Live data from Hacker News

Signal PINs

signal.org

131–140 of 199 posts

Re: Signal PINs

#131

Don't understand the negative comments here and on their subreddit... Secure Value Recovery and the associated PIN seems like an advance in the state of the art -- nobody else seems to do this. All users have to do is remember a few numbers. I find it surprising that many users got so upset by the software asking them to set a password that they removed the app... seems a bit extreme. I guess if it was part of a "sig…

>nobody else seems to do this

Plenty of apps add annoyances and nags for new features that uses don't necessarily care about. They correspondingly lose users and gain ire for doing so.

That the motivation and end feature is good is beside the point - they have simply gone about this in a very abrasive way and seem to think they 'know better'.

Re: Signal PINs

#132

Don't understand the negative comments here and on their subreddit... Secure Value Recovery and the associated PIN seems like an advance in the state of the art -- nobody else seems to do this. All users have to do is remember a few numbers. I find it surprising that many users got so upset by the software asking them to set a password that they removed the app... seems a bit extreme. I guess if it was part of a "sig…

Another number?

I have a pin for my sim-card, a pin for the phone encryption, pins for each of my 4 credit cards, a pin for the office door, a pin for my work phone, a pin for the computer smart-card login..

I'm very fine with not having a pin for Signal.

Re: Signal PINs

#133

Earlier quoted context omitted.

No, the thing that Signal always aimed for was "Making mass surveillance impossible", and "privacy for the masses". If you remove the mass part, you remove the main goal of Signal. The experts can maybe fork Signal, or use Matrix. Then there is always PGP/GPG.

Also if it doesn’t appeal to “Joe Public” then it will remain niche and most people will be stuck using other things to reach friends and family.

PINs kind of hinder that, wouldn't you agree?

Re: Signal PINs

#134
post #6

This is all well and good. But the forced/unsilenceable pin reminders seems a bit obtuse to me. https://support.signal.org/hc/en-us/articles/360007059792-Si... "Can I turn off these reminders? It is important to memorize your PIN, and the reminders cannot be disabled. We cannot recover your PIN if you forget it. You will see the reminders less frequently if you consistently enter your PIN correctly. The reminders wil…

I know my PIN yet it asks me everytime I open the app. It's extremely annoying. I wouldn't mind once a month, but it seems like it's 1 a week (which doesn't seem true, I feel like it's more every 2-3 days for me). I just wish there was an option to ask less frequently.

> it asks me everytime I open the app

According to this, the prompts should settle down to once every 14 days:

https://support.signal.org/hc/en-us/articles/360007059792-Si...

Re: Signal PINs

#135
post #24

Earlier quoted context omitted.

There are a million apps which store messages on a server, those users are already on those apps. The thing that differentiated signal is the data-less functionality.

No, the thing that Signal always aimed for was "Making mass surveillance impossible", and "privacy for the masses". If you remove the mass part, you remove the main goal of Signal. The experts can maybe fork Signal, or use Matrix. Then there is always PGP/GPG.

Is the Signal server source code and build environment out yet?

Re: Signal PINs

#136
post #13

I don’t want my messages to be stored anywhere other than on my phone. I hate when companies push this bullshit on you. I keep on getting reminders to set a pin and I can’t turn it off. I think one of the issues with software is that because it’s infinitely extensible, people just add more and more features, they don’t know when to stop. So they keep pushing features that satisfy 10% of their users to the detriment o…

If Signal really puts messages onto their servers behind easy to brute force PINs with the only protection being the SGX pixie dust, and maintainers really don't see a problem with it, then the end to end promise of Signal becomes moot and I'd feel that they'd have betrayed their user's privacy.

However, this is not what they are announcing. Signal does not store any message content in the cloud. It's only your address book as well as the list of blocked accounts. So that you don't completely start from scratch when you lose your phone. This makes total sense.

If you assume that SGX is insecure and Signal can just brute force the PINs (definitely a legitimate view!), then address book equivalent data is already available to Signal in the form of who-talks-to-whom metadata. The only difference is that the metadata needs to be collected over a time span while address books only require short time compromises of the architecture. But this is a minor regression in security, for a large gain in usability.

Re: Signal PINs

#137

Earlier quoted context omitted.

No, the thing that Signal always aimed for was "Making mass surveillance impossible", and "privacy for the masses". If you remove the mass part, you remove the main goal of Signal. The experts can maybe fork Signal, or use Matrix. Then there is always PGP/GPG.

Is the Signal server source code and build environment out yet?

It's been out for at least 4 years.

https://github.com/signalapp/Signal-Server

Re: Signal PINs

#138
post #6

This is all well and good. But the forced/unsilenceable pin reminders seems a bit obtuse to me. https://support.signal.org/hc/en-us/articles/360007059792-Si... "Can I turn off these reminders? It is important to memorize your PIN, and the reminders cannot be disabled. We cannot recover your PIN if you forget it. You will see the reminders less frequently if you consistently enter your PIN correctly. The reminders wil…

I actually like that it forces you to remember the PIN.

That's lovely, but once you've remembered it?

I'm never going to forget my mobile number, I don't need to keep calling myself to remember it.

Re: Signal PINs

#139
post #112

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

Right now if you re-install Signal on your device, you lose all your messages. That's already a very bad user experience, but imagine how much worse it would be if you lost your entire address book in that moment as well. Right now that's not a problem because your social graph is in the address book on your phone, and isn't managed by Signal. This is one of the primary reasons that Signal uses phone numbers for addr…

There must be at least 99% of the users that have phone number contacts only, because dealing with usernames is a hassle to begin with. And why not store username-only contacts in the phones normal address book to begin with?

Why force this "feature" on everyone? There is ZERO reason for Signal to do this. I might as well use WhatsApp if you're going to start doing this shit, but I guess that's the point.

Re: Signal PINs

#140
This post is about the UX, not about the crypto:

Meanwhile on Telegram everything just works more or less as is has always done.

If I click on settings I get a "menu" called "Passcode & Face ID". There's a button saying "Turn Passcode On", and a help text saying: "Note: if you forget the passcode, you'll need to delete and reinstall the app. All secret chats will be lost."

While I personally have big questions around the encryption in Telegram I think Telegram takes a much more effective approach towards making it available: by default it is just a very good messaging application that is a good replacement for Facebook Messenger and WhatsApp and almost everything else except Signal.

On top of that it provides secret chats which are end to end encrypted (and can also be set to automatically disappear), and an option for deleting all my data if I don't log in within 1, 3, 6 or 12 months.

Post reply on HN