Earlier quoted context omitted.
After countless discussions of Signal on HN, I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list. Surely, in either case the identifier can be treated as an opaque string, right? Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Sign…
> Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Signal's current design would break? I feel like you're mis-analyzing a social problem or some other design goal as a low-level technical problem. I don't know their real reason, but I can say that my email contact list is waaay messier and less curated than my phone contact list. It wou…
Twilio incident: What Signal users need to know
101–110 of 512 posts
Re: Twilio incident: What Signal users need to know
#102Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
I will admit that this requirement always confused me. What is there to benefit from by requiring it?
And then nobody would use Signal.
It’s very unfashionable today, but they decided to not let perfect be the enemy of good.
Re: Twilio incident: What Signal users need to know
#103Guys how is the punctuation here not a colon?!
This is an extremely serious issue according to my English Major inclination towards pedantry.
Re: Twilio incident: What Signal users need to know
#104Earlier quoted context omitted.
Do "normies" care about high quality encryption? And did signal ever turn on username support?
I think developers have a moral responsibility to make their products as secure as possible, within reason and while still being usable. It doesn't matter if the users care about the benefits. To your second question: no, not yet.
Re: Twilio incident: What Signal users need to know
#105>Among the 1,900 phone numbers, the attacker explicitly searched for three numbers, and we’ve received a report from one of those three users that their account was re-registered. I wonder if this was a curious attacker trying to see what they could do with their access, or a targeted attack.
You can btw use the password reset function on many sites to correlate it with notifications. Easy at public events.
Re: Twilio incident: What Signal users need to know
#106Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
I will admit that this requirement always confused me. What is there to benefit from by requiring it?
Re: Twilio incident: What Signal users need to know
#107Earlier quoted context omitted.
The Signal protocol has had "sealed sender" since 2018 - Signal server does not know who sent a message, because the sender's identity is E2E encrypted along with the message. Even if Signal's server saves a message (they claim not to, once downloaded), Signal's server by design has no way of knowing who sent the message.
Every inbound message is authenticated, and credentials are stored somewhere . Correct me if I am wrong, but I'm betting that it's with the same credential/channel as for logging-in a user (aka "sender"). Also, wasn't "sealed sender" broken (again) earlier this year by a group of researchers?
There is no authentication by the sender, and the sender does not upload any credentials.
Re: Twilio incident: What Signal users need to know
#108Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
I will admit that this requirement always confused me. What is there to benefit from by requiring it?
Re: Twilio incident: What Signal users need to know
#109Earlier quoted context omitted.
That's a good way to build a secure messaging app nobody ever uses.
It may very well be the case for the smartphone-flipping demographic that prefer WhatsApp and TikTok, but I think it's a misunderstanding/misrepresentation of the crowd that go for e.g. Signal and Telegram.
Re: Twilio incident: What Signal users need to know
#110Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?
It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.
But brogrammers will. /s