Live data from Hacker News

Signal WhatsApp Chats Import

github.com

191–200 of 283 posts

Re: Signal WhatsApp Chats Import

#191

Spending the weekend building Signal for iOS so I can try to dump message contents before I send an iPhone in to Apple. Just astounding that there is deliberately no way to backup messages (which has be available on Android for some time). Definite love-hate relationship with users, which I fully reciprocate. So great job getting WhatsApp import working. But too bad you can't export anything from Signal. Dark pattern…

It’s not working. This is just a link to renewed discussion on a closed issue.

Re: Signal WhatsApp Chats Import

#192
post #19

I have been using Signal for two years now and I love it. However I really, really hope they can work on a good backup and restore process as losing my message history because I have to reinstall the app on my desktop[1] or have to reset my phone is a horrible experience. Just build an encrypted blob and zip it up and pop it on my iCloud or Google Drive or leave it local and let me deal with it but I need something .…

Multiple devices / reinstall works flawlessly on Telegram.

I can't walk my mom through the archaic Signal backup/restore all the time.

Re: Signal WhatsApp Chats Import

#193
post #46

Earlier quoted context omitted.

> However I really, really hope they can work on a good backup and restore process as losing my message history because I have to reinstall the app on my desktop[1] or have to reset my phone is a horrible experience. I've tried to report bugs and talk to developers about this but there's one fundamental problem here - the Signal team fundamentally does not value chat history the same way a lot of people do. They thin…

> the Signal team fundamentally does not value chat history the same way a lot of people do This is the core problem as why many projects don't get mainstream. They have 2 options: they can focus on what they think is a priority, or on what the public thinks is a priority. I'm not saying Signal is wrong on doing what they are doing, as they are being successful among some niches (i.e: tech). But to grab Whatsapp user…

This is exactly why Telegram is beating Signal.

They're singularly focused on the user experience and what users want.

Uninstall / reinstall / multiple-devices works flawlessly.

Re: Signal WhatsApp Chats Import

#194

This is blowing up quite big now and I have managed to shift a lot of my friends to Signal now, I wonder if WhatsApp will go back on its decision. As we stand now even Signal is not safe because of the business model. I wonder what's the model on messaging apps that will work. I don't want the OS creators to own the messaging platforms as well by virtue of subsidising it through OS/hardware.

Moving a few close friends to another app is easy. Moving acquaintances, people you just met, businesses, organizations, etc. is another thing entirely.

Re: Signal WhatsApp Chats Import

#195
post #80

Earlier quoted context omitted.

Really? I can't believe that. I mean, in a sense, all software is just a vehicle for the data it processes, and the actual value lies in the data - not the software. That data is chats for Signal. If they think that's worthless, even just the history of it, it means they don't really value their own application. They are wrong.

The Signal protocol is forward-secret. I don't know the nitty-gritty specifics of the protocol, but the essence is this: You don't want someone getting access to your account two years from now to be able to access every old message. Consider every message a separate object that gets encrypted. The keys are changed/updated each time a new device is added to an account. That new device only knows the new key(s), and t…

Neither you nor any Signal dev knows what I want (i.e., what security vs convenience tradeoffs I am willing to make). I will choose the tool that allows me to use it in the way I want to use it.

Re: Signal WhatsApp Chats Import

#196
post #46

Earlier quoted context omitted.

> However I really, really hope they can work on a good backup and restore process as losing my message history because I have to reinstall the app on my desktop[1] or have to reset my phone is a horrible experience. I've tried to report bugs and talk to developers about this but there's one fundamental problem here - the Signal team fundamentally does not value chat history the same way a lot of people do. They thin…

>...the Signal team fundamentally does not value chat history the same way a lot of people do. Keeping around old messages more or less negates the value of forward secrecy. The Signal Protocol is obsessively forward secret. So it would be reasonable for those that have put so much work into getting rid of old messages for good would not value them.

This really miscomprehends what forward secrecy means. PFS prevents an adv who obtains the keys from decoding previous messages -- even with access to your unlocked phone (and the long lived keys) they couldn't obtain cleartext on any message you had deleted, even with the ciphertext. Also, having a plaintext message does not confirm it was a particular ciphertext.

But it really isn't available to the software author to know how long we want to keep a message for. If I want I can set a disappearing message timer.

Re: Signal WhatsApp Chats Import

#197

Earlier quoted context omitted.

Your point and use case are valid but unrelated. I agree with the parent comment but not with your sentiment.

The thing is: your use case and wants seems to be different than like, 90% of Whatsapp users, as they expect to never lose their history. So... Signal is not a replacement to Whatsapp

That's fine with me. I was just pointing out that those two requests are not really related.

I don't know much about WhatsApp, and I've never lost any message in Signal, so I am not sure I am well equipped to discuss whether it's fit for that purpose. But I would certainly love to save individual messages in some sort of vault, as well.

Re: Signal WhatsApp Chats Import

#198

Earlier quoted context omitted.

I mean, from the perspective of the crypto it doesn't matter. But it defeats the point of building a forward-secret system. Think of it like this: if I'm an attacker that breaks into the forward-secret chat app on your device, and you have kept a perfect record of every conversation you've ever had using that crypto system in _the same place you keep your identity keys_, then does it really matter whether the messagi…

Chat history isn't immediately at odds with PFS. As I see it PFS first and foremost is for protecting messages in transit. This is to prevent dragnet-style surveillance. Chat history means giving up some measure of at-rest security, but it has no impact on the in transit part. Personally I also think some compromise of at-rest is a reasonable trade-off for a lot of consumer contexts because physical capture of your d…

But PFS is specifically about including "my adversary may, at a later date, compromise my private key" in your threat model without giving up plaintext. If we assume that calculating a private key from the public key is ~impossible (which I hope you agree we can do), and we further assume the private key never leaves the device, then forward secrecy is what lets us know the only way to get plaintext is by stealing it from an endpoint. Maybe I'm failing to see the adversary you're defeating with PFS if they're never going to access your device and siphon off private data...

I'm no expert, but if all you care about is transit security, I don't think you need PFS (in E2EE messaging! TLS is a different story, because you have to trust the server). Just protect your private key. But if you're carrying multiple device's worth of accumulated messages _right alongside_ your private key, then what's the point of rotating ephemeral keys after each message?

EDIT: I agree about a compromise on PFS/chat history being reasonable in most scenarios. But I also think that defaults are really important, especially as the contents of chat history can be leaked by other participants, whose chat backups you can't really control. It's a tough problem to solve for everyone.

Re: Signal WhatsApp Chats Import

#199
post #179

Why does Signal require a phone number, after all these years? It's a gigantic red flag that they unnecessarily require a tie-in to the primary governmental communication surveillance system. I've seen multiple attempted explanations, but nothing convincing.

I think it’s for contact discovery. I agree that it would be better to have it not be tied to another system. However, sharing your new ID is a source of friction for messaging apps and everyone wants to grow their app as quickly as possible.

Re: Signal WhatsApp Chats Import

#200
post #73

That's funny. People use Whatsapp because outside US and Asia is the worldwide de facto standard for messaging. The new TOS does not state that Whatsapp is going to read your messages, actually even the non-techo-savvy population in Europe knows that Whatsapp uses end-to-end encryption (they just know that "it cannot be intercepted"), so they use it for good reasons, and will continue to do so, because 99% of people…

> So it's not going to happen that there is a mass move outside of Whatsapp anytime soon.

I (sadly) agree with you on this. (Ciao Salvatore)

I'm surprised you're being downvoted, is it possibly because of the reference to the current POTUS being "silenced" on Twitter (despite you later state that you're anti-Trump)?

Anyway, I believe you're incorrect on your stance on the new TOS, but I'm studying it more now because I am also a bit confused and I've read conflicting interpretations.

Edit: part of the confusion might stem from the fact that TOS in Europe do not include the data-sharing part with Facebook, which is instead included elsewhere [0]

(HN user antirez is based in Europe, not in the US)

[0]: https://twitter.com/NiamhSweeneyNYC/status/13471849630163394...

Post reply on HN