Live data from Hacker News

Signal app downloads spike as US protesters seek message encryption

qz.com

221–230 of 367 posts

Re: Signal app downloads spike as US protesters seek message encryption

#221
post #114
post #99

Earlier quoted context omitted.

Signal is not only used by protesters[0][1] so discovering that a phone number is connected to a Signal account by no means implies that the phone is used by a protester. [0]: https://www.militarytimes.com/flashpoints/2020/01/23/deploye... [1]: https://www.theguardian.com/politics/2019/dec/17/tories-swit...

Yeah, if you're ever asked why you're on Signal, just say you wanted to stay in touch with a programmer friend who's not on Facebook/WhatsApp, and they suggested Signal (that is now literally true as well - I suggest you try Signal, friend)

FWIW, many of my friends actually could say this, for I am a programmer who's not on Facebook/WhatsApp and recommends Signal.

It definitely needs to be more reliable, though. The last time I tried to call someone with Signal instead of just using it for messaging, I got a ringing indication but they heard nothing and then after a few seconds the call showed up as missed, and the same happened the other way around with them calling me. There seem to have been about 500 updates to the iOS app in the past 5 minutes via the app store, though, so many whatever caused that was a short-lived glitch.

Re: Signal app downloads spike as US protesters seek message encryption

#222

Long-time Signal user but I'm on the verge of moving I think. There are several UX shortcomings but the new PIN nag is a bridge too far. What are my options for alternatives? I imagine Telegram is the next best bet but very open to suggestions.

I have been using an app provided by my company (finance) called SecurLine It's weird how simple it is, and I don't have to provide my phone number like on Signal

Re: Signal app downloads spike as US protesters seek message encryption

#224
post #183
post #168

What really hurts Signal are two things: * sub-par user experience: WhatsApp is just nicer and smoother, and people tend to like that * very few people understand that Signal DOES NOT get your full contact list, while Facebook (through WhatsApp) does Especially the second point is very relevant with the current situation — you do not necessarily want to expose your entire social graph to Facebook. But so few people u…

Telegram is a great alternative also, offers encrypted chat's also.

I don’t trust telegram. Chats are stored forever on their servers encrypted using their secret method.

Re: Signal app downloads spike as US protesters seek message encryption

#225

Has anyone here successfully convinced their non-techie friends to switch to Signal? How have you done it? I've been trying on and off with my closest friends, but no luck.

I tried but couldn't. It just wasn't sticky enough for people to continue using it. Perhaps something like this latest growth could help?

I tried with Telegram after failing with Signal and that worked for many. For whatever reason (I assume the user experience is nice and more compatible with Whatsapp etc), non-techie people do prefer Telegram to Signal in my experience.

Re: Signal app downloads spike as US protesters seek message encryption

#226
post #92

The biggest drawback with Signal for protesters is that it exposes the user's phone number to everyone else in groups (just like WhatsApp does). There is no way to even hide the fact that you have an account on Signal. I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it. If the authorities don't use tactics like they did in Hong Kong, the protesters may be safe…

This tradeoff is arguably a good thing. By using phone numbers as IDs signal can rely on your phone's local contacts (meaning they don't have to send your social graph to their servers). This way they can keep very little metadata on you. There's pretty much nothing for them to turn over except the fact that your phone number has the signal app. Most of the other secure apps could turn over your entire contact list (…

The only keep my phone number, which is tied to my ID

Re: Signal app downloads spike as US protesters seek message encryption

#227
post #211

Earlier quoted context omitted.

Telegram doesn't have encryption for groups though.

Actually they do: https://telegram.org/faq#q-so-how-do-you-encrypt-data , but since group chats are using Telegram's servers the encryption is not client-to-client. Here is the actual specification of how does their srever-client encryption work: https://core.telegram.org/mtproto

>> “ since group chats are using Telegram's servers the encryption is not client-to-client”

That is, it is not end-to-end-encrypted (E2EE) — which is the whole point of apps like this.

Re: Signal app downloads spike as US protesters seek message encryption

#228
post #133

Earlier quoted context omitted.

The desktop app situation is pretty similar for all messaging apps. I don't really know any messaging application that has good, native desktop apps. Can't really include iMessage in good faith due to the platform restrictions.

Skype has always worked for me. Unfortunately it's not secure.

I usually hear nothing but complaints about Skype.

Re: Signal app downloads spike as US protesters seek message encryption

#229
post #206
post #200

Earlier quoted context omitted.

Do you have a reference for the claim that your full contact list is uploaded to servers? That seems important since their privacy policy says that they only use hashes, and it can’t be dependent on SGX since it runs on non-Intel hardware: https://signal.org/legal/#privacy-policy

The method is explained here: https://signal.org/blog/private-contact-discovery/ Yes, it's hashes of phone numbers instead of the phone numbers themselves, but that's a detail. Phone numbers are easy to brute-force especially for people the protesters are worried about, as well as easy to build rainbow tables for.

I would disagree with the "that's a detail" statement. Properly salted hashes make building a social network graph much more difficult. It's only relatively easy to brute-force a single number.

Re: Signal app downloads spike as US protesters seek message encryption

#230
post #97

Earlier quoted context omitted.

Telegram's homegrown crypto has been dismissed by many people (including experts). But it offers privacy features that some other messengers do not. Is Signal trustworthy considering that it exposes your phone number to everyone else in groups? With Telegram it's possible to communicate with anyone without revealing your phone number or profile picture or anything else.

> Telegram's homegrown crypto has been dismissed by many people (including experts). Only the expert's opinions are of any value IMO, and I've never seen anyone showing an attack on Telegram's encryption. Telegram themselves seem to claim that it's never broken. I often see vague criticism over the fact that they use their own protocol, but never anything more detailed than that. https://core.telegram.org/techfaq#q-i…

GP here. I agree. I believe there’s a stigma against Telegram. There was one security issue with the MProto version 1 several years ago, which was reported (given a bounty too, IIRC) and fixed. I don’t recall any other issue being reported after that.
Post reply on HN