Live data from Hacker News

Signal app downloads spike as US protesters seek message encryption

qz.com

121–130 of 367 posts

Re: Signal app downloads spike as US protesters seek message encryption

#122
I like signal, mainly because it's open source. One minor annoyance though, perhaps someone knows how to fix it: when I use Signal on either my phone or my laptop, going back to the other device makes it sync the messages. But it does this really slowly, making a notification noise for each message, sometimes for several minutes. How do you either coalesce them or just do it fast? Doesn't seem like it's really a speed issue.

Re: Signal app downloads spike as US protesters seek message encryption

#123
post #92

The biggest drawback with Signal for protesters is that it exposes the user's phone number to everyone else in groups (just like WhatsApp does). There is no way to even hide the fact that you have an account on Signal. I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it. If the authorities don't use tactics like they did in Hong Kong, the protesters may be safe…

This tradeoff is arguably a good thing. By using phone numbers as IDs signal can rely on your phone's local contacts (meaning they don't have to send your social graph to their servers). This way they can keep very little metadata on you. There's pretty much nothing for them to turn over except the fact that your phone number has the signal app. Most of the other secure apps could turn over your entire contact list (…

I've lost track of the number of times I've had this conversation but here we go:

There's nothing inherent in phone numbers here. Both iOS and Android also allows you to add e-mail addresses (and other identifiers) to your local contacts. I'm yet to hear an argument as to why e-mail addresses or other identifiers can't be used in addition to phone numbers, or why it would be a complicating factor.

Re: Signal app downloads spike as US protesters seek message encryption

#124
post #106

Earlier quoted context omitted.

The Signal app experience leaves a lot to be desired compared to Telegram or Matrix.

Telegram is THE standard in messaging apps. It's basically flawless. It's extremely fast, and it works every single time. Notifications are rock solid on every platform, it doesn't hog your battery and it feels fluid to use. Signal, Wickr, WhatsApp and others do not have this experience. They all have drawbacks and do not feel Telegram fast.

It may be the standard for speed, but it's not the standard for security.

Re: Signal app downloads spike as US protesters seek message encryption

#125
post #115
post #99

Earlier quoted context omitted.

Signal is not only used by protesters[0][1] so discovering that a phone number is connected to a Signal account by no means implies that the phone is used by a protester. [0]: https://www.militarytimes.com/flashpoints/2020/01/23/deploye... [1]: https://www.theguardian.com/politics/2019/dec/17/tories-swit...

In fact, that's the main reason I'm using it, and the main counter-argument to 'I've got nothing to hide', IMHO. Sure I don't, but there are plenty of people who justifiably do.

I have nothing to hide, but I have nothing I want you to see either.

Re: Signal app downloads spike as US protesters seek message encryption

#126
post #48

Earlier quoted context omitted.

The Signal app experience leaves a lot to be desired compared to Telegram or Matrix.

Does it tho? It changed a lot during the last years and for most stuff I do with my friends (videocalls, textmessages, recorded speechmessages, pictures, videos, groupstuff, desktop app) it just works fine.

With the exception of desktop app, I agree :).

The desktop app takes several minutes to open (at least on Linux), so I find that the only way to use it is to start it at boot and always leave it open. I'm still hoping that someone may create other clients, e.g. a Pidgin backend.

The mobile apps, on the other hand, work really well. Been using them for years now, both on Android and iOS.

Re: Signal app downloads spike as US protesters seek message encryption

#127

Earlier quoted context omitted.

This tradeoff is arguably a good thing. By using phone numbers as IDs signal can rely on your phone's local contacts (meaning they don't have to send your social graph to their servers). This way they can keep very little metadata on you. There's pretty much nothing for them to turn over except the fact that your phone number has the signal app. Most of the other secure apps could turn over your entire contact list (…

I've lost track of the number of times I've had this conversation but here we go: There's nothing inherent in phone numbers here. Both iOS and Android also allows you to add e-mail addresses (and other identifiers) to your local contacts. I'm yet to hear an argument as to why e-mail addresses or other identifiers can't be used in addition to phone numbers, or why it would be a complicating factor.

My guess would be that phone numbers are guaranteed to be unique IDs that (almost) every phone will have which simplifies things and reduces the risk of someone impersonating someone else.

I think they are working on non-phone number IDs though (Moxie was in an earlier signal thread on HN recently and mentioned it).

Re: Signal app downloads spike as US protesters seek message encryption

#129

Earlier quoted context omitted.

I've lost track of the number of times I've had this conversation but here we go: There's nothing inherent in phone numbers here. Both iOS and Android also allows you to add e-mail addresses (and other identifiers) to your local contacts. I'm yet to hear an argument as to why e-mail addresses or other identifiers can't be used in addition to phone numbers, or why it would be a complicating factor.

My guess would be that phone numbers are guaranteed to be unique IDs that (almost) every phone will have which simplifies things and reduces the risk of someone impersonating someone else. I think they are working on non-phone number IDs though (Moxie was in an earlier signal thread on HN recently and mentioned it).

There is an issue on Github that is collating the problems they are working through. I've lost track of it, though, unfortunately. I've been pretty cynical about it in the past, but the last time I looked at the issue, it does look more complex than I first imagined. I wish it were higher priority, though. Hopefully somebody will remember the issue and post it here (it was from an HN post that I found it originally). Unfortunately, I'm not even sure what project it's under and there are many projects.

Re: Signal app downloads spike as US protesters seek message encryption

#130

Earlier quoted context omitted.

I've lost track of the number of times I've had this conversation but here we go: There's nothing inherent in phone numbers here. Both iOS and Android also allows you to add e-mail addresses (and other identifiers) to your local contacts. I'm yet to hear an argument as to why e-mail addresses or other identifiers can't be used in addition to phone numbers, or why it would be a complicating factor.

My guess would be that phone numbers are guaranteed to be unique IDs that (almost) every phone will have which simplifies things and reduces the risk of someone impersonating someone else. I think they are working on non-phone number IDs though (Moxie was in an earlier signal thread on HN recently and mentioned it).

In that spirit, emails (when discovered on a device) are also unique IDs. Even if someone's email is The-Dog@someprovider_dot_com authorities can still track that this mailbox was accessed by IP x.x.x.x and this IP is provided to phone number 555-12345 which belongs to Henry Bemis.

It will take the authorities a bit more time (i.e. someone throws away their burner phone and authorities hack it)(with the assumption that phone numbers/SIM activations are provided using valid ID as it happens in many countries).

Post reply on HN