ...
Also, hasn't Moxie basically left Signal?
> If you think running servers is difficult and expensive (you're right), ask yourself why you feel entitled for us to run them for your product.
Forks are a natural consequence of releasing free software. This is the life they chose.
Also, free software isn’t a product.
The ToS is the only thing that governs end users connecting to the API, and it doesn’t deny end users the use of third party clients. Also, even if it did, that would be insane, like Google saying you can’t even load google.com when browsing with Firefox. It would be pretty much without precedent on the web, and bonkers.
The GPL is the only thing that governs developers’ use of the client codebase. The GPL of course allows forking and modification and redistribution.
Such forks and redistributions obviously cannot use Signal’s trademarks, so LibreSignal was dumb to do so. Ultimately the feelings of the Signal team don’t matter here - only the license under which they officially released the code. You can’t be more explicit about permitted uses than that.
You can’t be open source but then claim you don’t want forks. It’s one or the other.
"You must not (or assist others to) access, use, modify, distribute, transfer, or exploit our Services in unauthorized manners" [1]
By my reading, the ToS does deny the use of third party clients. Someone could try to argue that a third party is using the services in the same manner as the authorized first party client, therefore it doesn't break the ToS; but since the company's leadership have said that's not OK (causing the mentioned client to stop being updated), I'd assume that if that argument worked in court, they'd just change the ToS to be more explicit about stopping it.
This is like attempting to sue qBittorrent for copyright infringement.
Matrix also is just not particularly private. Servers control and know far too much about users, and pretty much no mainstream client enables E2E encryption by default. Matrix is an impressive piece of technology, but it has a long way to go before it's as usable for an average mobile phone user as Signal is.
I always like to remind people that you can also donate through your employer and many will match. This is a great way to multiply your donation and everybody wins. Your org is going to donate x amount a year anyways and so might as well "vote" on where some of this money goes.
For instance, I would love to see picture sent to me by my spouse automatically saved to camera roll. Signal has no option for this because it could put the privacy of me and the sender in jeopardy.
Fwiw, I want this feature too. And others. I've submitted feature requests in the past. I even asked that usernames add QR codes and links. I'm not sure if I was heard, but hey, the feature is there and even some of the echo people were against it.
My camera roll is for photos that I have taken. If I want to put something from someone else in there, that's a decision I will pro-actively make. Other apps shouldn't be doing that for me.
I don't want to be too negative on Signal since they do some good work and I do use it.
But freedom? No. It is another completely proprietary platform. A better one, but still proprietary, so the antithesis of internet freedom.
For example just earlier this month the Signal client overnight stopped working on my old Mac because they decided to no longer support older OSX releases. So I can longer use it on that machine, my primary desktop.
If Signal was in any way open or free (as in freedom) I'd just compile my own client to speak an open protocol and be back in business. But no, Signal is just a proprietary service with a proprietary client.
Isn't the source code available? What's preventing you from compiling your own copy?
Why can't you run your own? Sounds like it is not entirely open. (Never looked into it, so would be interesting to understand what is missing.)
> But you can compile the app and desktop clients yourself.
This has been talked at length here in HN before, they prohibit any clients other than their proprietary binary distribution.
If that has changed, I'd be thrilled. Can anyone point at it having changed?
I might very well be wrong, and if so, someone please correct me.
[0] There's always talk about the big deal breaker for Signal being that it isn't federated. So I've always wondered why this passion isn't used to generate a federated Signal network and is more focused on Matrix (who only recently started being E2EE). I don't know how these things work, I'm not that kind of programmer, but I can't see why you couldn't modify the server code to work in a federated fashion and edit the app code to be able to connect to both? I'm actually interested to know why if someone actually has an answer.
source?
From my understanding, they're not a fan of it (not sure if it's officially against their TOS or not) but they don't go out of their way to stop them. At least as long as you don't use the Signal name and make it clear you're not an official app.
Even in this blog post about usernames, they clearly make sure to mention them: "This means that in about 90 days, your phone number privacy settings will be honored by everyone using an official Signal app."
https://github.com/signalapp/Signal-Android/blob/main/reprod...
> older OSX
How old OSX are we talking? Is it older than current Xcode with Sonoma supports? If it's that, then you have your answer. If you want to daily drive and older machine Linux or even Windows should be fine, but this is not really the way with Apple hardware - if it was, Xcode would make this easier for the developer. For reference, you can still build for Windows Vista using current Windows 10 SDK - I haven't tried Windows 11 SDK, so not sure how things are there.
Otherwise, it'll always be niche. I'm never getting non-technical friends and family to adopt a messaging app that isn't unified for SMS and secure messaging. When they say "users might not know they're sending insecure SMS messages" - fine, you own the client. Make the client bright red with a flashing "INSECURE MESSAGES" across it for all I care. It's not hard to inform a user in 2024 that they are sending a less secure message.
Er, what? So no one you know uses Whatsapp, FB Messenger, Telegram, Google Talk, or anything else? I suppose it's possible that's true, but even if so, you and the people you know do not represent the common-case user.
Absolutely unacceptable.
Same with prioritizing stories, stickers and crypto payments as core features of Signal when that's not what most of their users care for. Meanwhile there's still no official way to port your existing chat history on PC and iOS to your new device, or support for Android tablets. Obviously, stickers are more important.
Obviously, the cryptographic guarantees of the two systems aren't even close to comparable.
I don't know what "feature" you're talking about not existing until 2014, but before Open Whisper Systems, the thing we call Signal was "TextSecure", a literal SMS replacement.
And some are better at being messengers than others.
Forcing you to use your phone number and then the same second you created your account go behind your back and spam everyone you just did so is neither private nor something many would associate with secure.
I guess something doesn't have to be secure if you can pretend it is public.
Of course Signal has carefully designed their goals to allow them to do that but in doing so that is a straight up asshole move in a context where they should be seeking trust?
Absolutely mind bending.
This is a great improvement, but they have already proven they can't be trusted with anyone's phone number so it is a damn shame they still won't allow you to create an account without one.
It is a decent service otherwise, but my fricking god I hope they at some point realize the harm they've done.
Up until today I've been ashamed of suggesting signal. Hopefully that will change with this feature.
1. Users were properly informed
2. Users were given the option to opt-out
And please don't pretend being annoyed about not being able to write third party client is in the same realm, that is just disingenuous.
And I'm not talking about something obnoxious like a cookie-banner here, something in the fine-print would go a long way.
I think it's a mischaracterization to say that they spam "everyone" when you create an account. They only tell others who a) have you in their contact lists, and b) have an account with Signal too. I agree, though, that they should be more transparent about this, and require that you opt in to this behavior.
Personally, though, I don't mind it; for the most part this is how I've discovered other contacts on Signal, and vice versa. But I can understand why it makes some people uncomfortable.
What I find "absolutely mind bending" is that this is such a big deal-breaker for people such as yourself. While I wouldn't call it a nothingburger, it's -- to me -- at most a simple error in assuming what people are comfortable with.
Edit: I re-read what a few others had said upthread about how indiscriminate this new-user notification is. The examples of notifications being sent to users that had been blocked via the phone's built-in call/SMS blocking features are especially chilling. There's really no excuse for that, but still, to me this automatic notification is a feature developed in good faith, with good intentions, not some nefarious privacy invasion. They should be taken to task for its failings, but dismissing the entire platform over it seems a bit over the top.
Of course it does, way more than "meaningfully". I actually wonder if I got your message right taken that I am not a native speaker of English.
Do you mean that if your phone is public (and you are known to be the owner) you will not get creepy calls, have ot listed as a free pizza delivery for calls after 23:00, having it blacklisted, ....
I must have understood wrong.
Otherwise what is the number of your president/prime minister? Or the CEO of Google/Apple/... I do not think they are public.
Who said Signal was a good product to begin with? And who though adding sticker would improve market share?
Casual users value UX and porting their chat history and VoIP calling vastly more than they value E-2-E encryption. You can't talk about growth when you fail to deliver on these fronts first. That's how Telegram and WhatsApps rule the market.
Adding stickers won't move the userbase needle when you already lost your potential users at the lack of chat history and UX.
My daughter loves stickers.
Also: "Who said Signal was a good product to begin with?" LOL. Just read the comments on this link bro.
How does Signal count it's active userbase? Like I said, me and almost everyone else I know have it installed but don't regularly use it because most people don't really like it versus the established Telegram and Whatsapp.
Like I said, a lot of people have Signal, but very few use it as their primary messenger on a regular basis, and more of a "it's just there in case one of those tech nerds who told me to install it decided to message me on"
Yes. I think your definition of "active user" is non-standard.
If you only use it a couple of times per week you're not really an active users when messenger apps on average get used multiple times per day.
So I don't think I;[m unreasonable at all to compare Signal to the average messaging apps in term of screen time.
This mechanism may not be ideal for all users, and it's possible that Signal has now outgrown it, but without it, there would be no Signal as we know it today.
How did THAT feature help Signal grow?
You only receive that spammy message if you already have Signal installed and your contact already has it too.
Signal grew a lot in 2021 (in Europe) because of the pandemonium created by Meta when they announced a change in WhatsApp Privacy Policy so everyone rushed to install Signal but the initial surge, was short lived.
Moving the clocks forward to today, looking at my extended network of family, friends and acquaintances, almost everyone has Signal installed, but most don't use it anymore as it's too frustrating and feels dead, so everything is still on WhatsApp, especially groups. All the Signal groups I have, originally meant to replace the WhatsApp groups, slowly died out and people stopped posting on them or following them, defaulting instead back to the WhatsApp groups.
You don't fix this lack of retention with stickers and spammy messenges.
https://support.signal.org/hc/en-us/articles/360007061452-Do...
Settings > Notifications > Notify When > Contact joins Signal
> We've discussed at length why this is not possible, but if you have more thoughts then please visit the forums. Please try not to open duplicate issues in the future, even if you feel like something is important.
I wonder why this is "not possible"
People seem to be asking for a way they can join Signal without their number showing up in the registry of Signal users. This is why it's "not possible".
edit: This may have changed today. I'm now seeing an option that lets me hide my number from the registry. This means that even someone with my phone number will not be able to message me on Signal, which seems like a good deal to me.
yeah, you need to authenticate to delete the account (aka deregister). How else would they verify that you are the owner of the account you want to delete?
That said, the complaint around this is usually that people don't want others to know that they use Signal. And unfortunately there was no way to _really_ do that (until now), because if you open your chat list, you'll see all of your registered contacts. But in the 7.0 release, we added the ability to hide yourself from being discoverable by phone number at all. So for people who don't want anyone else to know that their phone number is registered with Signal, they now have that option.
great, but what about all of those people that installed before 7.0 and had it already happen to them? "oops" doesn't help. at. all.
How can a privacy oriented company not see the privacy implication of this? Sometimes, you want to be forgotten by some people, and Signal is telling them you are still there and active on that number. I remember reading a story about someone getting into real trouble for that.
Without "usernames", the proper way to handle it would have been to not let anyone know you are on signal when they look up your number. To get into contact, send a message, then the recipient will receive a notification with the message and an option to rely. If the recipient doesn't respond, from the sender point of view, it should be as if the account didn't exist.
But I think it's inexcusable that these sorts of notifications could essentially allow someone to circumvent blocking done by one of their contacts. If I've blocked someone via my phone's default contact blocking mechanism, and then I join Signal, and that person is already on Signal, they should not suddenly be able to contact me... and even be explicitly invited to do so on their end!
I wouldn't be surprised, though, if neither Android nor iOS gives regular apps access to the blocked contacts list. So I'm not really sure how an app like Signal could solve this problem.
https://www.kitklarenberg.com/p/signal-facing-collapse-after...
I know some people defend Signal out of ignorance or loyalty, but I suspect there are some paid shills for Signal now. I don’t see how anyone with a bit of security awareness (which is the reason to use Signal instead of whatsapp) can justify using a phone number as an ID in 2024..
> Note that if provided with the plaintext of a username known to be in use, Signal can connect that username to the Signal account that the username is currently associated with. However, once a username has been changed or deleted, it can no longer be associated with a Signal account.
The "no longer associated", I will need to get Signal word for that, right. (You cannot cryptographically prove something was deleted, right.)
But it's good enough I guess
You'd have to take their word that this wouldn't change, though.
It’s probably the only piece of privacy friendly software I’ve recommended to older relatives that actually stuck. It’s not fancy, but it’s solid, simple and does what it’s supposed to.
(emphasis mine)
Couldn't Signal just brute-force all possible usernames in order to connect them with their accounts?
All in all, it seems usernames are just as public as anywhere else and the encryption part sounds like snake oil. Ok, maybe once more they try to protect the username table (or its equivalent in the zero-knowledge proof algo) from getting probed too often by means of an Intel SGX enclave or something, but I wouldn't want to trust SGX either.
aes starts at 128 bits
Either way, I was not talking about brute-forcing a single username. What I suggested was that Signal could loop over the space of all possible usernames. Every other name would be a hit (i.e. exist) and reveal the account ID, possibly even the phone number, of that user.
Hell, couldn't regular users do the same? The blog post at least doesn't mention anything about rate limits when probing usernames.
Interesting choice. I’m guessing most people might just use the last two digits from their birth year, to make it easy to remember.
Now that I know it still needs phone number I assume it will need to be unique so my use case fails.
For the record, I am still a happy Signal user and a monthly supporter, thank you very much.
It was great, then it focused on monetization at the cost of other things.
I still kept it because I could simply share an handle and talk with strangers over the internet on my phone/laptop. There won't be that need anymore.
I hope this feature puts pressure on Whatsapp to implement the same.
So I'd argue monetization here is not a top issue
I used it for the convenience.
Until they focused all their energy, time to monetization features. The quality of rest of the app began to deteriorate.
The app has grown a lot slower, and became buggy, along with it having several dark patters pushing for monetization.
What alternatives can be used instead, something that is easily accessible/available to the general public but not easy to obtain to create mass users?
For signal that would be harder to implement since it's more focused on 1o1 chats instead of groups, maybe if spam gets out of hand they could use a grey-listing approach like Instagram does where users outside your network get moved to the "message requests" inbox by default.
I’m still nervous about making new accounts in case it triggers some process to lock me out of my one account that I don’t have a phone number for. I couldn’t join the baldurs gate 3 discord to find people to play the game with because it required a phone number on the account, which I was already forced to use for my work account.
On the other hand, I’m glad they actually do enforce their rules, unlike Telegram (which is a haven for scammers, pedos, radical communists, open market drug dealers, and terrorists, not to mention the soul-depleting interactions I’ve had overall with chat rooms there)
Sorry, what?
Telegram can’t be trusted to not broadcast your pseudonym to whatever work or other contacts you might have saved on your phone.
Telegram doesn’t allow for changing one’s name per group chat like Discord does, so if you want to be known by a certain name only in a certain place, you need another account, which means you need another phone number. That’s not privacy.
As far as message contents go, people can click two buttons to export the entire chat. Or even delete the entire history. Then they’ll have the history and you won’t, and malicious actors (which are everywhere on Telegram) will be able to take your words out of context and use them against you. That’s not privacy.
On Discord at least you have some protections against that by having hoops to jump through to export messages (risking account ban or account creation limitation), helping keep people honest. The account age is also visible in plain sight, and that is very much a data point that people use to ward off potential bad actors.
Another dimension of privacy is I might want to read a message without knowing the sender read it. You may or may not care about that.
If you want to sell drugs and remain private, Telegram might be less likely to report you to the government.
Privacy is not about what features your app might have, it’s about what the user ultimately experiences, and the specific risks they take. The threat model suited for the average person is much more unfavorable on Telegram than on Discord.
It’s more complicated of a situation than being able to say “we can do end to end encryption”.
Disable contact sync, you don't need it for telegram to work
> Another dimension of privacy is I might want to read a message without knowing the sender read it. You may or may not care about that.
Long press on chat
> Then they’ll have the history and you won’t
You have a button to "nuke" chat for both of you from server. Then they'll have no proof except their words that "I didn't make this up, I honestly exported chat". Honestly, I don't really get this point. Can you elaborate a bit? What is the problem with exporting?
> If you want to sell drugs and remain private, Telegram might be less likely to report you to the government.
And with telegram you can register anonymous "number" on blockchain via tor and don't even care about telegram reporting you to the government. Is this intended to be bad point for telegram?
> threat model suited for the average person is much more unfavorable on Telegram than on Discord
Discord have TOS that allows it to read your private chats and ban you for privately discussing things that are against their code of conduct. This makes any sentence with words "discord" and "private" a complete joke. It's non-private messenger that never even pretended to be private. Maybe somewhat private if your main threat are random internet trolls
As it stands, if you let someone use your computer and you have signal desktop, they can see all your E2E texts. Desktop computer sharing is much more common than the devs acknowledge. Also there have been several high profile cases of federal agents squatting on a confiscated laptop, keeping it awake and eavesdropping on signal group chats without the other participants’ knowledge. See the evidence in the FTX trial as a recent example.
I'm a python programmer, and I have zero experience changing the internals of an electron app, but this is a big deal to me.
Also consider that, a sufficiently motivated private threat actor is likely going to break a pin, there's not enough entropy there, or they'll hit you with a $10 harbor freight pipe wrench until you tell them the pin.
For everything else, bitlocker, LUKS, or equivalent is more than sufficient and battle tested for those uses. Yes there are ways of breaking both, conditional on XYZ, etc, but, they're good enough. It does force you to multiboot, but that's good practice anyway, no reason someone using your computer should be using your root partition in 2024.
https://www.alexbilz.com/post/2021-06-07-forensic-artifacts-...
I would rather make this a feature of your desktop environment / window manager. Then you have this functionality for all apps, and the apps themselves don't have to make that functionality.
Edit: actually maybe what you're looking for is to have multiple accounts on one computer. Then every user has their own desktop environment with their own apps and data and apps are not shared among users.
I'm not going to argue the justification for this functionality with you all any more, and it is a little strange and suspicious that there are so many of you all opposed to a simple option being added to an app. It's a little insulting that you and other commenters think that multiple accounts on a computer and locking a computer with a keyboard shortcut are novel concepts that need to be explained.
If anyone is reading this who would like to help me instead of arguing against the implementation, my email is in my profile.
It may decrease privacy philosophically, but it isn't nefarious.
If you want a private messaging platform with zero prerequisite identity, use Briar.
You can keep it as an option.
> decrease spam by requiring some other source
Phone numbers never been a good way to counter spam, just look at social media, you can buy phone numbers in bulk these days, not to mention spam might work in social media because there’s the concept of “public space” where everyone shares and talk, so it does make sense for some bad actors to spam or even trying to influence others, that’s not the case in messaging app, because first I need to know your “unknown” username that I can’t see it elsewhere, and second, the efforts are worthy for such unsolicited message, which in case it was, you can get a burner to send it. The point is requiring a phone number to counter spam doesn’t work, and it doesn’t make sense either for messaging apps.
> If you want a private messaging platform with zero prerequisite identity, use Briar.
Well, personally I don’t use Signal, never will in its current state, but they always try to promote it as privacy messaging app while still relying on a broken system known as GSM.
It doesn't decrease privacy. It decreases anonymity which is distinctly different.
> If you want a private messaging platform with zero prerequisite identity, use Briar.
Or Session which is a fork of Signal that runs it's own network using standard PKI instead of a phone number for identities and a decentralised message delivery/onion routing system.
You either end up discriminating against users who have to use VOIP for whatever reasons (and there are legitimate reasons) by blocking VOIP numbers, or your barrier to entry for spammers is almost negligible. It's not a good system.
If you want to prove that users are humans, use a webcam and an id, or delegate the task to some bigcorp who already has a similar system. If that's too much for you in terms of privacy, you shouldn't be attempting to prove that users are humans in the first place. Maybe you should prevent spam via product driven solutions, e.g. whitelisted contacts.
What experience do you have to have gained this confident knowledge?
Yes, but what are you going to do with this information? All you know is how long they've been a signal user and when they last connected.
The metadata itself is just as valuable as the content of the messages.
If you want to prove that criminal A was in correspondence with criminal B, that's how you do it.
As per this comment, they store much more than just the last connection time[1].
If you know how to build an anonymous communication platform, that is convenient to use, and is also spam resistant/proof, you have the miracle platform idea.
https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec...
Obviously doesn't include warrants they may have received where a gag order is in place, but you can see from the responses they do publish that they only store phone number, initial registration date, and last connection date.
This is in direct opposition to the very first line of their privacy policy which lies when it states "Signal is designed to never collect or store any sensitive information." and they've refused for years now to correct that lie and update their policy to detail all the new data collection they're doing.
Here's some reading from the time of the change:
https://community.signalusers.org/t/proper-secure-value-secu...
https://community.signalusers.org/t/dont-want-pin-dont-want-...
https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin...
https://www.vice.com/en/article/pkyzek/signal-new-pin-featur...
Note that the "solution" of disabling pins mentioned at the end of that last article was later shown to not prevent the collection and storage of user data. It was just giving users a false sense of security. To this day there is no way to opt out of the data collection.
My personal feeling is that Signal is compromised and the fact that the very first sentence of their privacy policy is a lie and they refuse to update it to detail their new data collection is a big fat dead canary warning people to find a new solution for secured communication. Other very questionable Signal moves that make me wonder if it wasn't an effort to drive people away from the platform as loudly as they were allowed to include the killing off of one of the most popular features (the ability to get both secured messages and insecure SMS/MMS in the same app) and the introduction of weird crypto shit nobody was asking for.
I swear if VLC ever turns evil I'm giving up on recommending software forever (in the meantime, check out VLC if you haven't already!).
I don’t blame you, I think it did start with a good promise initially, but I believe just like anything centralized that turns big, it will become evil.
> in the meantime, check out VLC if you haven't already!
The player? Or is that a new messaging app? For messaging I usually use Matrix/simpleX/Session.
If there was such a hoo-hah and it was trivial to patch out, I expect we'd have a thriving patched fork up and running by now.
"Even under the sealed sender, observers said, Signal will continue to map senders' IP addresses. That information, combined with recipient IDs and message times, means that Signal continues to leave a wake of potentially sensitive metadata. Still, by removing the "from" information from the outside of Signal messages, the service is incrementally raising the bar." (https://arstechnica.com/information-technology/2018/10/new-s...)
A couple years after that "incremental" improvement Signal started keeping everything forever in the cloud which means that today governments can get a signal user's information just by brute forcing a PIN
See https://sgaxe.com/files/SGAxe.pdf for an attack that leaked Signal contacts.
From https://signal.org/blog/signal-is-expensive/
> We use third-party services to send a registration code via SMS or voice call in order to verify that the person in possession of a given phone number actually intended to sign up for a Signal account. This is a critical step in helping to prevent spam accounts from signing up for the service and rendering it completely unusable—a non-trivial problem for any popular messaging app.
I'm not sure why you need to assume that it will be linked back to your real identity; I haven't seen anything that indicates any motivation to do something like that. I'm all for being cautious, but being overly cynical can lead to letting perfect being the enemy of the good.
> I'm not sure why you need to assume that it will be linked back to your real identity;
I’m not assuming, only North America (edit: and some European countries) doesn’t require an ID for a phone number (1), and even in here, you would use it in other services that are linked to your real ID like banks or paying the phone bill online. The concept simply boils down to as soon as you find an account’s phone number, it’s a game over for that said privacy.
(1) https://www.comparitech.com/blog/vpn-privacy/sim-card-regist...
You completely misunderstand what kind of privacy Signal aims to achieve. Signal protects you from eavesdropping and data hoarding, two major privacy issues with solutions like Facebook Messenger for example.
They do not and have never claimed to offer a service where “privacy” means nobody knows who anyone is, it isn’t Tor and I wouldn’t want it to be.
If you don’t like the goals and design choices of Signal, just use another service.
There are benefits of the choices they’ve made, namely ensuring that most users of the service are “real people”, which I think is great. It’s not a social network, it’s a messaging app between friends that solves issues presented by alternatives like SMS or Instagram; that’s it.
Do they?! We can ask Tucker Carlsons about that https://www.reddit.com/r/signal/comments/16evuej/did_the_nsa...
As long as you can’t host and use your own server, you should never assume that.
> There are benefits of the choices they’ve made, namely ensuring that most users of the service are “real people”
You communicate with your colleagues and clients over emails and you know they are real, you probably play games too and use discord and you know they are real, meanwhile you can be talking to bot in twitter that they are registered with a “real” phone number.
A lot of people in the comments have things to say about that video.
Personally, I wouldn't trust anything that comes out of Tucker's mouth.
The only way to know for sure is for you to create an alternative service, write all code yourself, and host everything without ever leaving your server alone. And even then you can't be sure you haven't been hacked.
On a side note, if we're getting information from someone that lies a lot and often leaves out details that don't fit the narrative, then perhaps we should also look at the person, not just the issue.
You certainly can, the self destruction messages are one of the ways, sure, it is not the only solution as you need to make sure the OS is secure itself too, but definitely helps in that case, no messages stored at rest and all are encrypted in transit.
> Something else that might happen is you ending up with your phone hacked
Which is essential to have a messaging platform that allows multi-client/cross platform, say running that app on a hardened OS is an option and possible compared to only iOS with a phone a number for example.
> write all code yourself, and host everything without ever leaving your server alone.
You don’t need to write it yourself, as long as you can read it, and host it knowing no other services are spying on that server, should be miles ahead of other apps like signal, sure, you can still have that server breached, but first you need to know where’s that server, or even you are using this messaging app in the first place, contrary to Signal for example, all I need is checking if you use it by the phone number. Not to mention it will make it harder for whoever is trying to spy on you, if most people ran their instances, but that’s a little bit more of a dream as the average person won’t, but at least the option should be provided.
On the other hand Tucker isn't even being consistent in his telling of the story. He says that he hasn't told anyone and makes a big deal to even mention his wife, so we think even his closest confidants. But then what message did he send over signal that was extracted? The personal notes? There's also much more reasonable pathways for the NSA to get that information. If he's researching and just storing notes on signal he's still leaving breadcrumbs somewhere. He's a popular news host so I'd be surprised if the NSA hasn't tried to compromise his whole phone, and signal only protects your messages in transit. The only evidence we have is his word that someone from the NSA told him. Which itself would be really weird because it'd completely undermine that capability or imo a more likely explanation is someone is lying. Gov does disinformation all the time and convincing people a secure channel isn't seems pretty useful since they'll turn to easier methods.
So I don't have to rely on my distrust of Tucker or his history of misinformation. If this was my only and first encounter there's more than enough for me to be suspicious in just his telling.
How on Earth collecting a phone number may be considered as not data hoarding?
That's the vast majority of what intelligence agencies actually care about. They rarely care about message contents anymore.
By default, the first message between someone and you clearly identifies who is communicating with whom. That's enough.
We don't know whether an intelligence agency is listening in on their servers and logging this data.
Assuming an eavesdropper that can defeat TLS or is listening via DMA attacks on the signal servers,
- you can log initial signup or login, which allows you to connect user id and phone number
- you can log the first time a chat is created, which allows you to build a social graph of which person is connected to which other people
- even with sealed sender, you still know the identity of the receiver and the IP address of the sender, which is often enough to figure out who is in contact with whom
This would be enough dragnet surveillance to automatically figure out the contacts of people you've already identified as threats. You'd also have enough evidence to get a sealed court order to do targeted surveillance on these people.
Also, you need some way to log in to your account. So you need an identifier and some way to validate that you are the owner of that identity. And next to that you want to prevent spam. So I think the choice to use a phone number as an identifier for a text-messaging app that is meant to be a secure replacement of SMS is not that weird.
But let's say they are data hoarding our phone numbers, and they can get other details about us through the black market because we use other more insecure services where we suddenly don't seem to care about privacy. Then what do you think Signal does with this data? They can't resell it because they don't have anything unique, they actually need to invest money to link their database of just phone numbers to something else. And then? What malicious things will they be able to do?
What have you gained? What does the attack look like?
(Or a phone, even)
The news today is a step in the right direction for sure, but more needs to be done if they want more privacy and anonymity-focused people to use it. This section on what makes a good messaging platform still resonates: https://dessalines.github.io/essays/why_not_signal.html#what...
<https://www.nfcw.com/2022/10/20/379863/south-korea-to-roll-o...>
If it's not possible to buy a phone without a strong attestation of identity, as is the general case in at least one country, then the identity relationship is baked in.
It's probably possible to buy a burner phone even in South Korea. But for those who are using their standard-issue phone with Signal, the problem most certainly exists.
And even in countries where there isn't some national phone-as-identifier policy, effectively most people's phone numbers tie them to their real-space identity even if there's no explicit personal data association[1], and in most cases, phone number, IMEI, AAID, and/or billing data (credit card payment authorisation) provide far greater assurance.
________________________________
Notes:
1. <https://www.eff.org/deeplinks/2023/11/debunking-myth-anonymo...>
2. IMEI: <https://en.wikipedia.org/wiki/International_Mobile_Equipment...>, AAID: <https://support.google.com/authorizedbuyers/answer/3221407?h...> <https://noyb.eu/en/buy-phone-get-tracker-unauthorized-tracki...>
Point remains that 33 bits will identify any given person among the 8 billions now living, and a phone number itself, plus ancillary leakage (activity patterns, location) are an exceptionally poor basis for an anonymous or pseudonymous identifier.
If you read the thread the linkage between a phone number and a Signal account cuts down on fake accounts significantly - which has nothing to do with "social media" but it does have a lot to do with SPAM as you've incorrectly stated. I understand why it's not ideal, but there are tradeoffs in both directions. It's unlikely that usernames are going to expose users more than they currently are if they're already using Signal. And it's also unlikely that this new feature changes much, but I welcome the ability to prevent users from associating my known number to my Signal account. In this way the security model has improved considerably.
Governments won't go on a crusade against Signal as long as they keep records of who is using their platform to commit crimes.
Signal won't commit to being an anonymous platform likely for that reason.
This sounds terrible. Are they saying that your phone number will still be visible to anyone running an unofficial app, even if they didn't have it before?
Is it enforced by the protocol or is the number just "hidden" by the official app?
If you don't open the Desktop app for a few weeks though, there is a "syncing" step where it fetches the recent messages queue from the server (can't remember the exact number, might be the last 1000 messages or all messages from the last 30 days or something similar).
And it doesn't show any messages that came in on the phone during that time, so you're missing context and in practice you just have to use the phone for everything anyway.
Amen.
Guess I'm not signing up for Signal then.
Seriously though - this has always bothered me. They build the "most private" communications service ever, yet require one of the most identifying pieces of your information in order to use it.
If I didn't know any better I would swear it was a surveillance honeypot.
Can someone explain how this doesn’t leak information? If I add someone via username and I randomly guess their phone number, does Signal leak it after the fact?
Further down it says:
Selecting “Nobody” means that if someone enters your phone number on Signal, they will not be able to message or call you, or even see that you’re on Signal. And anyone you’re chatting with on Signal will not see your phone number as part of your Profile Details page – this is true even if your number is saved in their phone’s contacts.
So I think what they mean is if you've been chatting with someone before this update and they have already linked your phone number and signal account then setting to nobody won't revoke that.
However if you initiate a chat with someone new using your signal handle, even if they have your phone number stored, they won't know it is you.
Otherwise it seems like it would be easy to brute force someone's phone number!
Still I would love that this feature generated QR codes without the unique disposable username in human readable form.
Does it defeat the protections then to add a range of phone numbers in contacts and harvest username/phonenumber combinations?
It's 2 swipes to block and delete but a problem I never had to deal with before on Signal.
All of the current messaging apps are spyware in one form or another.
Why can't they function without access to the entire contacts list?
Contrast to MSN, which kept your contacts on the server, as well as information about your account, groups, your plaintext messages, etc.
I have always wished to integrate a similar method in our phone first booking solution to keep the number private beetween host and particpant.
Very inspiring!
I was tired of reading all the comments on here about how 'google search' is terrible, I now believe it and will be looking into all the suggestions here.
>Hide-Your-Number(tm) option!
>still need a number
LOL just install Session and SimpleX (and, for 'droid Chads: Briar). If P2P voice/video skeeves you then get mullvad or proton or something vpn. Why is it the normie will do all kinds of torturous steps like phone and identity verification to install instacoom...
... but they just refuse to install Session and copy/paste an identifier to add contacts (assuming non-locality, else there's QR), complaining it is "too hard whine mew!" Normies make dragnet surveillance so easy!
How about no phone numbers for registration at all?
* Gives the servers virtually no control over communications between parties.
* Goes through huge pains to minimize serverside metadata storage.
* Is a sealed system end-to-end; the client and the server are part of a single coherent design that together make promises about privacy and security that apply to every user of the system; Matrix is a protocol ecosystem.
A good example of this is group messaging: Matrix servers control group membership. In Matrix, group membership is key management; a Matrix server decides who can decrypt your group messages. That's not how Signal works! But I don't think anybody seriously thinks Signal is a replacement for a large Slack.
And yet uses AWS: https://news.ycombinator.com/item?id=39414322
The threat model assumes attackers have maximal control of the server environment.
Hence my position remains unmoved.
This continued insistence (widespread - not just you!) on the benevolence and good faith of US intelligence, post-Snowden, doesn't make any sense to me.
Take a step back and note that nobody on HN is going to make an argument premised on "you should trust NSA to follow the rules". You can accept that as an axiom and have easier conversations here.
...and this is the declassified part.
This is not good enough. Signal server is a single point of failure: NSA (and any other attacker, e.g., China) knows that the users can't go elsewhere, so it's very easy to target them all (thanks to the Signals's politics of walled garden). In case of Matrix, there are thousands of servers around the world, which you have to find and get into. They can run completely different software. This is not very scalable or easy.
https://www.nybooks.com/online/2014/05/10/we-kill-people-bas...
The paper you linked to was published before they started collecting and storing sensitive user data in the cloud
I have no idea how to get my extended family on a Matrix homeserver without extensive handholding. I can barely figure it out myself and I was a huge XMPP nerd that ran my own ejabberd server for years.
Then let your phone number receive the spam instead?
It prevents the creation of an unlimited number of signal accounts by a single user with no cost to the user but cost to signal and other signal users.
edit: Your are probably right in that it does not change the risk of spam for a single user, as you could guess the phone number or just iterate over all known phone numbers and try to connect to them.
requiring phone numbers only solves the cost problem for signal(The company/legal entity) and lowers(hopefully) the amount of spam that would get send.
I just laughed reading this. I never used Signal, for obvious reasons, so I wouldn't know, but was it really the default? And people were using it as supposedly private messenger? That's unbelievable.
I have SMS, Whatsapp, Signal, and Threema installed, and it's a hot mess of disparate networks. I hate it.
Long-press the send button.
Thankfully, your experience is not universal. It's still the primary means of communication between me and the majority of my friends, technical and non-technical alike. I believe they've walked back (or, at least, not committed to) that crypto project - at least, I haven't heard anything about it in so long that I barely remembered what you were referring to.
I'm skeptical of crypto too, but this sounds like an over-reaction that is cutting off your own nose to spite your face.
Think of how many systems innocently ask for phone numbers as a hard requirement for account creation (under the guise of DFA). Think of all the restaurants that innocently ask for it “so we can text you when your tables ready”, or when you buy a shirt at Banaba Republic, “can I get a phone number”. Like seriously, WTF?
In reality it’s now the defacto method to identify and reconcile your records across ecosystems.
Apple needs to create throw away phone numbers like they’ve successfully done with email addresses. I expect this to be their next iCloud+ offering.
I tried element, somehow that keeps kicking him out, or I need to validate new sessions or something.
Also, Signal loves to claim how secure it is, but they will never dare to tell you that participating in the Android and mainstream mobile systems nobody is secure. Especially not on Google Play. If the government wants to spy on you, they WILL! It does not matter if they can't decrypt your messages because they will be sucking the data right off your phone with invisible screenshots and AI transcribing the text or by other means like key logging. There are people who claim Pegasus does not even need you to click on some link anymore, all they need is your phone number. And Pegasus is for sure not the only thing out there.
Signal and others create the illusion of privacy, there is no privacy on any smartphone with any kind of mainstream OS. Probably not even on the "hardened" de-googled Android forks.
Or sama's crypto eyeball scanning thing? (WorldCoin?)
What this does is provide a casual level of privacy. It gets us parity with the phone number hiding in tools like telegram.
https://support.signal.org/hc/en-us/articles/360007059752-Ba...
The process to transfer the history is to scan a QR code displayed on the new phone by the app on the old phone.
Well, the camera on my old iPhone is broken. The phone has 3 other working cameras, but I cannot switch which one the app uses…
update: only on android. turns out there are quite a few caveats for backup. See https://support.signal.org/hc/en-us/articles/360007059752-Ba...
I doubt that's a habit many people will develop for a setting they didn't even know existed.
There's no single obvious thing called "this is what everyone wants from backup".
> It doesn't "require" Syncthing
I'm talking about your solution, and yes it does seem to require syncthing, unless you are using some fourth party tool that sets up syncthing automatically for you, and in that case it still isn't built in to Signal.
There are other possible solutions, but you used your solution as an example. If you have a different solution that doens't require syncthing and also doesn't require manual intervention (i.e. Signal app can automate the process), please share it. Remember what the comment said that we are replying to:
> Please stop peddling this horrible experience as a form of a valid backup. A process that requires full manual interaction and requires you to know ahead of time when your phone will break or be stolen is not a useful backup process.
Did you not have to manually setup syncthing (or some other sync tool) to get it working? Or do you know of some way to do that with just Signal?
Unless you are saying that Signal has a built-in backup solution that doesn't require manual intervention (like configuring some sort of third-party syncing service) then you aren't rebutting anything.
You want signal to fully automate the process of configuring your device with an arbitrary third party service to send backups to with zero "manual intervention"? I think you're asking for the moon on a stick.
It's after all, a device that's carried around and much easier to destroy than pretty much any other.
For most of population (you know, the ones we all want to get onto Signal so they stop using Meta and Apple stuff) not losing their valuable pictures, memories and conversations is way above the paranoia of some theoretical government official deciding to give up while trying to unlock your phone.
Should Signal support/implement all of these? Some of them? Which ones?
Same story with the PIN signal requires if you haven't used it in a few hours. It's the same as your phone PIN and there isn't anywhere you can change it, so it's just security theater.
This is not the Signal PIN. It sounds like you have the Screen Lock option enabled.
https://support.signal.org/hc/en-us/articles/360007059792-Si...
What happened to those arguments now? Were they bullshit this whole time?
The TL;DR is that they collect and forever store sensitive data in the cloud, meaning that the US gov could almost certainly access that data and any other government could access any one person's data too just by brute forcing a PIN
Because I know I don't have that skill set or time. I do have however some big fat red flags on using it because it was opted for by an entity whose entire existence is based around backdoors and spying.
Honestly i find it absurd that some folks say just because something is open source it's automatically safe. The vast majority of us whether the project is open source or not lack the skill or capacity to pick up on a well obfuscated hole. Hell even the best of us aren't that good.