Live data from Hacker News

Looking back at how Signal works

signal.org

231–240 of 301 posts

Re: Looking back at how Signal works

#231
post #2

> how we think about concepts like privacy, security, and trust I was disappointed to see that a mobile number is needed and that this number is shown by default in groups. Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily. So I now prefer Telegram because at least it hides numbers in groups by default.

Telegram isn't really a subject to compare to Signal.

I own a cellphone number for an Eastern European provider and had been using Telegram solely for news reader purposes. None of the people i communicate knows the number. Much to my surprise i learned that Telegram cooperates with local authorities, i would never found it out if not for COVID-19. The messages i got were addressing the precautions and regulations during the pandemic. While i appreciate the effort, i feel like it's a clear overreach on Telegram's part.

How do i know it was Telegram rather than the authorities themselves? The sender information clearly stated the sender was Telegram (same as a chatbox created to inform on What's new), i've got a push notification even though push notifications were app level turned off.

Can't imagine Signal compromising the trust of it's userbase by sending any sort of material that comes from the healthcare department of whatever country my phone number would be from.

Re: Looking back at how Signal works

#232
post #224

I love Signal. I've convinced a multitude of people to switch and some use it day to day currently, but mostly to talk to me. So i feel my contacts do it out of respect and `compatibility` of communication. What baffles me is the the incompatible feature matrix. First of all, for some reason iOS users get the updates faster than the Android. I was exploring emoji reactions yesterday while my Android contact admitted…

Never tried Signal, but from what you're telling, it seems that they redevelop the core functionalities for each platform.

That's interesting, because i've been looking for a way to share core logic code across platform (mobile & desktop at least), and still haven't found something really user friendly. From my brief lookup (rust & gomobile are the ones i've looked at), it seems that most dev environment seem to support some kind of C-style interfacing, but it becomes much more clumsy as soon as you're trying to have it run on java.

Has anyone found a solution that he's comfortable with and would recommend ?

Re: Looking back at how Signal works

#233
post #30

Earlier quoted context omitted.

If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers. As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up. These other apps send your social graph to their servers, track and store metadata, don’…

> roll their own cryptography Signal did the same thing. They invented their own cryptographic algorithms. https://en.wikipedia.org/wiki/Double_Ratchet_Algorithm And the social graph IS sent to servers by Signal. It's protected only by hashing (trivial to circumvent) and by the Intel SGX technology (a bit harder to circumvent, but I doubt that the US govt can't do it).

Signal's crypto is an incremental improvement of existing algorithms with good reputation, OTR and SCIMP.

Telegram's crypto is reportedly designed from scratch, with questionable choices such as SHA1 and MAC-then-encrypt.

https://www.cryptofails.com/post/70546720222/telegrams-crypt...

https://eprint.iacr.org/2015/1177.pdf

Re: Looking back at how Signal works

#234
post #228

Earlier quoted context omitted.

iOS may get updates faster than Android and have emojis, but iOS can't backup or transfer your messages to a new phone. This basic feature has been an open request for nearly 3 years. https://github.com/signalapp/Signal-iOS/issues/2542 The inconsistent features between iOS and Android are annoying.

Actually iOS can transfer message history to a new iPhone https://support.signal.org/hc/en-us/articles/360007059752-Ba... Not having a backup is seen as a disadvantage by many but i literally feel it's for the best. There's plenty of scenarios when parties benefit from it.

Purchasing a new phone is only a small subset of the scenarios where a backup is useful, for example, in the last two years Apple support has requested that I reset my phone and reinstall iOS twice. Having to buy a second phone to temporarily store my data is not a viable alternative.

Or losing your phone.

Or accidentally breaking it.

Or having it stolen.

A backup protects my data in these situations where a transfer utility does not.

Backups disabled by default would be a sensible approach, but is very much being childish not to let users access their own data.

Re: Looking back at how Signal works

#235
post #79

Earlier quoted context omitted.

There is no consensus on wether being against fascism is good or bad? Being against fascism is not a group or organisation. It’s like calling bird watching an organisation. Yes, there are bird watching organisations, as there are antifa organisations, but neither bird watching nor antifa is an organisation.

This is like asking if there's no consensus on whether "all lives matter". Or no consensus on being "pro-life". Phrases often have context that mean more than their literal dictionary definition. Edit: The comment I replied to originally asked "There is no consensus on wether being against fascism is good or bad?"

I can think of one group of people who are not against fascism, so yes, there is no “consensus” on whether fascism is good or bad I guess

Re: Looking back at how Signal works

#236
post #231
post #2

> how we think about concepts like privacy, security, and trust I was disappointed to see that a mobile number is needed and that this number is shown by default in groups. Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily. So I now prefer Telegram because at least it hides numbers in groups by default.

Telegram isn't really a subject to compare to Signal. I own a cellphone number for an Eastern European provider and had been using Telegram solely for news reader purposes. None of the people i communicate knows the number. Much to my surprise i learned that Telegram cooperates with local authorities, i would never found it out if not for COVID-19. The messages i got were addressing the precautions and regulations du…

As mentioned elsewhere it all about the threatmodel. I have a group where others like to be anonymous, at least to ppl they do not know (yet). They will very likely not care about authorities to see our messages as they have nothing to hide from that perspective.

Re: Looking back at how Signal works

#237
post #7
post #2

> how we think about concepts like privacy, security, and trust I was disappointed to see that a mobile number is needed and that this number is shown by default in groups. Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily. So I now prefer Telegram because at least it hides numbers in groups by default.

Because mobile numbers enable much more easier use than emails. I talk to so many people on WhatsApp who don't even know what an email is, and would certainly never use the app if it couldn't pick their contacts from Contact List. The goal of Signal has always been "privacy for the masses". The experts always had 20 solutions available.

How did they install whatsapp if they didn't have an email, since you need one for the play store and app store?

Re: Looking back at how Signal works

#238
post #236
post #231

Earlier quoted context omitted.

Telegram isn't really a subject to compare to Signal. I own a cellphone number for an Eastern European provider and had been using Telegram solely for news reader purposes. None of the people i communicate knows the number. Much to my surprise i learned that Telegram cooperates with local authorities, i would never found it out if not for COVID-19. The messages i got were addressing the precautions and regulations du…

As mentioned elsewhere it all about the threatmodel. I have a group where others like to be anonymous, at least to ppl they do not know (yet). They will very likely not care about authorities to see our messages as they have nothing to hide from that perspective.

>They will very likely not care about authorities to see our messages as they have nothing to hide from that perspective.

`Nothing to hide` isn't the point of my message but the willingness of Telegram to collaborate with 3rd parties be that for a good or bad cause is what concerned me. I already own a tool to get unsolicited messages — email.

Re: Looking back at how Signal works

#239
post #176

Earlier quoted context omitted.

> Don't get me wrong, RCS will be a fine enough fallback (once it's E2E), but standardized chat is the dream. Is there a plan for RCS to be E2E? Given that RCS went under the GSMA umbrella in 2008, and it's 2020 and adoption is minimal, I don't have any hopes for a future update that supports E2E to come out any time sooner than 2040, with handsets supporting it in 2050, and all endpoints supporting it in 2065; Googl…

Tackling this point separately: the entire reason they do this is because they routinely experiment with side projects and then build the ideas that work well into the services that gain traction. As much as it comes with the drawback of being scattershot in general, it specifically creates a track record for failure with messaging because successful messaging products, as a rule, have network effect - something you…

>As much as it comes with the drawback of being scattershot in general, it specifically creates a track record for failure with messaging because successful messaging products, as a rule, have network effect - something you can't build when you're playing with three different approaches simultaneously.

I think what Google needs to do is to seperate the messaging protocol from the messaging software. The protocol needs network effects. The software doesn't. That's why shutting down Google Inbox didn't kill email and it's why any new experiments with email software can benefit from the network effects that email protocols already have.

Re: Looking back at how Signal works

#240
post #146

Earlier quoted context omitted.

This is a fair concern, and I hope Signal Addresses it at some point, but Telegram is no replacement. From Telegram's Wikipedia page "The default messages and media use client-server encryption during transit.[19] This data is also encrypted at rest, but can be accessed by Telegram developers, who hold the encryption keys," and "the desktop clients (excluding macOS client) do not feature end-to-end encryption, nor is…

It really depends on your threat model: do you trust the people you are talking to but not Signal (though in practice this doesn't even work as they are way too centralized, but whatever), or do you not trust the people you are talking to but are willing to trust Telegram? Clearly we should be able to have something where we don't trust either, as there is nothing about these phone numbers that is critical to Signal'…

Moxie addressed the phone number issue[0].

To save time he mentions that owning a SIM card or a smartphone with a Contacts application that holds phone numbers is a portable social network by design.

Pushing his idea further it's much easier for anyone to learn the penetration of Signal by checking against existing phone numbers. I can't imagine someone with a 200+ phone numbers querying service to validate a phone number is registered with Signal.

And while nicknames sound perfect in theory they lack one specific thing — validation of authenticity of a speaker. By this i mean an impersonator can claim the username and pose as someone else. Given a lot of people use transparent nicknames on the internet, it can pose a threat. So even when the nicknames roll out as a feature of Signal, it's good to facilitate somehow that a party i'm in contact with is someone genuine. Checking against phone numbers can mitigate the risk of fraud.

[0] https://youtu.be/Nj3YFprqAr8

Post reply on HN