Live data from Hacker News

Signal PINs

signal.org

61–70 of 199 posts

Re: Signal PINs

#61
The way the Signal PIN feature implementation has been handled by the Signal team is extremely disappointing.

The blog post completely fails to explain why this feature is mandatory, and why users are now locked out of being able to view their messages until they setup a PIN. The Signal app has now essentially taken all messages hostage, and users are unable to access messages until they create a PIN.

I am a huge proponent of Signal, but this is unacceptable behavior.

Re: Signal PINs

#62

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

I was quite disappointed as well. I guess the only way to go is to use a strong password, which is NOT "memorizable" and hope that the reminder banner won't show up too often. Very sad ...

Re: Signal PINs

#63
post #2

Don't miss: > PINs will also help facilitate new features like addressing that isn’t based exclusively on phone numbers

I dunno but for example Wire does implement addressing without giving phone number optionally if you sign in with an email and a password, which makes me less convinced of the necessity of forced PINs in this style to enable such cases (which should be optional in the first place). Same thing with syncing across devices which requires you opt in to add email/password combo to enable those features.

Re: Signal PINs

#64
post #13

I don’t want my messages to be stored anywhere other than on my phone. I hate when companies push this bullshit on you. I keep on getting reminders to set a pin and I can’t turn it off. I think one of the issues with software is that because it’s infinitely extensible, people just add more and more features, they don’t know when to stop. So they keep pushing features that satisfy 10% of their users to the detriment o…

I don’t think they plan to store messages, but essentially conversations and contacts. This is in reaction to the number one most requested feature: Allow usage without a phone number.

Re: Signal PINs

#66

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

I think they've messed up badly with this update. I have several friends who want to get rid of Signal because they could not access their messages until they've set up a PIN.

Imagine needing to configure and remember a PIN on the spot when you need to urgently read your messages.

Re: Signal PINs

#67

I've already got a passphrase on my Signal app. Why do I also need a PIN on top of that? If it's supposed to be an easier alternative to a passphrase, then okay, but stop showing me the freaking notification to setup a PIN...

You mean the pre-existing “Registration lock” feature? I think they are using the same pin. I’ve had that set for years and I’ve been getting pin reminders for the last several months and I now see “Change your PIN” in my settings.

Re: Signal PINs

#68
I've been using Signal PINs for a long time to lock the app to my SIM card and unfortunately they are a real pain. This sounds exactly the same.

First off the app is incessant about asking you to enter your PIN to prove you know it; this prompt is supposed to get less frequent and I suppose it does but is still way too frequent. Some of us are competent at storing secrets in a password manager and this is like a punishment for us because it can easily take several minutes to go retrieve the strong password, copy it, paste it in.

It actually reduced the security for me; I started out with maybe a 16 or 20 digit PIN and cut it to a smaller number of digits that I could memorize. (I still haven't memorized them!)

There were also issues with Signal's implementation of the feature. I chose quite a long PIN (>20 digits) at first for security only to find out later from them that it was above the silently imposed limit. Later when I went to verify the PIN it would not work because whatever silent truncation was done when establishing the PIN was not re-performed on verification so it did not recognize the PIN.

Re: Signal PINs

#69
post #24

Earlier quoted context omitted.

There are a million apps which store messages on a server, those users are already on those apps. The thing that differentiated signal is the data-less functionality.

No, the thing that Signal always aimed for was "Making mass surveillance impossible", and "privacy for the masses". If you remove the mass part, you remove the main goal of Signal. The experts can maybe fork Signal, or use Matrix. Then there is always PGP/GPG.

Also if it doesn’t appeal to “Joe Public” then it will remain niche and most people will be stuck using other things to reach friends and family.

Re: Signal PINs

#70

Earlier quoted context omitted.

This is a feature critical for wide adoption. Most users will swear off any app that makes it easy for them to lose all their chats.

That certainly is not a feature I have ever cared about. Do people really scroll back through old chat logs on a regular basis? I wonder why.

I don't know if I would say I do so Regularly, but I find having the history available useful on occasion for remembering or referencing prior discussions. Sometimes there's a link I've shared with one friend that I'd like to share with another friend some indeterminate amount of time later, and so it's convenient to just go to that first conversation and search through it.
Post reply on HN