Live data from Hacker News

Signal PINs

signal.org

191–199 of 199 posts

Re: Signal PINs

#191
post #162
post #142

Earlier quoted context omitted.

I mean, for a start the messages are stored locally, it doesn't protect the messages server-side, because they are never stored on the server. All the pin does is keep the server-side data, i.e. your address book and conversation information, safe. Secondly, outside of encryption, it should not be Signal's job to enforce whether a logged-in user of a phone can see that user's content . It is the operating system's jo…

Well most mobiles don't offer multi user and phones are often loaned temporarily to other people. For example for kids to play on.

Android 9 and 10 has multi-user.

And if you take into account the "lending phones to kids" scenario it gets worse because that just means that when your 4yro kid gets your phone they can irrecoverably delete all your messages, simply by playing around with it.

Re: Signal PINs

#192

Earlier quoted context omitted.

Except that I don't trust Telegram because they seem to ship a marketing-first, cryptography-later sort of product. IIRC initially their "E2E encryption" could be decrypted on the server. In contrast, Signal seems to put strong encryption first.

There is no E2E encryption in Telegram for any reasonable definition of the term.

This is plain wrong. I think even tptacek has become more careful about his wording now.

There's a lot of problems around Telegram from their marketing to their crypto implementation to their incentives.

But please stick to the facts.

Re: Signal PINs

#193

This post is about the UX, not about the crypto: Meanwhile on Telegram everything just works more or less as is has always done. If I click on settings I get a "menu" called "Passcode & Face ID". There's a button saying "Turn Passcode On", and a help text saying: "Note: if you forget the passcode, you'll need to delete and reinstall the app. All secret chats will be lost." While I personally have big questions around…

Telegram is not a secure messenger, it offers the same level of non-security as skype or fb messenger - not even that of watsapp.

It has different problems than skype, fb messenger and WhatsApp.

For starters it doesn't give my raw metadata including who I talk to, when and so on to Zuckerberg, or unencrypted chat logs of both sides of a chat to servers in USA.

Re: Signal PINs

#194

Earlier quoted context omitted.

Telegram is not a secure messenger, it offers the same level of non-security as skype or fb messenger - not even that of watsapp.

It has different problems than skype, fb messenger and WhatsApp. For starters it doesn't give my raw metadata including who I talk to, when and so on to Zuckerberg, or unencrypted chat logs of both sides of a chat to servers in USA.

Do you have higher trust towards the Durov brothers and their UK/UAE company ? Because it does all that with them.

Re: Signal PINs

#195

Earlier quoted context omitted.

There is no E2E encryption in Telegram for any reasonable definition of the term.

This is plain wrong. I think even tptacek has become more careful about his wording now. There's a lot of problems around Telegram from their marketing to their crypto implementation to their incentives. But please stick to the facts.

Facts are that whatever e2e encryption telegram allegedly offers needs to be invoked per-conversation as a 'secret chat' and is not availabe on dekstops, normal conversations are ¯\_(ツ)_/¯ -encrypted

Re: Signal PINs

#196
post #112

I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me. I don't understand why it isn't just optional. They claim they want to protect my Signal da…

Right now if you re-install Signal on your device, you lose all your messages. That's already a very bad user experience, but imagine how much worse it would be if you lost your entire address book in that moment as well. Right now that's not a problem because your social graph is in the address book on your phone, and isn't managed by Signal. This is one of the primary reasons that Signal uses phone numbers for addr…

It’s frustrating that we can’t still use a local address book for this. vCard is an extensible format, so a contact vCard could very well contain a Signal-specific identifier. I don’t know if the various mobile contact APIs support this though; I suspect not.

Re: Signal PINs

#197

Earlier quoted context omitted.

It has different problems than skype, fb messenger and WhatsApp. For starters it doesn't give my raw metadata including who I talk to, when and so on to Zuckerberg, or unencrypted chat logs of both sides of a chat to servers in USA.

Do you have higher trust towards the Durov brothers and their UK/UAE company ? Because it does all that with them.

So far - unless I've missed something big - there's nothing to suggest they aren't trying to stick to their plan to keep keys and encrypted data on different servers in different jurisdictions..?

And the Durov brothers weren't running a massive ad and tracking network last I checked.

Re: Signal PINs

#198

Earlier quoted context omitted.

Do you have higher trust towards the Durov brothers and their UK/UAE company ? Because it does all that with them.

So far - unless I've missed something big - there's nothing to suggest they aren't trying to stick to their plan to keep keys and encrypted data on different servers in different jurisdictions..? And the Durov brothers weren't running a massive ad and tracking network last I checked.

Don't you wonder how they make or plan to make revenue or do you think they're in it for truth, justice and happiness of all mankind ?

Re: Signal PINs

#199

Earlier quoted context omitted.

So far - unless I've missed something big - there's nothing to suggest they aren't trying to stick to their plan to keep keys and encrypted data on different servers in different jurisdictions..? And the Durov brothers weren't running a massive ad and tracking network last I checked.

Don't you wonder how they make or plan to make revenue or do you think they're in it for truth, justice and happiness of all mankind ?

Yes, I do. I even mentioned it in another reply to you:

> There's a lot of problems around Telegram from their marketing to their crypto implementation to their incentives.

That said there are multiple ways around the monetization problem as long as you aren't trying to become a Silicon Valley unicorn:

- 1 USD pr user like WhatsApp

- Paid stickers and storage like MeWe

- Extra storage and extra features like Evernote

- Paid API access

- etc

Post reply on HN