Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?
It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.
Twilio incident: What Signal users need to know
81–90 of 512 posts
Re: Twilio incident: What Signal users need to know
#82Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?
I do wish Signal would be more transparent though. Given that this is such a difficult problem and they've been struggling with it for years, it reasons that it is time to seek help. This is like when a student just studies for hours and hours on end, spinning their wheels. They aren't learning anything. At some point you need a tutor, help from a friend, or asking the professor for help. (Or analogy in work if that's better)
Signal, it is time to be transparent.
Re: Twilio incident: What Signal users need to know
#83Earlier quoted context omitted.
The sane alternative is that it could keep a client-side contact book that users would be responsible for managing entirely on their own, including when setting the app up on a new phone. Addendum: also, there is nothing preventing this type of contact book data from being backed-up/synced to a new phone, like any other data and settings of any other app. iOS has this feature since like 7 years now. Android, too, I'm…
That's a good way to build a secure messaging app nobody ever uses.
Re: Twilio incident: What Signal users need to know
#84Earlier quoted context omitted.
It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.
Do "normies" care about high quality encryption? And did signal ever turn on username support?
Re: Twilio incident: What Signal users need to know
#85Re: Twilio incident: What Signal users need to know
#86Earlier quoted context omitted.
Users having to add their contacts each time they set Signal up on a new phone, should the app keep its own client-side contact book, doesn't sound like hassle. Could you please explain how Signal does not have a social network map, when 1) user accounts are equal to mobile phone numbers, and 2) Signal servers route messages between user accounts.
The Signal protocol has had "sealed sender" since 2018 - Signal server does not know who sent a message, because the sender's identity is E2E encrypted along with the message. Even if Signal's server saves a message (they claim not to, once downloaded), Signal's server by design has no way of knowing who sent the message.
Also, wasn't "sealed sender" broken (again) earlier this year by a group of researchers?
Re: Twilio incident: What Signal users need to know
#87Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
I will admit that this requirement always confused me. What is there to benefit from by requiring it?
Re: Twilio incident: What Signal users need to know
#88Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
I will admit that this requirement always confused me. What is there to benefit from by requiring it?
Re: Twilio incident: What Signal users need to know
#89Earlier quoted context omitted.
Signals very explicit goal is making something that's usable for everybody. If they'd wanted to make a nerd-messenger they'd make a different product. (I still consider it a major downside that the phone number is the only lookup key)
Sounds pretty drastic to me to draw the line between "everybody" and "nerds" at the point of the contact book being available or not.
Re: Twilio incident: What Signal users need to know
#90Earlier quoted context omitted.
How do you deal with spam without requiring a phone number to register?
Give people the option to pay. I would gladly pay $100 one time fee if it meant I could avoid having a phone number associated. https://jmp.chat is a great work around but I would rather just have an email address or ideally nothing but a receipt directly associated with my signal account.