Live data from Hacker News

Disappearing messages for Signal

whispersystems.org

31–40 of 187 posts

Re: Disappearing messages for Signal

#32
post #22

I've been receiving a bunch of "Bad encrypted message..." lately. Wonder what's up with that.

Tons of those, plus repeats, and "random" delays. Sometimes it takes a few minutes for messages to go through (single check). Last week was really bad. I don't know how multiple messages can happen; shouldn't they have a unique ID?

Yeah. My understanding is the message key used to decrypt first copy should be immediately deleted after decrypting it, so how can the second copy be decrypted successfully? Seems to fly in the face of forward secrecy unless it's purely a client side bug.

Bad encrypted message, if I recall correctly, means either the MAC check failed or the protobuf payload inside didn't deserialize correctly.

I don't know.. I'm not setup to debug it on my regular phone with a production signal apk installed.

Re: Disappearing messages for Signal

#33

Earlier quoted context omitted.

Good point, the internet does make the upsell much much much more in-your-face.

It's more than that; I'm old enough to have carried a compact Spanish-English dictionary while traveling. An unabridged dictionary was heavy enough that you couldn't hold it in one hand. In other words, there used to be such a thing as 'too much dictionary'. Now, like any other information source, it's the size of my phone, except when it's the size of my laptop.

I remember the complete Oxford dictionary in my school library because it stretched over many large volumes. Forget holding it, you need a trolley!

Re: Disappearing messages for Signal

#35
post #27

Earlier quoted context omitted.

Tons of those, plus repeats, and "random" delays. Sometimes it takes a few minutes for messages to go through (single check). Last week was really bad. I don't know how multiple messages can happen; shouldn't they have a unique ID?

Last week was due to server issues https://whispersystems.discoursehosting.net/t/intermittent-m...

I saw the mailing list post, then got the bad messages a day later. Probably the same issue, still curious about the technical details though.

Re: Disappearing messages for Signal

#36

How do they make money?

If you want to implement the signal protocol for your own company (see WhatsApp, Messenger, Allo, ...) you will probably have to buy a license ($$$), and ask for their help ($$).

* https://whispersystems.org/blog/whatsapp-complete/

* https://whispersystems.org/blog/allo/

* https://whispersystems.org/blog/facebook-messenger/

Re: Disappearing messages for Signal

#37

Signal keeps getting better with each release, great job at everyone from Whisper Systems.

I love using Signal and will continue to make modest donations, but I would really appreciate an improvement in audio call quality. I still use Silent Circle for calls because it is so tiring to talk when the bitrate is low.

Re: Disappearing messages for Signal

#38
Cool feature, though it'd be nice if Signal fixed the message delay and message dropping problem. But Signal uses the proprietary GCM service (because "it's impossible to do message sending correctly, so let's force people to use proprietary software") so they probably can't fix it...

Re: Disappearing messages for Signal

#39
I love Signal and this seems to be a stab at Wickr since from what I've heard that is the reason people prefer it to Signal sometimes. Having said that, it has a couple of problems:

1. Images are downsampled without warning. There should be some sort of warning or mini info box for the times when the images are downsampled and there should be information about the changes in resolution.

2. If one uses it as the main messaging app, one has to search through history sometimes. But there is no chat search feature. I am forced to scroll all the way up and copy the message data to an editor. Even really basic case insensitive search would be great.

Re: Disappearing messages for Signal

#40
post #30
post #9

Earlier quoted context omitted.

If their sense is that -- after configuring 1 week self destruct, the people they're talking to likely won't be keeping months and months of chat logs on their phone anymore -- it's a very true sense of security.

[deleted]

What good is a seatbelt if the person sitting next to you can stab you? The blog post makes a point of this not being secure if the person you're messaging is malicious and that's not what it's for.

I think these two comments make good points:

I just had an interesting conversation with a friend who was recommending that I use Telegram/Wickr, and I told him that Signal was where it's at. Then he asked me if it had self-destructing messages, and I said "Why bother? That can be easily circumvented". His reply was that in some countries phones had been confiscated, and even though one person had enabled local encryption, the user with the confiscated phone had not enabled it; thereby implicating everyone who had communicated with that person (even though the messages were delivered secure over the network). So while self-destructing messages are in many ways a flawed guarantee of privacy, they can perform a very useful function in cases where the users are not malicious, but rather are security ignorant (i.e. most people with a phone).

https://whispersystems.discoursehosting.net/t/automatically-...

I've always been thinking that the critique of such a feature is based on a false underlying premise.

Yes, it's true that the recipient can make a screenshot of the message. But the recipient in the absolute majority of cases is not a "threat" in a classical sense, not someone with bad intentions or someone who is not supposed to know the contents of that message. After all, the sender trusts the recipient, as he is the one sending the message to the recipient in the first place.

The usual scenario is a recipient who is not that security-aware and doesn't think about those things that much if at all. Personally, I'd say most of my contact are that way.

The sender might send this recipient a message containing something especially critical, say, a user name and a corresponding password, and doesn't want to see that information in the wrong hands if e. g. later on, the recipient loses their phone, the phone gets stolen, etc. Also note that this kind of recipient is unlikely to use a general passphrase for Signal as this lessens convenience.

So what's essentially happening here is a security-minded sender taking security measures for or in place of a thrustworthy, albeit forgetful, non-security-minded, etc recipient.

https://whispersystems.discoursehosting.net/t/automatically-...

Post reply on HN