Live data from Hacker News

Signal PINs

signal.org

31–40 of 199 posts

Re: Signal PINs

#31
post #13

I don’t want my messages to be stored anywhere other than on my phone. I hate when companies push this bullshit on you. I keep on getting reminders to set a pin and I can’t turn it off. I think one of the issues with software is that because it’s infinitely extensible, people just add more and more features, they don’t know when to stop. So they keep pushing features that satisfy 10% of their users to the detriment o…

Does it say that they're storing messages? The examples are all the metadata "Signal provides private groups, private contact discovery, private profiles, etc". I interpreted this as saying that my groups and contacts are synced, not the content of the messages.

Re: Signal PINs

#32
post #5

This really worries me: now the safety of my data hinges on Intel's remote attestation and a password I can remember.

> and a password I can remember. This is going to be the reality of any data system which you want to have complete control over. I suppose it could also be a complex key you instead keep on your drive, but that has risks as well.

The previous status quo was that nobody had the data other than your device.

Re: Signal PINs

#33
post #9

Earlier quoted context omitted.

I agree. Shouldn't you put your PIN in a password manager anyway? Why call it a PIN and not a password to begin with? Is there a difference I'm missing?

Same reason iPhones support PINs. It’s easier for the user, and provides some level of protection versus nothing. If it’s not user friendly, the user will defer to convenience over security. Signal PINs do support alphanumeric strings FYI. If you have a password manager, use a string. If not, a PIN works just fine.

It seems alphanumeric PINs are allowed now. At least on iOS, I do get the option to change the PIN to an alphanumeric one.

The whole PIN thing has changed quite a bit in the past 6 months or so.

Re: Signal PINs

#35

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

> I don't care about their Intel SGX whatever because I don't want to have to trust their servers in the first place.

Yeah: particularly given how Intel SGX gets broken every year :/... prime+probe, foreshadow, load value injection, plundervolt... Moxie's fetish for Intel SGX is extremely concerning.

Re: Signal PINs

#36

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

I’d really like to have a more sane version of Signal as a fork, which allows the maintaining of compatibility, but given how hostile they’ve been towards this sort of thing I suspect it would be unmaintainable.

Re: Signal PINs

#37
post #9
post #6

This is all well and good. But the forced/unsilenceable pin reminders seems a bit obtuse to me. https://support.signal.org/hc/en-us/articles/360007059792-Si... "Can I turn off these reminders? It is important to memorize your PIN, and the reminders cannot be disabled. We cannot recover your PIN if you forget it. You will see the reminders less frequently if you consistently enter your PIN correctly. The reminders wil…

I agree. Shouldn't you put your PIN in a password manager anyway? Why call it a PIN and not a password to begin with? Is there a difference I'm missing?

My understanding is it's designed around making short passwords more secure by trying to limit brute force attacks. Seems interesting.

https://signal.org/blog/secure-value-recovery/

Re: Signal PINs

#38
If you lose your phone and pin, how much does someone have to bruteforce to recover your messages on a new phone?

Surely they'd have to do more work than iterate through a possibly as small as 4-digit key?

Re: Signal PINs

#39

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

Does homefort sync over the lan or it requires a 3rd party/ proxy broker? It says "The mobile app connects to your home computer" which concerns me a bit as it sounds like a VNC headline.

Re: Signal PINs

#40

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

Isn't the point of something like this PIN that the only thing stored on the cloud is an encrypted blob that they don't have the keys to? That way it doesn't matter if SGX or similar breaks or not, since the encryption is only happening on your devices. The PIN is the key.
Post reply on HN