Live data from Hacker News

You can change your number

signal.org

361–370 of 410 posts

Re: You can change your number

#361
post #290
post #171

Earlier quoted context omitted.

If that happens, that's not a disastrous thing. That means one person reveals who they're talking to in general, not just on Signal. It doesn't mean that the millions of Signal users all lose that privacy. But no, I don't use Signal. I just think it's strange how some people can't seem to wrap their head around any of the rationale for this when it's the most transparent thing in the world. Do I like it? No, but it's…

I don't think you are getting it -- I am not talking about single user. Whatsapp has 2 billion users, and they are pretty open that they upload entire user's phonebooks to Facebook-owned servers. We know Facebook is not worried much about privacy, so I am pretty sure that this data can be subpoenaed, sold and so on. If you care about privacy, you probably want to install something else, like Signal. But you know what…

No one knows which app you're contacting them on. Send them a text message and suddenly your activity is cloaked.

This isn't that hard.

Re: You can change your number

#362
post #330

Earlier quoted context omitted.

Discord is not end to end encrypted, and Discord, along with whoever buys them, will receive the complete plaintext message history of all of your conversations with those friends.

Yup, and I don’t care. If I ever organize a protest I’ll do it on Signal, or another end-to-end encrypted platform. For daily banter I’ll use whatever a majority of my friends prefer. That’s currently Discord for the above-mentioned reasons.

[deleted]

Re: You can change your number

#363
I never understood using phone # as a permanent ID. phone numbers change (heck, I effectively have 2 whatsapps, because I have a US phone # and an international phone # because of this).

ID shouldn't matter to most users (it can be hidden behind the scenes). Phone # is great for looking up the ID, but users should be able to remap it at will.

Example:

register with your phone #. This generates a new ID (you don't know or care about it). If you have to login from a new device, that doesn't have the ID stored, can you login with your phone #, but all this does is look up the ID and uses that ID to try and then authenticate you.

If someone wants to find you, they use the phone number to look up your ID. Once its looked up and mapped, the phone number never needs to be used again.

If I change my phone #, all I have to do is update the mapping of phone # -> id (i.e. add a new entry, remove the old entry). Anyone contacts who have me already, will not be bothered by this (they only care about the ID, which they already have). new "contacts" will also behave correctly, as I no longer have that phone #, so it shouldn't be able to be used to find me (it might be someone else's # now).

Users would be able to move phone #s and their existing contacts would be able to follow them. New telephone users would be able to get recycled old phone #s without getting messages from the old owner of number's contacts (assuming they had previously contacted).

the only places I see people think this might fall down (but I think are wrong) is

1) if the same user creates a new id with the old phone #. However, the solution seems pretty simple, you just need a way to invalidate the old ID (i.e. never to be used again) and force the contact to get the new id for the phone number.

2) what happens when a user moves devices. i.e. they might have to redo the mapping of phone # -> id. However. at its worst, this is no worse than the current system (which effectively does that update on every single message). In practice, there are ways to move data between devices which would just move the mappings with it (examples being a cloud cache backup, the ability migrate data from device to device, or probably other ways as well).

Re: You can change your number

#364
post #349
post #330

Earlier quoted context omitted.

Discord is not end to end encrypted, and Discord, along with whoever buys them, will receive the complete plaintext message history of all of your conversations with those friends.

But for a lot of purposes, encryption really isn't that important. Most friend groups isn't a group of journalists and their sources discussing state secrets. The privacy from end-to-end encryption is a nice-to-have, but I'm not even sure if it's worth the inherent inconvenience for most friend groups.

How do friend groups deal with members who might want to drop a potentially controversial in future viewpoint, let alone a politically charged opinion?

Any use of a non-e2e service as a replacement for an e2e service basically means either self-censorship or recklessness. The data is not going away, and if context changes can implicate everyone involved.

Re: You can change your number

#365
post #332

Earlier quoted context omitted.

Phone numbers are associated with one's real-life identity though.

Sometimes, but you can always get one that isn't for use with Signal. That's what I do.

In many countries the government and the company that you register the number with need to know who you are (or can deduce it from the place where you are connecting).

Re: You can change your number

#366

Why would supposedly secure communicator use actual phone number as identifier is beyond me. And everybody does that, either phone number or email. The only software I could find for anonymous communication was old Polish communicator http://gg.pl which uses arbitrary numbers as identifiers I understand that startups are scared that they won't be able to build up userbase from scratch but come on! Discord and Slack d…

> I understand that startups are scared that they won't be able to build up userbase from scratch but come on! Discord and Slack did it.

I don’t use slack but the few times I tried to use discord it always said something suspicious was going on and asked me for my email (needless to say I immediately closed the window) I wasn’t using vpn, only my default ublock and Firefox built in track blocking.

Re: You can change your number

#367
post #332

Earlier quoted context omitted.

Sometimes, but you can always get one that isn't for use with Signal. That's what I do.

In many countries the government and the company that you register the number with need to know who you are (or can deduce it from the place where you are connecting).

Yes, but people in those countries can buy a US VoIP number from a US vendor for $2 and use that as their Signal number.

You don't need to use a GSM number, and you don't need to use the country code in which you live. The fact is, mostly anonymous phone numbers are available on the internet for use with Signal, and Signal (correctly) does not discriminate on country code or "type" of number. Any number that can receive phone calls or texts will do.

There are indeed countries that want to tie phone numbers to strong identity, but you can simply get a second number from a country that's not so hellbent on restricting access.

The number you're logged in to in Signal on a phone does not need to be the same number of the SIM card inside that phone. You can use any number you wish.

Re: You can change your number

#368
post #330

Earlier quoted context omitted.

Discord is not end to end encrypted, and Discord, along with whoever buys them, will receive the complete plaintext message history of all of your conversations with those friends.

Yup, and I don’t care. If I ever organize a protest I’ll do it on Signal, or another end-to-end encrypted platform. For daily banter I’ll use whatever a majority of my friends prefer. That’s currently Discord for the above-mentioned reasons.

You know that. It's unlikely that all of the rest of the people who join Discord because "all of their friends are on it" that your presence there influenced know that, and in many possible future scenarios, you and others' presence there directly contributes to the harm that may befall them as a result of their loss of privacy thereby.

https://www.brainyquote.com/quotes/cardinal_richelieu_183310

It's also impossible to effectively self-censor in the present for potential content-based threats in the future.

Discord also bans certain entire domains from being sent as links in DM, as an antispam measure, and requires in their ToS that people give up their civil rights to join. It's not polite to ask friends to submit to third-party censorship of private conversations just to talk to you.

Re: You can change your number

#369

Why would supposedly secure communicator use actual phone number as identifier is beyond me. And everybody does that, either phone number or email. The only software I could find for anonymous communication was old Polish communicator http://gg.pl which uses arbitrary numbers as identifiers I understand that startups are scared that they won't be able to build up userbase from scratch but come on! Discord and Slack d…

Email is okay to me because you can actually own one.

Phone numbers though are terrible because they're tied to countries, their security depends only on your carrier, you can't run your own carrier to take it into your own hands, and sending SMS costs money. Also the underlying interconnection networks like SS7 aren't secure at all and rely on trust.

Re: You can change your number

#370

Why would supposedly secure communicator use actual phone number as identifier is beyond me. And everybody does that, either phone number or email. The only software I could find for anonymous communication was old Polish communicator http://gg.pl which uses arbitrary numbers as identifiers I understand that startups are scared that they won't be able to build up userbase from scratch but come on! Discord and Slack d…

> Why would supposedly secure communicator use actual phone number as identifier is beyond me. It's pretty simple - user friendliness and sign-up friction. Signal's main market is not us HN user tech bros who want (pseudo)anonymity. It's main market is closer to regular people, the same people who are fine with using WhatsApp or Facebook messenger or whatever, with their phone number. They also want it to be as easy…

Doesn't explain why _only_ phone numbers are (currently) supported. Having phone numbers as the default or even asking permission to import your contacts would have been fine-ish if it was also possible to register using another anonymous method like email...

One counterpoint to using phone numbers: In China mobile phone numbers are almost universally enforced as your digital identifier because it makes surveillance extremely easy for a government while making it relatively hard for platforms themselves. Registering for a phone number mandates an ID check at the point of the service provider. This means that with a phone number based login, (1) you can be largely anonymous to platforms as you can have > 1 phone number, (2) you have 2fa built in automatically, but also (3) that the government can easily figure out who owns what accounts because your accounts are directly linked to your phone(s) and your phone(s) directly to you.

It would be a great step forward if Signal moves towards alternate verifications that don't involve phone numbers...

Post reply on HN