Live data from Hacker News

Default disappearing messages

signal.org

161–170 of 187 posts

Re: Default disappearing messages

#161
post #94

I dunno, I think being able to hoard your own data shouldn't be demonized or valorized? Fine with whatever the default is, but I feel like the subtext here is that Signal thinks people's phones are going to be increasingly compromised so this will be a more necessary, and the "remember the passing acoustic conversation" is just a way to put a less depressing spin on that.

>the subtext here is that Signal thinks people's phones are going to be increasingly compromised Phones are compromised by default. E2EE doesn't matter if someone else owns both ends.

> Phones are compromised by default

The issue is a matter of degree. Everything and everyone are compromised to some degree; perfection is not the standard.

Re: Default disappearing messages

#162
What's the point? They copied Telegram's "secret chat" feature, which is completely encrypted and spun out a WhatsApp equivalent. The narrative has been spun around "journalists and dissidents" and precisely, the same group of users, can use Telegram too with usernames instead of actual mobile phone numbers. It's appealing to the feature set I know, but it boils down to the dumbification of UI. Telegram is a complete platform - secret chats don't sync across devices (I have a reason to believe it might be using the on-device system to generate keys), but it is not a show-stopper for me. I fail to understand the hoopla around Signal.

Re: Default disappearing messages

#163
post #3

The max timer is too short. 6 months would be a convenient value - enough time to reference the messages while they might be relevant, but also not floating around forever

From Signal in July 2020:

> As far as longer durations are concerned, it's tricky, because backups do not include disappearing messages. That can cause unexpected behavior for a user that set their timer to 18 months.

https://github.com/signalapp/Signal-Android/issues/9855

Re: Default disappearing messages

#164

Signal associates users to their phone numbers. Does this mean if they are subpoenaed by the government they can give the list of their users ?

"the only information we can produce in response to a request like this is the date and time a user registered with Signal and the last date of a user’s connectivity to the Signal service"

https://signal.org/bigbrother/eastern-virginia-grand-jury/

Re: Default disappearing messages

#165

Earlier quoted context omitted.

From here: * https://signal.org/docs/specifications/x3dh/ ... I understand that the prekeys are signed. I will confess that I have no deep understanding of how everything works together. Signal protocol is somewhat baroque.

The (signed) prekeys are public information about a user, although unlike their long term Identity key the prekey is replaced periodically to help ensure Forward Secrecy. The signature means Alice knows she was given Bob's real public prekey and not a fake, but she doesn't get a different prekey (or signature) than Charlie or Deborah if they ask in roughly the same time period. A loose equivalent in the OpenPGP world…

[deleted]

Re: Default disappearing messages

#166
post #113

Earlier quoted context omitted.

You wrote "Remember, when Telegram came around WhatsApp was un-encrypted. Not point-to-point encrypted, just encoded." Given that Telegram was first released in 2013, your own quote contradicts that.

ok, now I admit you might have caught me in a mistake. Thanks! I like to get corrected. Edit: and have my upvote. Now: can you admit that WhatsApp was unencrypted and you were wrong?

WhatsApp was unencrypted in its early days, sure. As you said, 2009 was a different time. I'll admit that 2012 was significantly later than I expected, and FWIW that does reduce my trust in WhatsApp (who I've never been the biggest fan of in any case).

But I think my original point still stands, because at no point has Telegram been a more secure alternative to mainstream messenger options (such as WhatsApp), despite their marketing and branding being security/privacy-oriented and their "breakout moment" being a targeted, hypocritical call-out of WhatsApp security. Yes, I'm holding them to a higher standard than WhatsApp. But I think that's completely fair given that security and privacy is Telegram's supposed selling point, whereas WhatsApp never positioned itself as anything more than a way to send messages to each other.

If Telegram had come first then I could understand why people would keep using it. But I don't get why anyone would switch to it (except for the owned-by-Facebook thing I guess, which sure, is much more of a question about what your threat model is).

Re: Default disappearing messages

#167
post #62

Earlier quoted context omitted.

Then don't set this option?

Isn't it something that the sender decides?

The person who initiates the conversation does, yes; that is already the case today. However, you can change the conversation settings not to do that.

Of course, if the other party would prefer history to be deleted, it's generally nice to go along with that.

Re: Default disappearing messages

#168
post #166

Earlier quoted context omitted.

ok, now I admit you might have caught me in a mistake. Thanks! I like to get corrected. Edit: and have my upvote. Now: can you admit that WhatsApp was unencrypted and you were wrong?

WhatsApp was unencrypted in its early days, sure. As you said, 2009 was a different time. I'll admit that 2012 was significantly later than I expected, and FWIW that does reduce my trust in WhatsApp (who I've never been the biggest fan of in any case). But I think my original point still stands, because at no point has Telegram been a more secure alternative to mainstream messenger options (such as WhatsApp), despite…

> But I think that's completely fair given that security and privacy is Telegram's supposed selling point, whereas WhatsApp never positioned itself as anything more than a way to send messages to each other.

Why don't you look at discussions here and see why people use Telegram?

Many, maybe most of us don't think of it as specially secure.

If you ask why people use it they'll tell you it is fast, stable, almost bug free, well designed and everyone else in their group uses it.

I've yet to see anyone using cryptographic security as a selling point.

Telegrams biggest claim to fame security wise is their censorship resistance and that they get away saying they've never give authorities one bit of user data, year after year. If they had a secret deal with anyone that should soon become obvious.

Edit:

> and FWIW that does reduce my trust in WhatsApp (who I've never been the biggest fan of in any case).

I'm consistent here: I liked them better back then when they were a scrappy startup trying to do good in a world of ads and tracking.

Technical issues can be fixed, as they have done.

The incentives formed by being bought for $17bn (or 19 or whatever?) by Facebook, they cannot easily be fixed.

Yes, messages are now E2E-encrypted but we now have thousands of people working trying to exploit metadata etc instead of 50 guys trying to avoid that.

Re: Default disappearing messages

#169
post #166

Earlier quoted context omitted.

WhatsApp was unencrypted in its early days, sure. As you said, 2009 was a different time. I'll admit that 2012 was significantly later than I expected, and FWIW that does reduce my trust in WhatsApp (who I've never been the biggest fan of in any case). But I think my original point still stands, because at no point has Telegram been a more secure alternative to mainstream messenger options (such as WhatsApp), despite…

> But I think that's completely fair given that security and privacy is Telegram's supposed selling point, whereas WhatsApp never positioned itself as anything more than a way to send messages to each other. Why don't you look at discussions here and see why people use Telegram? Many, maybe most of us don't think of it as specially secure. If you ask why people use it they'll tell you it is fast, stable, almost bug f…

Like I said in the parallel thread, literally the first line of the first ad/result I get when searching for Telegram is "Telegram messages are heavily encrypted". It may not be your reason for using it but it's very much what they're pushing.

Re: Default disappearing messages

#170
post #73
post #69

Earlier quoted context omitted.

For that same reasoning I support telegram more than signal. I simply do not see signal ever get to a widespread adoption, I do not see signal trying to get to a widespread adoption either; signal is not a messaging app it is a secure comunication app and for this they make a lot of tradeoffs. An example is E2EE, it is a nice property but today it has significant UX implications that makes it bad default in my opinio…

> For that same reasoning I support telegram more than signal. I simply do not see signal ever get to a widespread adoption, I do not see signal trying to get to a widespread adoption either; signal is not a messaging app it is a secure comunication app and for this they make a lot of tradeoffs. But Telegram's whole selling point is privacy and security. If security is not your priority (which is totally reasonable!)…

There are a lot of regional variations on this and the only regions I am vaguely familiar with are a couple countries in europe and the US/Canada, that said:

> there are plenty of other messaging apps that are much more established than Telegram.

Not where I live, the only comparable app is whatsapp and after that various social media platforms probably.

> [E2EE] Doesn't seem to have been a problem for e.g. WhatsApp.

It is, porting backups between phones (last time I tried) requires both phones to be active.

> and it's not like people were using SMS/phone calls until Telegram came along with the revolutionary new idea of an internet messaging app.

They were using whatsapp, which in my opinion is worse than telegram and uses E2EE as a PR shield. I personally do not trust facebook to deliver a trustworthy app (they would have to be OSS with reproducible builds at least) I do not care that my messages are encrypted on their servers, they can steal them from my phone storage directly. It is a matter of lack of trust towards facebook.

Post reply on HN