This is all well and good. But the forced/unsilenceable pin reminders seems a bit obtuse to me. https://support.signal.org/hc/en-us/articles/360007059792-Si... "Can I turn off these reminders? It is important to memorize your PIN, and the reminders cannot be disabled. We cannot recover your PIN if you forget it. You will see the reminders less frequently if you consistently enter your PIN correctly. The reminders wil…
It is beyond comprehension that they think pin reminders being mandatory is ok. I have been a huge fan of signal from the beginning and this is single handily a deal breaker and has me looking for alternatives. How did they not learn from this when they tried it with the activation lock.
Signal PINs
171–180 of 199 posts
Re: Signal PINs
#172I don’t want my messages to be stored anywhere other than on my phone. I hate when companies push this bullshit on you. I keep on getting reminders to set a pin and I can’t turn it off. I think one of the issues with software is that because it’s infinitely extensible, people just add more and more features, they don’t know when to stop. So they keep pushing features that satisfy 10% of their users to the detriment o…
The 90% want their message history synced across devices.
Re: Signal PINs
#173Earlier quoted context omitted.
I dunno but for example Wire does implement addressing without giving phone number optionally if you sign in with an email and a password, which makes me less convinced of the necessity of forced PINs in this style to enable such cases (which should be optional in the first place). Same thing with syncing across devices which requires you opt in to add email/password combo to enable those features.
They store your social graph in plaintext on their servers.
The main issue I see is with the intrusiveness of how Signal PINs are handled by the UI, this will only work to alienate users or encourage writing simple PINs that make them weak to use! It would've been much better had it been treated as a fully opt in feature and PINs treated more as passwords, without the constant bombardment of reminders to input it.
This can be placed behind a "sync" option for example and enabling it opens a dialogue explaining the need for password, from there it's up to the user to enable sync and in doing so they have to set a password like normal services.
That's just my 2 cents ¯\_(ツ)_/¯
Re: Signal PINs
#174I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…
Right now if you re-install Signal on your device, you lose all your messages. That's already a very bad user experience, but imagine how much worse it would be if you lost your entire address book in that moment as well. Right now that's not a problem because your social graph is in the address book on your phone, and isn't managed by Signal. This is one of the primary reasons that Signal uses phone numbers for addr…
This is true for today's Matrix network, but we do have peer-to-peer Matrix working now too (as previewed at https://fosdem.org/2020/schedule/event/dip_p2p_matrix/) which stores the metadata purely on the clients. There are no servers, other than rendezvous points to seed the network. (It's still vulnerable to traffic pattern analysis, but we're working on that - and Signal suffers this even more).
It's also worth noting that because Matrix doesn't tie identity to phone numbers (or anything else), the 'social graph' which is built up is of limited use if it's built up of anonymous personae.
Re: Signal PINs
#175Curious: So this PIN has to be stored on the Signal server? Now lets assume most average (non-technical) users will simply type in/re-use their smartphone pin (most of the people i know will do this.) Would this mean if there's a data breach in the 'Signal cloud', their Pins have now leaked onto the internet? Doesn't seem like a great idea to store peoples Pin codes in a cloud... would probably be better if they'd ju…
Read the article before commenting.
So what i'm curious about is, how can this be? If you have lost your device (and thus all the keys stored in the signal app/phone), how can they store just a single pin while at the same time being able to prevent it to be recovered/brute forced (since it only has to be 4 digits)?
Re: Signal PINs
#176Earlier quoted context omitted.
That's lovely, but once you've remembered it? I'm never going to forget my mobile number, I don't need to keep calling myself to remember it.
But the reason you don't forget it is probably because you recall it all the time. You definitely recall your phone number for purposes other than calling yourself. This has given me a good idea for a study: find people who have changed phone numbers and see how many of those people can remember them. Then plot the data by the last time they used that number.
Re: Signal PINs
#177Earlier quoted context omitted.
You are the exception, the overwhelming majority of users don't use a password manager. I agree that an advanced option to disable PIN reminder prompts would be nice, but I understand and respect the Signal team for focusing on more important things. I can live with a 5 second prompt every 2 weeks.
The overwhelming majority of users don't use Signal, either.
Signal's challenge is to build features that other apps already have but in a way that respects their users' privacy. They make their share of mistakes but I'm deeply grateful for what they do and try not to lose sight of the important stuff.
Re: Signal PINs
#178Earlier quoted context omitted.
You are the exception, the overwhelming majority of users don't use a password manager. I agree that an advanced option to disable PIN reminder prompts would be nice, but I understand and respect the Signal team for focusing on more important things. I can live with a 5 second prompt every 2 weeks.
You can respect Signal team, and still don't deny that this forced habit-building is UX anti-pattern. Which doesn't make sense anyway, because majority will not accept increased discomfort it creates, and minority which values security more do use pw managers.
Re: Signal PINs
#179This post is about the UX, not about the crypto: Meanwhile on Telegram everything just works more or less as is has always done. If I click on settings I get a "menu" called "Passcode & Face ID". There's a button saying "Turn Passcode On", and a help text saying: "Note: if you forget the passcode, you'll need to delete and reinstall the app. All secret chats will be lost." While I personally have big questions around…
Re: Signal PINs
#180This post is about the UX, not about the crypto: Meanwhile on Telegram everything just works more or less as is has always done. If I click on settings I get a "menu" called "Passcode & Face ID". There's a button saying "Turn Passcode On", and a help text saying: "Note: if you forget the passcode, you'll need to delete and reinstall the app. All secret chats will be lost." While I personally have big questions around…
Except that I don't trust Telegram because they seem to ship a marketing-first, cryptography-later sort of product. IIRC initially their "E2E encryption" could be decrypted on the server. In contrast, Signal seems to put strong encryption first.