Live data from Hacker News

Signal PINs

signal.org

51–60 of 199 posts

Re: Signal PINs

#51
post #24

Earlier quoted context omitted.

This is a feature critical for wide adoption. Most users will swear off any app that makes it easy for them to lose all their chats.

There are a million apps which store messages on a server, those users are already on those apps. The thing that differentiated signal is the data-less functionality.

What do you mean data-less? By design there has always been a Signal server.

Signal should not stay as the simplest possible iteration of an encrypted chat application. If we want more people to use privacy-concious applications, those applications need to evolve.

Re: Signal PINs

#52

Earlier quoted context omitted.

Does homefort sync over the lan or it requires a 3rd party/ proxy broker? It says "The mobile app connects to your home computer" which concerns me a bit as it sounds like a VNC headline.

The idea is to use try to use NAT traversal (i.e. STUN or UPnP) to get a direct connection, and otherwise relay (i.e. TURN) with end-to-end encryption. I'm hoping IPv6 will eventually allow direct connections everywhere so nothing needs to be relayed. I haven't built that stuff yet though so the current version requires that your home computer has a public IP address and that you open a port in your router. Obviously…

Check out zerotier; I've been looking at similar p2p techniques and ZT does a good job of packaging them all up with a relaying fallback.

Re: Signal PINs

#53
This was bound to happen. Signal is a non-federated messenger controlled by a single organization hostile to alternative clients. It isn't much better than WhatsApp/Facebook.

Re: Signal PINs

#54

If you lose your phone and pin, how much does someone have to bruteforce to recover your messages on a new phone? Surely they'd have to do more work than iterate through a possibly as small as 4-digit key?

If I understand the settings correctly (just opened Signal on my phone to explore this), you can require the PIN for re-registering (like after losing a device) and set up a 7-day lockout for failed PIN entries (not sure the number of permitted failures before lockout). This would greatly reduce the speed of brute force, though could also be used for a nice denial of service.

Re: Signal PINs

#55

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

I’d really like to have a more sane version of Signal as a fork, which allows the maintaining of compatibility, but given how hostile they’ve been towards this sort of thing I suspect it would be unmaintainable.

They don't block third party clients ala WhatsApp, but going on GitHub and arguing with people isn't a good thing either :/

Re: Signal PINs

#56

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

I’d really like to have a more sane version of Signal as a fork, which allows the maintaining of compatibility, but given how hostile they’ve been towards this sort of thing I suspect it would be unmaintainable.

I think I liked Signal better when it was just encrypting text and sending it over SMS. I noticed recently that someone has been maintaining such a fork, under the name "Silence", but haven't had a chance to try it yet.

Re: Signal PINs

#57

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

It's not optional because its purpose is incompatible with that.

They want to add signal identifiers that aren't phone numbers. If such identifiers are to communicate with you, you need to store what's necessary.

Re: Signal PINs

#59
post #13

I don’t want my messages to be stored anywhere other than on my phone. I hate when companies push this bullshit on you. I keep on getting reminders to set a pin and I can’t turn it off. I think one of the issues with software is that because it’s infinitely extensible, people just add more and more features, they don’t know when to stop. So they keep pushing features that satisfy 10% of their users to the detriment o…

This is a feature critical for wide adoption. Most users will swear off any app that makes it easy for them to lose all their chats.

That certainly is not a feature I have ever cared about. Do people really scroll back through old chat logs on a regular basis? I wonder why.

Re: Signal PINs

#60
post #4

That's kinda weird timing. Signal's been asking me for a PIN for about 2 weeks now. Did Aurora screw up and give me an early version? Or did they just roll this out to users weeks ahead of publishing an announcement?

> Signal's been asking me for a PIN for about 2 weeks now. And my copy started preventing me from using it entirely yesterday with a full-screen un-dismissable popup[1] :( [1]: https://i.redd.it/4sip5dcw9iy41.png [2] [2]: https://www.reddit.com/r/signal/comments/giw4if/the_signal_p...

I just got the nag-alert a couple days ago. I don't really want to set a PIN, so I have been ignoring it. If they are going to force us all into the new system, maybe it is time to stop putting up with Signal's constant forced-upgrade treadmill and find some other means of secure communication.
Post reply on HN