Live data from Hacker News

Technology preview: Private contact discovery for Signal

signal.org

141–150 of 169 posts

Re: Technology preview: Private contact discovery for Signal

#141
post #100

Earlier quoted context omitted.

> In my opinion the signal ios client is significantly less polished than the telegram client. I could convince my girlfriend to switch to telegram, after she found signal to be intolerable on her android device as well. My reaction is the opposite. I love the signal iOS app because it doesn't try to do SMS. It lets you enter the code which is great if I want to use a Google Voice number instead of a carrier number (…

How much do you use it? I sometimes do 1000+ messages a day and find that it's constantly breaking on me.

Can you make sure any issues are filed over at github.com/WhisperSystems/Signal-iOS ?

Re: Technology preview: Private contact discovery for Signal

#142

When will I be able to sign up without a phone number? The phone number requirement is ridiculous and makes true anonymity incredibly difficult.

This. They had a (hopefully non-technical) justification for this but it's of course completely unnecessary. Your identity could just as easily be a username or a random key. If you need to share that identity you could always do it out of band. I tried to use Signal and even gave it permission to use my contacts when I installed it. Once it found the handful of people I know using it I disabled those permissions. To…

You've been able to use Signal-iOS without contact access for a while.

Re: Technology preview: Private contact discovery for Signal

#143

Earlier quoted context omitted.

In case someone from Open WhisperSystems is reading: please do NOT add stickers and junk to your clean and pretty system. I know a lot of people that would leave the service if it turned into WeChat (including me). Stick to the fundamental engineering of privacy as you are doing, and forget the gimmicks.

> I know a lot of people that would leave the service if it turned into WeChat (including me). Where will they go? To some less secure alternative simply because of stickers?

> To some less secure alternative simply because of stickers?

I'm afraid you really can't rule that out, no.

Re: Technology preview: Private contact discovery for Signal

#144

In case someone from Open WhisperSystems is reading: please add stickers. Seriously, I know so many people who are on Telegram just because of its sticker system and won't consider anything without that feature. This comes up again and again in online discussions where Signal is mentioned, and it hurts to see all the care and effort the OWS team has put into providing real security rejected out of hand because of it.…

Thank you. It only took me a couple of years in East Asia to start feeling frustrated by the lack of nuanced, instant and effortless communication provided by stickers when I message over Signal. I, too, have many friends who would otherwise consider Signal and instead stick with LINE and Messenger for this reason.

Re: Technology preview: Private contact discovery for Signal

#145

I cringed in anticipation of the HN comments on this one. Cue the inevitable HN complaints that it's not perfect security, that you still have to trust your CPU manufacturer, that the app permissions are too invasive, that it uses phone numbers as identifiers, and that it runs on Google play services. Pull your head out of the trees and look at the forest: humanity desperately needs privacy herd immunity, and you are…

> People NEED an alternative to Facebook messenger, Facebook WhatsApp, closed source Viber and Telegram

In a broad sense, they don't actually - being pretty much happy with all these messengers.

Re: Technology preview: Private contact discovery for Signal

#146
post #91

Earlier quoted context omitted.

To succinctly convey emotions, opinions, viewpoints, "feels". To simply have a non-verbal vocabulary, to have a different quality to certain parts of the communication, to signify a different quality of seriousness/playfulness/feeling. It's the new emoticon. :-)

The only thing I could see that would potentially top this would be talking animated emoji....The feces one comes to mind specifically

It it talks, it takes too much time to parse, and it becomes too specific.

Pictures, maybe with a max 0.5 sec animation are okay, and no sound. (At least that's my hunch.)

Re: Technology preview: Private contact discovery for Signal

#147

I cringed in anticipation of the HN comments on this one. Cue the inevitable HN complaints that it's not perfect security, that you still have to trust your CPU manufacturer, that the app permissions are too invasive, that it uses phone numbers as identifiers, and that it runs on Google play services. Pull your head out of the trees and look at the forest: humanity desperately needs privacy herd immunity, and you are…

You might want to try to stop telling people what they may or may not do. You want to stifle possibly valid criticism with dogma by comparing the healthy and informatve discussion here with 'anti-vaxxers'.

Adding to that, nobody in the top 10 root comments is actually "discouraging people from protecting themselves".

Re: Technology preview: Private contact discovery for Signal

#148
post #46

This is definitely interesting (and probably the first end-user-valuable SGX-on-server application I've seen), but there are two issues IMO: 1) Intel SGX isn't really capable of resisting moderately serious physical side channel attacks by someone with physical proximity or access to the server. It's decent for low-value, or widely deployed apps where compromise of a single instance only hurts once user, but for a ce…

What do you mean by moderately serious. Side channels are mostly a software level issue. SGX doesn't try to solve them at the moment. If you mean attack the hardware security in general that'd require decapping the chip itself, right?

Re: Technology preview: Private contact discovery for Signal

#149
post #47

Earlier quoted context omitted.

> Don’t use phone numbers, use usernames! As it turns out, that is far more private and secure. It is. But it's not convenient. Everyone has contact list with numbers and people want to talk to their friends immediately not call them for their ID for service X.

Everyone? I've got basically no phone numbers of many of my friends, or they've switched them so often that the ones I have are long wrong. Half the numbers in my contacts list don't exist anymore. I certainly prefer usernames.

Clearly you're not the target market for Signal but there are many encrypted messangers out there for you.

Re: Technology preview: Private contact discovery for Signal

#150

I cringed in anticipation of the HN comments on this one. Cue the inevitable HN complaints that it's not perfect security, that you still have to trust your CPU manufacturer, that the app permissions are too invasive, that it uses phone numbers as identifiers, and that it runs on Google play services. Pull your head out of the trees and look at the forest: humanity desperately needs privacy herd immunity, and you are…

Here it is again.

>Anything against signal is propaganda and anti-privacy because of the big picture

>anything against telegram is deserved because I've been told it's bad that they rolled their own crypto

Fragmentation/competition in this space is good. If you think whatsapp is less secure than Signal despite the author of this software working on it then maybe you need to evaluate for yourself if he is indeed "a leader in the field".

Post reply on HN