Live data from Hacker News

Signal PINs

signal.org

141–150 of 199 posts

Re: Signal PINs

#141

Earlier quoted context omitted.

I've found that tapping next to the registration lock PIN prompt will dismiss it on Android. A "dismiss" button and a "don't ask me again, I won't lose this" checkmark would make much more sense to me.

> "don't ask me again, I won't lose this" This option should be labelled according to the reality rather than people's wishful thinking "Don't ask me again, when I lose this I am OK with losing the account and messages" There's probably a pithier way to express that we could get into the common lexicon as I foresee it being useful in many places. Maybe we can just label it "Yolo!" ?

Or we could label it: "I use a password manager like every other tech-serious user."

... that would encapsulate the basic reality that no one can actually remember all their ~500 secure passphrases.

Re: Signal PINs

#142

Earlier quoted context omitted.

I've found that tapping next to the registration lock PIN prompt will dismiss it on Android. A "dismiss" button and a "don't ask me again, I won't lose this" checkmark would make much more sense to me.

> "don't ask me again, I won't lose this" This option should be labelled according to the reality rather than people's wishful thinking "Don't ask me again, when I lose this I am OK with losing the account and messages" There's probably a pithier way to express that we could get into the common lexicon as I foresee it being useful in many places. Maybe we can just label it "Yolo!" ?

I mean, for a start the messages are stored locally, it doesn't protect the messages server-side, because they are never stored on the server. All the pin does is keep the server-side data, i.e. your address book and conversation information, safe.

Secondly, outside of encryption, it should not be Signal's job to enforce whether a logged-in user of a phone can see that user's content. It is the operating system's job to enforce user-level security, and users of Signal are unlikely to keep their phones without a pin, fingerprint, or other level of authentication.

The fact that you cannot turn off the option to lose all your messages when you lose a pin that you have been forced to set is horrific for those of us that rely on conversation history as a memory aid, and is precisely the reason why I have refused to set a pin.

Re: Signal PINs

#143
post #112

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

Right now if you re-install Signal on your device, you lose all your messages. That's already a very bad user experience, but imagine how much worse it would be if you lost your entire address book in that moment as well. Right now that's not a problem because your social graph is in the address book on your phone, and isn't managed by Signal. This is one of the primary reasons that Signal uses phone numbers for addr…

> Right now if you re-install Signal on your device, you lose all your messages.

Right now, if I re-install Signal on a new device, it will (hopefully) prompt me for a Signal-generated passphrase that I've stored very securely, and then allow me to restore everything, messages and address book, from a backup that I've diligently made and stored under an additional layer of encryption together with the rest of my data.

Will that facility remain available? Will the backup remain encrypted with the strong passphrase, or will any app with access to external storage be able to exfiltrate something that the Signal Foundation would be able to decrypt under the assumption that SGX is broken?

While I've so far been impressed with Signals' choices (prioritizing security but staying usable), I'm extremely disappointed with the new reliance on SGX, and forcing me into this scheme would likely get me to ditch Signal.

In particular, if I get a dialog forcing me to set a PIN, I'm out (at that point, Signal will be broken for me anyways - I'm using it to talk to very non-technical users that react to UX changes with a blank stare; they won't be able to use the app if a mandatory modal popup shows up, and flying over to teach them how to deal with it isn't exactly an option right now.)

I use Signal so I don't have to trust opaque stuff happening at a third party. From my understanding, Secure Value Recovery relies heavily on SGX, and becomes mostly equivalent to plain text (brute-forcing a short PIN) if you don't trust SGX.

Re: Signal PINs

#144
post #123
post #112

Earlier quoted context omitted.

Right now if you re-install Signal on your device, you lose all your messages. That's already a very bad user experience, but imagine how much worse it would be if you lost your entire address book in that moment as well. Right now that's not a problem because your social graph is in the address book on your phone, and isn't managed by Signal. This is one of the primary reasons that Signal uses phone numbers for addr…

> Right now if you re-install Signal on your device, you lose all your messages. That's already a very bad user experience, but imagine how much worse it would be if you lost your entire address book in that moment as well. How about letting people back this up? There's no way to do this on iOS or in the desktop app. You're solving a problem of your own making with a solution your core audience of privacy conscious u…

I'm not sure why you're being downvoted? Backups are an essential feature of chat apps, and it seems pretty sane that a lot of Signal users don't want any information stored in the cloud, full stop.

Re: Signal PINs

#145
post #113
post #109

Earlier quoted context omitted.

Still stupid, shouldn't they ask if I want that functionality? Not like it's going to be hard to brute force a user's PIN. They should explain what the pins is BEFORE they ask. What it looks like is you are going to be locked out of signal if you make a mistake. Not like the average signal user is watching the whisper systems blog.

> Still stupid, shouldn't they ask if I want that functionality? It's kind of a difficult thing to ask. "Do you want this app to work like every other app in the world in the ways you've come to expect?" If people were to simply reinstall Signal and find that all of their contacts were gone, all of their groups were gone, all of their block lists were gone, etc... they'd almost certainly be surprised. It's not a beha…

> "It's kind of a difficult thing to ask. "Do you want this app to work like every other app in the world in the ways you've come to expect?" If people were to simply reinstall Signal and find that all of their contacts were gone, all of their groups were gone, all of their block lists were gone, etc... they'd almost certainly be surprised. It's not a behavior anyone expects."

You could say:

"Hi there! Do you want to keep a backup of your conversation metadata locally, or via the cloud? The latter requires you to be badgered for a pin every day and lose all your data, even the information that the pin doesn't protect, if you lose it. The former allows you to backup to a file you can save on your computer, and store a password in your password manager!"

Re: Signal PINs

#146
post #43
post #9

Earlier quoted context omitted.

I agree. Shouldn't you put your PIN in a password manager anyway? Why call it a PIN and not a password to begin with? Is there a difference I'm missing?

You can use a long alphanumeric string as your 'PIN', and on iOS at least, you can insert that PIN via a password manager.

Hmm, because they use the word PIN (personal identification number) I set a 6 number PIN, I feel a bit stupid about that now. But then this means that my messages are in another place than my phone? A bit unclear from what the app told me...

Re: Signal PINs

#147

This post is about the UX, not about the crypto: Meanwhile on Telegram everything just works more or less as is has always done. If I click on settings I get a "menu" called "Passcode & Face ID". There's a button saying "Turn Passcode On", and a help text saying: "Note: if you forget the passcode, you'll need to delete and reinstall the app. All secret chats will be lost." While I personally have big questions around…

Except that I don't trust Telegram because they seem to ship a marketing-first, cryptography-later sort of product. IIRC initially their "E2E encryption" could be decrypted on the server. In contrast, Signal seems to put strong encryption first.

Re: Signal PINs

#148
post #112

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

Right now if you re-install Signal on your device, you lose all your messages. That's already a very bad user experience, but imagine how much worse it would be if you lost your entire address book in that moment as well. Right now that's not a problem because your social graph is in the address book on your phone, and isn't managed by Signal. This is one of the primary reasons that Signal uses phone numbers for addr…

I can see why the ability to store a social graph and other metadata on Signal's servers would be a useful feature for users who don't want to tie their Signal data to their phone number and/or a plaintext social graph, and it would make sense to give users the opportunity to opt into that functionality. But for those of us whose social graph is our phone's contact list, having it forced upon us is a significant step backwards in terms of UX while adding essentially no value.

One of the things that made me optimistic about broad adoption for Signal prior to this change is that it was basically zero-friction for Android users to use Signal over the stock messaging app, aside from the few seconds it takes to download Signal and enter your phone number. But bugging the user for a PIN all the time is a significant reason to stick to the stock messaging app (or any other one, for that matter) and makes it a lot harder for me to recommend Signal in good faith to friends and family who don't care about privacy.

Re: Signal PINs

#149
Why is signal so eager to make changes. It has been pestering me to create profile names,I don't want that so I ignore it. That's just a small drop in the bucket but why fix it isn't broken? Why not make things optional.

This b.s. is starting to remind me of the systemd crap lin Linux. I am at a point where I prefere paid open source apps and services (with a free tier) so the devs have incentive to listen to users.

It worked well a year ago,now they are ruinig it. I constantly have problems with Signal where it takes hours at times to deliver the message and this translates to real world problems and misunderstandings with people for me. Just fix the bugs,make new features optional and opt-in unless you absolutley have no choice.

Re: Signal PINs

#150
post #91

Earlier quoted context omitted.

It asks you to make it a habit. > I just wish there was an option to ask less frequently. It asks you when you open Signal until you lock it again, no? (At least on Android.)

I don't need a habit, I have a password manager.

You are the exception, the overwhelming majority of users don't use a password manager.

I agree that an advanced option to disable PIN reminder prompts would be nice, but I understand and respect the Signal team for focusing on more important things. I can live with a 5 second prompt every 2 weeks.

Post reply on HN