Live data from Hacker News

Signal PINs

signal.org

71–80 of 199 posts

Re: Signal PINs

#71
post #66

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

I think they've messed up badly with this update. I have several friends who want to get rid of Signal because they could not access their messages until they've set up a PIN. Imagine needing to configure and remember a PIN on the spot when you need to urgently read your messages.

Interesting, mine keeps nagging me at the bottom of the screen every day, but hasn't forced it on me at all yet.

Re: Signal PINs

#72

Earlier quoted context omitted.

This is a feature critical for wide adoption. Most users will swear off any app that makes it easy for them to lose all their chats.

That certainly is not a feature I have ever cared about. Do people really scroll back through old chat logs on a regular basis? I wonder why.

Absolutely. I just searched way back one chat to find the size of a bike helmet I bought that I had mentioned there years ago, as mine has been stolen this afternoon. Others contain fond memories, cooking recipes, there is a group chat we have with locations and restaurants to visit. It's been useful on many occasions to have those logs as a kind of informal diary, because I mention most important events to at least one of my closest remote friends. Not having persistent chat logs is a dealbreaker for me.

Re: Signal PINs

#74

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

I’d really like to have a more sane version of Signal as a fork, which allows the maintaining of compatibility, but given how hostile they’ve been towards this sort of thing I suspect it would be unmaintainable.

From what I understand, they are fine with forks of Signal as long as these forks have distinct branding and don't depend on OWS services to operate, I'd imagine because they don't want the operational burden of ensuring the compatibility of third party clients nor confused users going to OWS for support instead of the third party devs.

Which, imo, is a pretty reasonable decision.

Re: Signal PINs

#75
post #71
post #66

Earlier quoted context omitted.

I think they've messed up badly with this update. I have several friends who want to get rid of Signal because they could not access their messages until they've set up a PIN. Imagine needing to configure and remember a PIN on the spot when you need to urgently read your messages.

Interesting, mine keeps nagging me at the bottom of the screen every day, but hasn't forced it on me at all yet.

Samezies

Re: Signal PINs

#77
post #57

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

It's not optional because its purpose is incompatible with that. They want to add signal identifiers that aren't phone numbers. If such identifiers are to communicate with you, you need to store what's necessary.

> It's not optional because its purpose is incompatible with that.

I don't blame signal for forcing strong PINs, I don't know what's their purpose, but non phone number identifiers don't require cloud storage. The contact list (with the associated public keys) does.

What? How? You just need a key (password). If you are able to log into that "identified" then you are online with that and others can message you on that, and the network will route messages to your client.

There's nothing to store up to this point.

And if people want backups they can optionally enable that. Or the network could support multiple clients signed in for the same "identified" and allow those authenticated and authorized clients to sync/backup among themselves.

Re: Signal PINs

#78
post #66

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

I think they've messed up badly with this update. I have several friends who want to get rid of Signal because they could not access their messages until they've set up a PIN. Imagine needing to configure and remember a PIN on the spot when you need to urgently read your messages.

I've lobbied for signal, and gotten friends and family to join. Most are annoyed by the PINs and some have left.

Their handling of PINs seems quite contrary to their goal of pretty good security for the largest possible number of people.

It's VERY frustrating to have your device asking for pins every time you use it. I'm trying to protect from attackers on the internet, not someone who is going to assault me. After all if they assault me for my phone they can assault me for my pin. Single devs need to read https://xkcd.com/538/

Re: Signal PINs

#79
post #78
post #66

Earlier quoted context omitted.

I think they've messed up badly with this update. I have several friends who want to get rid of Signal because they could not access their messages until they've set up a PIN. Imagine needing to configure and remember a PIN on the spot when you need to urgently read your messages.

I've lobbied for signal, and gotten friends and family to join. Most are annoyed by the PINs and some have left. Their handling of PINs seems quite contrary to their goal of pretty good security for the largest possible number of people. It's VERY frustrating to have your device asking for pins every time you use it. I'm trying to protect from attackers on the internet, not someone who is going to assault me. After a…

That's not what the PINs are for.

Re: Signal PINs

#80
post #44

Earlier quoted context omitted.

The PIN is a very short key, so the only real protection is that Intel SGX (which notably gets broken every year, and so this doesn't actually work) is preventing people from getting access to the encrypted data to brute force the key; the enclave then enforces some limit on the number of attempts (and maybe some rate limit on the speed of attempts).

The client allows them to be alphanumeric, but the default is 4 numbers. The irritating behaviour of repeatedly asking for it to be entered at awkward times means people will just set it to 1337 and call it a day.

I used my debit card PIN, so I should be fine right?
Post reply on HN