Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

91–100 of 512 posts

Re: Twilio incident: What Signal users need to know

#91

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

They trade your privacy for not having to figure out some technical issues.

Also, when they rolled out their cryptocurrency payment system (after keeping the server-side source code secret for more than a year, during which Moxie, who is a paid advisor to that same cryptocurrency, denied they were working on a payment system), they got KYC for free.

Re: Twilio incident: What Signal users need to know

#92

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

I believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.

Re: Twilio incident: What Signal users need to know

#93

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

Making it more expensive to create spam accounts, I'd guess.

Re: Twilio incident: What Signal users need to know

#94

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

Besides fighting spam accounts, finding and connecting with others is easier. No more needing to ask somebody what their account name / friend code / ICQ number / whatever UID a system uses to add them to your contacts. It's not a good user experience to type in someone's sometimes insane username.

Meanwhile, someone in my contacts that installs Signal automatically sees my name pop up and can start chatting. Far easier, and helps drive adoption.

Re: Twilio incident: What Signal users need to know

#95
post #74
post #35

Earlier quoted context omitted.

Isn't email even worse for security?

You can trivially create as many emails as you want, anonymously and for free. In many countries, registering phone numbers anonymously is illegal and/or impossible.

> You can trivially create as many emails as you want, anonymously and for free.

Where? Gmail and hotmail both don't allow this.

Re: Twilio incident: What Signal users need to know

#97
post #94

Earlier quoted context omitted.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

Besides fighting spam accounts, finding and connecting with others is easier. No more needing to ask somebody what their account name / friend code / ICQ number / whatever UID a system uses to add them to your contacts. It's not a good user experience to type in someone's sometimes insane username. Meanwhile, someone in my contacts that installs Signal automatically sees my name pop up and can start chatting. Far eas…

Except the reality is that I'm asking for a phone number to add people (well on whatsapp here in europe), and most screen names people chose can be communicated verbally while phone numbers often have people resorting to handing the phone displaying the number around.

Re: Twilio incident: What Signal users need to know

#98
post #53

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.

> weak 4-digit PIN

Are you sure that it makes sense to require people to pick something longer and non-numeric for a PIN?

Or is your claim (wrongly) that people don't have longer non-numeric PINs (lots of us do) ?

Re: Twilio incident: What Signal users need to know

#99
post #35
post #8

Earlier quoted context omitted.

Give people the option to pay. I would gladly pay $100 one time fee if it meant I could avoid having a phone number associated. https://jmp.chat is a great work around but I would rather just have an email address or ideally nothing but a receipt directly associated with my signal account.

Isn't email even worse for security?

"security" is vast and means different things to different people.

Email can absolutely be used for with e2e encryption keeping the content of exchanges from external eyes.

Email can absolutely not be used for hiding metadata of who talks to who.

Re: Twilio incident: What Signal users need to know

#100
post #94

Earlier quoted context omitted.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

Besides fighting spam accounts, finding and connecting with others is easier. No more needing to ask somebody what their account name / friend code / ICQ number / whatever UID a system uses to add them to your contacts. It's not a good user experience to type in someone's sometimes insane username. Meanwhile, someone in my contacts that installs Signal automatically sees my name pop up and can start chatting. Far eas…

There's no need to make it a requirement for this. Matrix has similar functionality, but doesn't require that you add your phone, just makes it an option.
Post reply on HN