Live data from Hacker News

Looking back at how Signal works

signal.org

51–60 of 301 posts

Re: Looking back at how Signal works

#51

I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…

I do get the occasional missing messages in the desktop client but what I notice most is that it gets unstable and weird when there is a update available (which I don't get notified about). Desktop and laptop with Ubuntu btw, signal installed via snap if I recall correctly.

Have you checked if yours is up to date?

Re: Looking back at how Signal works

#52
post #51

I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…

I do get the occasional missing messages in the desktop client but what I notice most is that it gets unstable and weird when there is a update available (which I don't get notified about). Desktop and laptop with Ubuntu btw, signal installed via snap if I recall correctly. Have you checked if yours is up to date?

I have the PPA set up and it autoupdates, but I will double-check, thank you.

Re: Looking back at how Signal works

#53

Earlier quoted context omitted.

> the Apple App Store and Google Play Store will just stop allowing it to be downloaded Time for a privacy focused app store!

at least on Android you can sideload it

I recall reading something recently about how in a coming release, Android will disable sideloading. The sole permitted way to sideload will be to enable ADB and then install the app with adb install. Some techies will continue to do that, just like some people unlock the bootloader and install LineageOS on their device, but removing Signal from the Play Store would make it as good as dead for the general public. (Even Signal’s website discourages people from downloading the APK from them, and prefers that people use an app store instead!)

Re: Looking back at how Signal works

#54
Signal is a walled garden. They refuse to allow federation and even prohibit any modified client to use their servers.

It's the least open "open source" model, and once (if) they gain significant market share they can easily close down the app and lock-in the users.

Please use and spread federated alternatives. Donate and contribute.

Re: Looking back at how Signal works

#55
The anti-Signal rhetoric has already started. News articles about Antifa specifically mention that they communicate via Signal.

If Antifa is designated as a terrorist organization, then we'll see all the counter-terrorism tools brought to bear against them. If the state can't break Signal encryption, then you'll see renewed energy for anti-encryption / anti-privacy policies.

Re: Looking back at how Signal works

#56
post #28

What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be downloaded if they do not add the backdoor in? Is there a workaround that will allow people to use it still? I've heard people mention locating the servers in other countries, but wouldn't the various App stores be bound by US law and still not allow them?

Signal’s official statement on the EARN It Act is here: https://signal.org/blog/earn-it/

Thanks for the link. There's a subtle threat in there, that they'll move out of the country if they have issues which I think a lot of tech companies would.

This bill is so stupid in that tech companies can relatively easily move.

Re: Looking back at how Signal works

#57

Earlier quoted context omitted.

In most European countries you need to submit your ID to get any sort of working SIM card.

If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers. As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up. These other apps send your social graph to their servers, track and store metadata, don’…

>If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway?

Well, if you're operating on that premise, which is to say, a premise of complete and total resignation and surrender, then from that starting point of course you haven't lost anything. I don't think anybody is joining you though in agreeing that that's a legitimate starting place to analyze privacy concerns associated with the phone number requirement.

Re: Looking back at how Signal works

#58

The only reason I don't use Signal is because it still uses your phone number for ID. What is even the point of verifying by number?

If it didn't have this feature of being a drop-in replacement for SMS, then I would be using Matrix to communicate with my two privacy-minded friends, and plain-text SMS to talk to everyone else in my contact list. With this feature, I've been able to convince about half of my Android-using contacts into switching (iOS is a harder sell).

Re: Looking back at how Signal works

#59
post #32

Earlier quoted context omitted.

Signal has an option to prevent this by locking the number with your PIN. This capability introduces plausible deniability that a phone number assigned to a SIM is actually associated with the number of a Signal account. Don't know if that matters legally or not. Also the people doing shady things are generally hopping accounts regularly anyway.

PIN only stops registration for a fixed amount of time, believe 7-days, then the entity controlling the number would be able to reclaim the account. If the “attacker” maintained control, new devices that add the number from their contact list would get no alert; that is, the users would have to figure out the number is controlled by someone else.

That’s 7 days since last use. So if you continue to use the app at least once every 7 days, it will remain registration locked.

Also, anyone who had communicated with you before the switch would see a “safety number changed” notification if the number became affiliated with a new device.

Re: Looking back at how Signal works

#60

Earlier quoted context omitted.

If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers. As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up. These other apps send your social graph to their servers, track and store metadata, don’…

>If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Well, if you're operating on that premise, which is to say, a premise of complete and total resignation and surrender, then from that starting point of course you haven't lost anything. I don't think anybody is joining you though in agreeing that that's a legitimate starting place to analyze privacy concerns assoc…

This is such an uncharitable interpretation of what I was saying that it's basically a straw man.

If you're required to use ID to get a SIM (as K2L8M11N2 stated in the parent comment I replied to), then what I was saying follows - that the person is already tied to the phone number anyway.

In this context Signal revealing the only data they have (that a phone number signed up on X day) really doesn't matter or reveal anything new.

K2L8M11N2's other response to my comment is a helpful clarification, it's less about what can be compelled from Signal the company and more about what can be turned over if a user's device is compromised. In that context the name to number connection is more serious because they also have the content.

Post reply on HN