Live data from Hacker News

Disappearing messages for Signal

whispersystems.org

131–140 of 187 posts

Re: Disappearing messages for Signal

#131
post #72

Earlier quoted context omitted.

Indeed. It's not just crypto nerds would want to use the service without having to have a smartphone with a phone number. The phone requirement is beyond ridiculous. How did Signal get the reputation it enjoys in the tech community anyway?

What's a trustworthy alternative?

Wire [1], which I've been trying for the past few months, seems so. It's quite rich in its feature set compared to Signal, all messages are E2E encrypted and provides multi-device sync and multi-platform support.

[1]: https://wire.com

Re: Disappearing messages for Signal

#132
post #22

I've been receiving a bunch of "Bad encrypted message..." lately. Wonder what's up with that.

Tons of those, plus repeats, and "random" delays. Sometimes it takes a few minutes for messages to go through (single check). Last week was really bad. I don't know how multiple messages can happen; shouldn't they have a unique ID?

> and "random" delays. Sometimes it takes a few minutes for messages to go through (single check).

This was the main reason I almost stopped using Signal several months ago and started trying out Wire (which is also slower when compared to Telegram). I find it disappointing that the problem still exists. I can't convince others in my circle to use it if basic message delivery is flakey and slow.

Re: Disappearing messages for Signal

#133

Earlier quoted context omitted.

I would like to be able to re-register a new number without having to de-activate the account thereby not losing all of my chats.

Is there a way from preventing certain contacts from knowing I'm on Signal? Like, it is embarrassing that Jason from college knows I'm on Signal. I know you guys will disagree and say it is not embarrassing, but it seems that a privacy-focused app would respect this notion. Obviously being a member of certain apps (grindr) can be seen as negative. I think I should be able to Whitelist my contacts.

This is a feature I would like not only in Signal, but also in platforms like Telegram and Wire. There are several valid reasons not to announce one's presence on a messaging platform to everyone who somehow has your phone number or address.

Telegram allows using a username to mask sharing the phone number with new contacts, but its initial setup is based on the phone number and it insists on notifying everyone who has your number that you've joined the platform. Messaging platforms would be much better if they considered such things as privacy issues and provided more control in the user's hands, with sensible defaults and good initial setup instructions.

Re: Disappearing messages for Signal

#135

Signal keeps getting better with each release, great job at everyone from Whisper Systems.

I love using Signal and will continue to make modest donations, but I would really appreciate an improvement in audio call quality. I still use Silent Circle for calls because it is so tiring to talk when the bitrate is low.

I'd guess both SC and WhatsApp use opus, whereas Signal at the moment is using speex. There is an issue open at github, but it does not seem to be a priority.

I haven't read very much about it, but there seems to be concerns about opus leaking data about the call. I don't know how, but from android5.0 there is an opus encoder included that supports CBR mode.

Re: Disappearing messages for Signal

#136

Earlier quoted context omitted.

Did FB/WA clarify that they use the OW audio encryption algos, or did they just put the OW 'trophy' on the wall without the actual implementation? WhatsApp is, I agree, very good quality for what it is, but I would never trust it or FB with anything but social/personal calls. Social Media platforms are for other people to hand over their lives to. Let them subsidize my detachment from their usage, and I thank them fo…

Looking at WhatsApps security whitepaper: "WhatsApp calls are also end-to-end encrypted When a WhatsApp user initiates a call: 1 The initiator builds an encrypted session with the recipient (as outlined in Section Initiating Session Setup), if one does not already exist 2 The initiator generates a random 32-byte SRTp master secret 3 The initiator transmits an encrypted message to the recipient that signals an incomin…

SRTP and ZRTP is only for negotiating what to use. You can still use different codecs. I'd guess Wire, WA and SC use opus (since it is by far the best), while signal is still using speex.

ZRTP makes negotiation possible, so a roll-out of opus should be possible without breaking older clients.

Re: Disappearing messages for Signal

#137

Earlier quoted context omitted.

Indeed. It's not just crypto nerds would want to use the service without having to have a smartphone with a phone number. The phone requirement is beyond ridiculous. How did Signal get the reputation it enjoys in the tech community anyway?

Wire ( http://wire.com ) does not need a phone number (register with email on a desktop browser at http://app.wire.com , then login to mobile) and does not need a copy of your contacts. Supports text, image, files, audio, video. E2E encryption is based on Signal protocol. Funded by Skype founder.

Wire uploads your contacts to their service by default (on Android before M, because you nodded at the installation or something). No post installation popup asking you if you want to share them. (August 2016)

Wire has not even a way to remove contacts. I'm not kidding. After the faux pas above I had random 'Wire contacts' that it discovered for me, based on a combination of 'in my address book' and 'in their address book'. You cannot unfriend/remove those, at all. Talked to their support and they actually confirmed that (4th of August, doubt that it changed) you can only _block_ users.

Blocking != removing. If "random ex-coworker" comes up in my list, I might want to remove the contact without blocking the person. One's "Don't care about this contact" vs "This contact has no place in my life".

Bringing Wire up as a decent example for contact handling therefor seems .. strange.

Re: Disappearing messages for Signal

#138
post #126

Earlier quoted context omitted.

I almost installed Wire this afternoon. Unfortunately this part > does not need a copy of your contacts is not quite correct if you read the fine print. From https://wire.com/legal/ > 5.1 Account ... You agree that if you give the App permission to access your address book, anonymized phone numbers and emails from the address book will be uploaded to the Service for the purpose of connecting users.

That's completely optional and not the default. It does what it says, makes known users easier to find,but you can still search for them without that.

This is either new or wrong.

I just posted a sibling comment to the GP: At least in August it wasn't optional and happened automatically on Android, unless you were running M: The permissions requested during installation (contact access, to even have a way to offer this feature) of the app were exercised without asking for further consent and your contacts were shared with their server unconditionally.

Re: Disappearing messages for Signal

#139

Earlier quoted context omitted.

I don't disagree with your general point, but I'm curious, why would having a privacy-focused app be embarassing? I'm curious what kind of attitude you have for it, or what you expect some of your contacts to think of it.

Because it makes me look like a drug dealer. Which is to say it is easy for me to guess why most the people in my contacts who use Signal, use Signal. Some are journalists. Some are tech researchers. The guys with bad jobs who aren't good at computers make me wonder...

Sounds like the image we should move away from, so it gets better for everyone. While I don't disagree with your previous point, I think part of the reason for OWS to do this might be to nudge people like you towards this being mainstream, instead of okay, so why is this guy using this?

Re: Disappearing messages for Signal

#140
post #121

Earlier quoted context omitted.

You can't trust the client. It's the same fundamental flaw with DRM. If that person does not want it archived, you can make it difficult but not impossible.

I don't think it's nearly as difficult as DRM. That feature is mostly a gimmick. A lot like Snapchat's. This might help with security if it takes as long to crack someone's phone as it takes to expire the messages.

Actually, I can get the source code for the client, delete the "auto expire" feature and compile it. So there's nothing stopping anyone from archiving messages you want them to be able to read.
Post reply on HN