Live data from Hacker News

Signal PINs

signal.org

91–100 of 199 posts

Re: Signal PINs

#91
post #6

This is all well and good. But the forced/unsilenceable pin reminders seems a bit obtuse to me. https://support.signal.org/hc/en-us/articles/360007059792-Si... "Can I turn off these reminders? It is important to memorize your PIN, and the reminders cannot be disabled. We cannot recover your PIN if you forget it. You will see the reminders less frequently if you consistently enter your PIN correctly. The reminders wil…

I know my PIN yet it asks me everytime I open the app. It's extremely annoying. I wouldn't mind once a month, but it seems like it's 1 a week (which doesn't seem true, I feel like it's more every 2-3 days for me). I just wish there was an option to ask less frequently.

It asks you to make it a habit.

> I just wish there was an option to ask less frequently.

It asks you when you open Signal until you lock it again, no? (At least on Android.)

Re: Signal PINs

#92

Earlier quoted context omitted.

The client allows them to be alphanumeric, but the default is 4 numbers. The irritating behaviour of repeatedly asking for it to be entered at awkward times means people will just set it to 1337 and call it a day.

I used my debit card PIN, so I should be fine right?

Bank level encryption. Yep, fine.

Re: Signal PINs

#94
post #91

Earlier quoted context omitted.

I know my PIN yet it asks me everytime I open the app. It's extremely annoying. I wouldn't mind once a month, but it seems like it's 1 a week (which doesn't seem true, I feel like it's more every 2-3 days for me). I just wish there was an option to ask less frequently.

It asks you to make it a habit. > I just wish there was an option to ask less frequently. It asks you when you open Signal until you lock it again, no? (At least on Android.)

I don't need a habit, I have a password manager.

Re: Signal PINs

#95
post #6

This is all well and good. But the forced/unsilenceable pin reminders seems a bit obtuse to me. https://support.signal.org/hc/en-us/articles/360007059792-Si... "Can I turn off these reminders? It is important to memorize your PIN, and the reminders cannot be disabled. We cannot recover your PIN if you forget it. You will see the reminders less frequently if you consistently enter your PIN correctly. The reminders wil…

I know my PIN yet it asks me everytime I open the app. It's extremely annoying. I wouldn't mind once a month, but it seems like it's 1 a week (which doesn't seem true, I feel like it's more every 2-3 days for me). I just wish there was an option to ask less frequently.

[deleted]

Re: Signal PINs

#96
post #66

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

I think they've messed up badly with this update. I have several friends who want to get rid of Signal because they could not access their messages until they've set up a PIN. Imagine needing to configure and remember a PIN on the spot when you need to urgently read your messages.

Can the pin be 1111? I use a similar pin for the app Threema. Better than nothing I guess and easy to remember. (Also, after restarting the device I have to enter a complicated password.)

Edit: Now I see. Signal wants to save data in the cloud. My Threema PIN is just for my device.

Re: Signal PINs

#97
post #9
post #6

This is all well and good. But the forced/unsilenceable pin reminders seems a bit obtuse to me. https://support.signal.org/hc/en-us/articles/360007059792-Si... "Can I turn off these reminders? It is important to memorize your PIN, and the reminders cannot be disabled. We cannot recover your PIN if you forget it. You will see the reminders less frequently if you consistently enter your PIN correctly. The reminders wil…

I agree. Shouldn't you put your PIN in a password manager anyway? Why call it a PIN and not a password to begin with? Is there a difference I'm missing?

Newer products seem to be tending to label something a PIN if it isn't stored by a third party, because this means it can't get stolen, and as a result it's safe to choose relatively weak human memorable secrets that would be unsuitable as a traditional "password" that we're all using password managers to store instead.

For example a Yubico Security Key can use a PIN. So I could use that as second factor for my Facebook. No matter how lazy, incompetent or even malevolent Facebook is, they never see that PIN, they just get a bitflag in which the Security Key promises it confirmed my identity before authenticating. If they insisted and I allowed them to, they could verify it's a real Yubico brand product (in reality Facebook don't do that) and maybe trust the bitflag on that basis, but even then they aren't learning what PIN I set, how long it is, anything useful.

You probably don't want to store such PINs in a Password Manager, although it's unlikely to be a big security problem to do so, they are intended to be human memorable unlike a "good" modern password.

Re: Signal PINs

#98

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

>I guarantee you, the vast majority of Signal users are only using it because they have some weird privacy-obsessed friend (i.e. us) that has roped them into using it. They don't care enough about Signal to memorize a PIN and get constantly tested on whether they remember it. They want it to just work.

This cannot be stressed enough

Re: Signal PINs

#99
post #90

I'm looking forward to hearing how they plan to prevent brute-forcing of these. A physical hardware device can wipe keys after a certain number of failures. I definitely look forward to the ability to move Signal forward to a new device without losing all logs, and the ability to use Signal without tying it to a phone number.

Basically, SGX: https://github.com/signalapp/SecureValueRecovery The enclave is hardened against Spectre and LVI with this (BOLT/LLVM based), and other techniques: https://github.com/signalapp/BOLT The last build step before signing is a verifier that checks that there are no missed mitigations, built using Intel Xed, to try to avoid potential missing mitigations due to an LLVM or BOLT bug.

I'm familiar with Signal's usage of enclaves. The case I'm wondering about is what happens if someone seized (or surreptitiously accessed) Signal's servers, ran the unmodified enclaves, but fed in different PIN requests to those enclaves in a brute-forcing attempt. What prevents that?

Re: Signal PINs

#100
post #68

I've been using Signal PINs for a long time to lock the app to my SIM card and unfortunately they are a real pain. This sounds exactly the same. First off the app is incessant about asking you to enter your PIN to prove you know it; this prompt is supposed to get less frequent and I suppose it does but is still way too frequent. Some of us are competent at storing secrets in a password manager and this is like a puni…

I've found that tapping next to the registration lock PIN prompt will dismiss it on Android. A "dismiss" button and a "don't ask me again, I won't lose this" checkmark would make much more sense to me.

> "don't ask me again, I won't lose this"

This option should be labelled according to the reality rather than people's wishful thinking

"Don't ask me again, when I lose this I am OK with losing the account and messages"

There's probably a pithier way to express that we could get into the common lexicon as I foresee it being useful in many places. Maybe we can just label it "Yolo!" ?

Post reply on HN