Live data from Hacker News

Looking back at how Signal works

signal.org

221–230 of 301 posts

Re: Looking back at how Signal works

#221
post #213

Earlier quoted context omitted.

The way you use encryption matters as much as the quality of the crypto used. In Telegrams case, usage is all wrong and not even better than e.g. WhatsApp. Opt-in E2EE is worse than having it be default, and server side encryption with server side keys is bordering on the pointless.

Thank you for reflecting with an opinion. I also believe that opt-in E2EE is worse than having it by default. We have precedent for E2EE chats by default and syncing those E2EE messages across devices using the latest RiotX for Matrix. I'd love to see Telegram adopt that strategy. I use Telegram because it delights its users. When I have tried to bring friends and family to first Riot, then Signal, the experience I e…

Don't get me wrong, Telegram is a very nice app, and I especially like the wide platform support. It's great at what it does, and that's many things, but unfortunately not secure-by-default communication.

Re: Looking back at how Signal works

#222
I want to love Signal, but it's just so meh.

* Message sync is like non-existent. Messages on my phone or laptop aren't kept in sync at all. Delete one one place, they don't delete in both.

* Let me edit messages, like every other message platform. I also want to be able to delete messages from the group. When I delete it deletes locally but not for the group, not even between my own devices I don't think. This sucks because deleting the message implies to anyone who has used a message system that the messages are deleted from everyone, but they aren't. Oof.

* When you set messages to expire, you can't make them expire. It only applies to future messages. I want to set this at the conversation level, not on a weird message-by-message basis with no way to change it globally after.

* I want to be able to sign in without using a cell phone number. Let me sign up with anything else, don't tie it to a cell phone line that can be hijacked.

* Let me add emoji responses to messages. Like every other message platform.

* Bonus, be peer-to-peer somehow. Dunno, like Blockchain magic it or something. Don't make me rely on some server somewhere. Just makes me feel uneasy that there's a middle man with all my messages.

How unrealistic is all this? (=

Re: Looking back at how Signal works

#223
post #2

> how we think about concepts like privacy, security, and trust I was disappointed to see that a mobile number is needed and that this number is shown by default in groups. Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily. So I now prefer Telegram because at least it hides numbers in groups by default.

This is a fair concern, and I hope Signal Addresses it at some point, but Telegram is no replacement. From Telegram's Wikipedia page "The default messages and media use client-server encryption during transit.[19] This data is also encrypted at rest, but can be accessed by Telegram developers, who hold the encryption keys," and "the desktop clients (excluding macOS client) do not feature end-to-end encryption, nor is…

I don't get why people praise e2e so much

If you look in the past main attack vectors on messengers are via exposed phone number, third-party insecure cloud backups or just physically accessing your device. Telegram addresses all of these while also allowing e2e encryption, just not by default for now because UX. At the same time many other popular messengers advertise "e2e by default" while being not secure at all and having mediocre UX (no desktop clients, no seamless sync, no usernames etc).

Re: Looking back at how Signal works

#224
I love Signal. I've convinced a multitude of people to switch and some use it day to day currently, but mostly to talk to me. So i feel my contacts do it out of respect and `compatibility` of communication.

What baffles me is the the incompatible feature matrix.

First of all, for some reason iOS users get the updates faster than the Android. I was exploring emoji reactions yesterday while my Android contact admitted the feature was not yet available for his device. I had to double check with Play Store to confirm.

I've found peace with the sync issues for the desktop client though, it got much more stable compare to 8 months ago. What still feels like a massive UX problem is inability to forward messages on the desktop. Given, i have lots of people coming from different places that do not know each other but share same interests it's just painstaking to copy/paste the same URL five time in a row.

And at the same time, there's no support for the Android tablets as secondary devices.

For a person deep in Apple ecosystem it felt weird to learn that Android users don't share the same experiences i do. That makes the sales pitch to try Signal way less appealing for the Android folk.

Re: Looking back at how Signal works

#225

Earlier quoted context omitted.

> Meanwhile, yes, Matrix took years to add encryption, but it works much better than Signal, even with quite a few small bugs. I'm not sure which Matrix client you use, but clients like Riot don't even let you opt out of sending read receipts unless you edit `/etc/riot/config.json` to enable experiments and then go into the settings to disable read receipts. Problems like this (and issues like this [0]) give me the i…

I'm a massive Matrix fan and have high hopes for it but in experiments we've done with activist and journalist partners we've found the Riot.im client often gets a bit complicated for people to use. I think the main issue people have is related to keys. As I techie I love the options but I find many don't like having all the options. Signal of course is a lot easier as it hides many of those issues in the UI/UX.

It's gotten better - I'm dual-running Riot/Matrix and Signal. Cross-signing has fixed the main issues affecting encrypted chat usability but there's still plenty of UI improvements to make.

Re: Looking back at how Signal works

#226
post #218

Is it worth trying to move my friends from WhatsApp to Signal? As I understand it, they're both e2e encrypted. I'm also trying to move my chats from SMS and Gchat to something encrypted, but am torn between WhatsApp and Signal. The former has more of a buy-in with my contacts already. I realize WhatsApp is owned by Facebook, but isn't the whole point of e2e encryption that you don't have to trust the intermediate inf…

> As I understand it, they're both e2e encrypted The important distinction here is that WhatsApp uploads your entire contact book to Facebook. They have up-to-date information on your entire real-life social graph (including people who are not on Facebook and/or never shared their phone with Facebook) and the groups you belong to. If you don't believe me, request a copy of your data in WhatsApp and see for yourself.…

It is possible to use WhatsApp (on iOS, at least) without giving it contact access. I do this and it isn't too bad—you still see people's WhatsApp nicknames, so it's not like you're just looking at phone numbers. Of course, that does nothing to stop them from tracking who you actively communicate with.

Re: Looking back at how Signal works

#227
post #224

I love Signal. I've convinced a multitude of people to switch and some use it day to day currently, but mostly to talk to me. So i feel my contacts do it out of respect and `compatibility` of communication. What baffles me is the the incompatible feature matrix. First of all, for some reason iOS users get the updates faster than the Android. I was exploring emoji reactions yesterday while my Android contact admitted…

iOS may get updates faster than Android and have emojis, but iOS can't backup or transfer your messages to a new phone. This basic feature has been an open request for nearly 3 years.

https://github.com/signalapp/Signal-iOS/issues/2542

The inconsistent features between iOS and Android are annoying.

Re: Looking back at how Signal works

#228
post #224

I love Signal. I've convinced a multitude of people to switch and some use it day to day currently, but mostly to talk to me. So i feel my contacts do it out of respect and `compatibility` of communication. What baffles me is the the incompatible feature matrix. First of all, for some reason iOS users get the updates faster than the Android. I was exploring emoji reactions yesterday while my Android contact admitted…

iOS may get updates faster than Android and have emojis, but iOS can't backup or transfer your messages to a new phone. This basic feature has been an open request for nearly 3 years. https://github.com/signalapp/Signal-iOS/issues/2542 The inconsistent features between iOS and Android are annoying.

Actually iOS can transfer message history to a new iPhone https://support.signal.org/hc/en-us/articles/360007059752-Ba...

Not having a backup is seen as a disadvantage by many but i literally feel it's for the best. There's plenty of scenarios when parties benefit from it.

Re: Looking back at how Signal works

#229
post #127

Earlier quoted context omitted.

Thanks, makes sense, though guess I would expect a non-profit to communicate this; don’t believe Signal even links to the 990 I linked to on their own website; possible they don’t want the public to (easily) know salaries, assets, etc - but unclear.

True, but remember that Signal (the app developer) is an LLC. The 990s may eventually be posted on the Signal Foundation website if they ever finish it: https://signalfoundation.org/

Thanks, good point, was aware of that, but others might not be; never seen a good explanation for their legal structure, both as it relates to the present & future.

I have checked both URLs for 990s, only way I found it was via a link in the footer of Signal’s Wikipedia page.

Re: Looking back at how Signal works

#230

Earlier quoted context omitted.

I'm sorry but absolutely nothing about this is a straw man or uncharitable, and I'll explain why. >If you're required to use ID to get a SIM (as K2L8M11N2 stated in the parent comment I replied to), then what I was saying follows Yes, and this is what I was responding to. You want that "if" to be taken for granted as an unchallenged starting premise to your entire argument. And that amounts to a massive privacy conce…

> "You want that "if" to be taken for granted as an unchallenged starting premise to your entire argument." I don't want that 'if' to be anything. It was the premise, because the parent comment I was responding to was stating it as a fact for where they live. My point is that signal revealing your phone number and when you signed up doesn't reveal anything new about you. The issue is the case K2L8M11N2 mentioned when…

"The social graph" (your phone book) is most likely already uploaded somewhere by third-party app or even Google/Apple themselves. Using separate contact list (even uploaded to some server) seems more secure to me than using your phone's one.

The phone number is much more valuable to any authority than other metadata because they are more likely to have access to cell service than to messenger services.

In the context of the post, signal is much more vunerable than even basic things like email or web chats because police can effortlessly identify anyone in the group chat with a single request to cell company.

Post reply on HN