Live data from Hacker News

Signal app downloads spike as US protesters seek message encryption

qz.com

241–250 of 367 posts

Re: Signal app downloads spike as US protesters seek message encryption

#241
post #220

Earlier quoted context omitted.

The point made by the parent commenter was that you can join any group (if you get someone to invite you) related to a certain topic and get the phone numbers of everyone in that group. I am not sure about the situation in the US, but in Europe almost all phone numbers are directly linked to a certain person and address by the provider.

> The point One of the points which, yes, I agree with, but I mainly responded to this: > I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it.\ > I am not sure about the situation in the US, but in Europe almost all phone numbers are directly linked to a certain person and address by the provider. Or you can go to a corner shop and buy a Lyca or Lebara SIM with…

> Or you can go to a corner shop and buy a Lyca or Lebara SIM with cash. No need to give them your address. You can buy top ups in cash as well. At least in Western Europe this is available everywhere, pretty much.

This is not legal in Norway.

Re: Signal app downloads spike as US protesters seek message encryption

#242
post #168

What really hurts Signal are two things: * sub-par user experience: WhatsApp is just nicer and smoother, and people tend to like that * very few people understand that Signal DOES NOT get your full contact list, while Facebook (through WhatsApp) does Especially the second point is very relevant with the current situation — you do not necessarily want to expose your entire social graph to Facebook. But so few people u…

I don't think Signal is "really hurt" by WhatsApp being slightly smoother and nicer. Signal caters to those who put a premium on privacy, they are ready and willing to have a slightly less "nice and smooth" UX.

Why does it "really hurt" Signal that are sub-group of the population is ignorant of its features? I doubt that's going to stop people from downloading a privacy app, most people don't care about privacy anyway, and if they do, they will DL signal.

Re: Signal app downloads spike as US protesters seek message encryption

#243
post #53

Earlier quoted context omitted.

There's a lot more than just crypto. Its much more common for systems to fail in the supporting code then it is for the crypto to be wrong. So first step is probably learn reverse engineering and verify the crypto is being used correctly. Then after that get a phd in cryptography.

The source code is available.

Unless the build is reproducible it would be smart for a paranoid person to use the published source code only as a comparison with the decompiled app.

Re: Signal app downloads spike as US protesters seek message encryption

#244
post #114
post #99

Earlier quoted context omitted.

Signal is not only used by protesters[0][1] so discovering that a phone number is connected to a Signal account by no means implies that the phone is used by a protester. [0]: https://www.militarytimes.com/flashpoints/2020/01/23/deploye... [1]: https://www.theguardian.com/politics/2019/dec/17/tories-swit...

Yeah, if you're ever asked why you're on Signal, just say you wanted to stay in touch with a programmer friend who's not on Facebook/WhatsApp, and they suggested Signal (that is now literally true as well - I suggest you try Signal, friend)

If the law enforcement is talking to you in the U.S., the only right answer is "I'd prefer to have a laywer here."

Not a joke, for real.

They are experts at getting you to talk to them even if you know this. They are experts at getting you to say things that incriminate you or your friends -- that you or your friends have done nothing wrong (in your opinion/as far as you know) will not protect you.

The only answers you should be rehearsing or thinking of in advance are "I would like a lawyer" and "I would like to remain silent." They are rehearsing how to get you to say incriminating things, a lot. Rehearsing or thinking up any other answers only plays into their strengths. Even knowing this, I've been tricked into talking to them, to my detriment. They are really good at it.

Re: Signal app downloads spike as US protesters seek message encryption

#245
post #220

Earlier quoted context omitted.

> The point One of the points which, yes, I agree with, but I mainly responded to this: > I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it.\ > I am not sure about the situation in the US, but in Europe almost all phone numbers are directly linked to a certain person and address by the provider. Or you can go to a corner shop and buy a Lyca or Lebara SIM with…

> Or you can go to a corner shop and buy a Lyca or Lebara SIM with cash. No need to give them your address. You can buy top ups in cash as well. At least in Western Europe this is available everywhere, pretty much. This is not legal in Norway.

There are many countries it isn't legal in, which is a shame. The ability to get an anonymous phone ought to be something people care about preserving.

Re: Signal app downloads spike as US protesters seek message encryption

#246
post #239

Earlier quoted context omitted.

This was allegedly used by the authorities in Hong Kong during protests there in 2019, but using Telegram. Telegram responded by introducing a new setting that hides your number from people that aren't in your own contacts. https://telegram.org/blog/scheduled-reminders-themes#new-pri...

Telegram indeed have better UX and same level of e2e security. Why Signal is getting all the publicity?

Telegram is not opensource, Signal is...and yes you can setup your own server with Signal. Why trust a Closed-source-Software? Do you even know that it is encrypted?

Re: Signal app downloads spike as US protesters seek message encryption

#247
post #216
post #210

Earlier quoted context omitted.

I think you might want a better way of phrasing that: it’s not the “full contact list” - most people would assume that includes names and all of the other metadata - and since it’s rate-limited there’s an interesting trade off where it’s not easy to brute-force but it is targetable if you are trying to track specific known people.

The name, profile pic, etc. is less relevant than the social graph itself. State actors already have phone number name mappings at least about their own residents. If you are just curious about who's visa applications to deny because according to data collected by your IMSI-catcher many of their contacts have participated in an anti-government protest, then the name etc. isn't really relevant.

Yes, I know. My point was that a better term might help you make your point without sounding like you’re claiming something different.

Re: Signal app downloads spike as US protesters seek message encryption

#248

Earlier quoted context omitted.

In that spirit, emails (when discovered on a device) are also unique IDs. Even if someone's email is The-Dog@someprovider_dot_com authorities can still track that this mailbox was accessed by IP x.x.x.x and this IP is provided to phone number 555-12345 which belongs to Henry Bemis. It will take the authorities a bit more time (i.e. someone throws away their burner phone and authorities hack it)(with the assumption th…

You can access email only through Tor and they will never know your real IP.

Wrong...they probably don't know your IP..but a agency that has global surveillance in place, can find your source IP quite easy.

Re: Signal app downloads spike as US protesters seek message encryption

#249
post #239

Earlier quoted context omitted.

This was allegedly used by the authorities in Hong Kong during protests there in 2019, but using Telegram. Telegram responded by introducing a new setting that hides your number from people that aren't in your own contacts. https://telegram.org/blog/scheduled-reminders-themes#new-pri...

Telegram indeed have better UX and same level of e2e security. Why Signal is getting all the publicity?

Telegram has off-by-default E2E encryption with a less vetted algorithm that only works for 1:1 chats, and less focus on minimizing server knowledge. That's clearly not

> same level of e2e security

Re: Signal app downloads spike as US protesters seek message encryption

#250
post #125
post #115

Earlier quoted context omitted.

In fact, that's the main reason I'm using it, and the main counter-argument to 'I've got nothing to hide', IMHO. Sure I don't, but there are plenty of people who justifiably do.

I have nothing to hide, but I have nothing I want you to see either.

I have something to hide...it's called privacy.
Post reply on HN