Live data from Hacker News

Disappearing messages for Signal

whispersystems.org

121–130 of 187 posts

Re: Disappearing messages for Signal

#121

Earlier quoted context omitted.

What if the person you're chatting with does not want it archived? (I'm not questioning, but wondering what a protocol would be)

You can't trust the client. It's the same fundamental flaw with DRM. If that person does not want it archived, you can make it difficult but not impossible.

I don't think it's nearly as difficult as DRM. That feature is mostly a gimmick. A lot like Snapchat's.

This might help with security if it takes as long to crack someone's phone as it takes to expire the messages.

Re: Disappearing messages for Signal

#122

Earlier quoted context omitted.

Is there a way from preventing certain contacts from knowing I'm on Signal? Like, it is embarrassing that Jason from college knows I'm on Signal. I know you guys will disagree and say it is not embarrassing, but it seems that a privacy-focused app would respect this notion. Obviously being a member of certain apps (grindr) can be seen as negative. I think I should be able to Whitelist my contacts.

I don't disagree with your general point, but I'm curious, why would having a privacy-focused app be embarassing? I'm curious what kind of attitude you have for it, or what you expect some of your contacts to think of it.

Because it makes me look like a drug dealer. Which is to say it is easy for me to guess why most the people in my contacts who use Signal, use Signal. Some are journalists. Some are tech researchers. The guys with bad jobs who aren't good at computers make me wonder...

Re: Disappearing messages for Signal

#123
post #104

Earlier quoted context omitted.

Wire ( http://wire.com ) does not need a phone number (register with email on a desktop browser at http://app.wire.com , then login to mobile) and does not need a copy of your contacts. Supports text, image, files, audio, video. E2E encryption is based on Signal protocol. Funded by Skype founder.

Wire does not use Signal Protocol, they used some of our code to create a protocol of their own devising that we do not recommend.

Why do you not recommend? Hopefully you're not just saying that because they aren't Signal..

------------------------------------------------

I've been using Wire for a few weeks now and I'm absolutely happy. They recently released a linux client https://medium.com/wire-news/get-your-linux-on-999403a1a4fe#... (not a chrome app!) (though I think it's electron).

I'm quite happy with them, give them a try.

Re: Disappearing messages for Signal

#124

Signal keeps getting better with each release, great job at everyone from Whisper Systems.

I love using Signal and will continue to make modest donations, but I would really appreciate an improvement in audio call quality. I still use Silent Circle for calls because it is so tiring to talk when the bitrate is low.

I've never noticed a quality issue... because I've never had a call connect at all (to be fair, it's been a while since I accidentally clicked the "call" button and checked, since I've long given up on trying to use it deliberately).

Re: Disappearing messages for Signal

#125
post #102

Earlier quoted context omitted.

Only a small subset of people will be messaged with the app, it does not need access to the entire address book.

They have explained what the permission is needed for http://support.whispersystems.org/hc/en-us/articles/21253585... They have a privacy policy https://whispersystems.org/signal/privacy/ They have explained their reasoning https://whispersystems.org/blog/contact-discovery/ You have access to the source https://github.com/WhisperSystems You have proof that they don't store your contacts and can't provide them even af…

I'm not the poster who you replied to, but - Just because someone explains their reasoning, doesn't mean you have to agree with them :)

I don't particularly want to send Signal a list of contacts - I'd rather not leak that information about my social graph. I understand how they want to use that information for discovery, so they can know who already uses the app.. But for my needs, this isn't necessary. I'd prefer to manually ask my friends for their username on the service.

If there were additional options, I might choose to use their service. As it is, it doesn't fit my needs, and that's OK.

I'm sure there's plenty of other people who appreciate it.

Re: Disappearing messages for Signal

#126

Earlier quoted context omitted.

Wire ( http://wire.com ) does not need a phone number (register with email on a desktop browser at http://app.wire.com , then login to mobile) and does not need a copy of your contacts. Supports text, image, files, audio, video. E2E encryption is based on Signal protocol. Funded by Skype founder.

I almost installed Wire this afternoon. Unfortunately this part > does not need a copy of your contacts is not quite correct if you read the fine print. From https://wire.com/legal/ > 5.1 Account ... You agree that if you give the App permission to access your address book, anonymized phone numbers and emails from the address book will be uploaded to the Service for the purpose of connecting users.

That's completely optional and not the default. It does what it says, makes known users easier to find,but you can still search for them without that.

Re: Disappearing messages for Signal

#127

I'm not sure I like the UX for the disappearing messages. Having a little hourglass after every message breaks the flow up. I'd rather see the message bubbles be black instead of blue. It's also not intuitive to tap on a recipient's name to enable disappearing messages. Lastly, maybe messaging should default to 1 week disappearing messages...

I was thinking that too.

I actually want my messages to just be deleted every month, but w.e. I'll take it.

Re: Disappearing messages for Signal

#128
post #7
post #3

Earlier quoted context omitted.

"Disappearing messages are a way for you and your friends to keep your message history tidy. They are a collaborative feature for conversations where all participants want to automate minimalist data hygiene, not for situations where your contact is your adversary — after all, if someone who receives a disappearing message really wants a record of it, they can always use another camera to take a photo of the screen b…

This should be strictly a recipient controlled option, only affecting the recipient's view then. Anything else is still a misleading UX for the sender, and assumes people read the fine print. They don't.

This is horrible logic and ignores important opt-in/opt-out dynamics which are critical to our conception of privacy. By enabling "self-destruct," (or "disappear") the sender merely forces the recipient to "opt-in" and take affirmative action in order to archive the message (i.e. Screenshot). This is how telephone conversations generally work -- no recording unless one party takes action to tape it. Despite this ability to tape, we certainly still consider telephone to be more "secure" due to this archival distinction. Very often it is the advice of lawyers to avoid putting something in writing, and communicate it in person or over the phone instead. Disappearing messages brings us closer to this desirable ephermerality.

Re: Disappearing messages for Signal

#129
> Hexadecimal isn't compatible with all alphabets, so it left a lot of people out.

Not ... really. Latin characters are available in every locale. Virtually anyone literate enough to use signal is going to distinguish the latin letters A through F. You reading this, I'm assuming you're not literate in Greek, but can you distinguish the letters α, β, γ, and δ, even if you cannot name them? Don't bring up CJK; virtually no one in this day and age is functionally literate in any CJK language that can't read the Latin alphabet.

Let's take the hypothetical person literate in another script who is completely unfamiliar with the letters ABCDEF. They don't use our arabic numerals either. If you need to localize arabic numerals, why on earth couldn't you localize hexadecimal, too?

Obviously, hexadecimal is not friendly to the layperson as a means of representing numeric quantities. But neither is comparing two 60 decimal digit numbers as a means of authentication. I don't think it's inherently easier for a layperson to match 60 decimal digits versus 50 hexadecimal digits.

Re: Disappearing messages for Signal

#130

Earlier quoted context omitted.

Indeed. It's not just crypto nerds would want to use the service without having to have a smartphone with a phone number. The phone requirement is beyond ridiculous. How did Signal get the reputation it enjoys in the tech community anyway?

Wire ( http://wire.com ) does not need a phone number (register with email on a desktop browser at http://app.wire.com , then login to mobile) and does not need a copy of your contacts. Supports text, image, files, audio, video. E2E encryption is based on Signal protocol. Funded by Skype founder.

And Wire is multi-platform with multi-device sync (like Telegram, except that on Wire all messages are E2E encrypted, not just secret chats), which Signal does not provide in a similar way.

I still use Telegram for the most part, Wire for some, and Signal the least - this is mainly due to the user experience, feature set and speed of message delivery.

Post reply on HN