Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
Twilio incident: What Signal users need to know
221–230 of 512 posts
Re: Twilio incident: What Signal users need to know
#222Earlier quoted context omitted.
I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so. I haven't done a deep dive, but as far as I can tell in most cases it's legal to 3d print too, though admittedly that's something that there are some semi-serious efforts to change. In other words I'd suspect the classification of "self defense advocate" to be a self serving branding effort since there a…
>I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so. Outside of the United States, that's usually not the case. Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous. And even within the United States, there are individual s…
A good and fair point. I'd fallen into the trap of being too US centric on HN.
> Were it not for certain Supreme Court decisions, handgun ownership would be outright illegal in the District of Columbia and likely in several other states.
Sure, were it not for the Supreme Court. But as there remains plenty of ways to legally obtain guns in the US, I'm still going to doubt that you've resorted to gun smuggling for "self defense"
Re: Twilio incident: What Signal users need to know
#223Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…
1. generally, a certain phone number uses signal
(1) happens once, upon registration of your phone number. You don't see history of which phone numbers are communicating, do you?
In other words, you don't need Signal to buy someone's location history. You just need their phone number and Signal doesn't particularly provide that to you.
Per my understanding, Signal provides subpoena/nation-state resistant level security and is in fact used by many people with high security needs.
Re: Twilio incident: What Signal users need to know
#224Earlier quoted context omitted.
> abortion seekers Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.
Why is it laughable? https://www.npr.org/2022/08/12/1117092169/nebraska-cops-used...
Irrelevant of your position, please read the entire article that you referenced for facts (pre-RvW overturn, pregnancy at 23~28 (?) weeks, took Pregnot, buried in back yard, Nebraska law was at that time 20 weeks).
The Vice article seems to have quite a lot more facts and references. https://www.vice.com/en/article/n7zevd/this-is-the-data-face...
Re: Twilio incident: What Signal users need to know
#225This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…
where does Telegram fit in your opinion? genuine question from someone oblivious to messaging advances in the last decade.
Services like Signal, Whatsapp, Keybase, or iMessage that provide e2e encryption for all chats, group or otherwise, (albeit with differing levels of implementation security) have chosen to do so at the expense of things like mobility of chat history across devices and the ability to easily discover and join new group chats and instead focus on a less organized, more ad-hoc form of messaging that's a rather different use case than Telegram's.
Re: Twilio incident: What Signal users need to know
#226This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…
I love Keybase, but I would never recommend it today. Zoom acqui-hired the team in 2020: https://blog.zoom.us/zoom-acquires-keybase-and-announces-goa...
Re: Twilio incident: What Signal users need to know
#227Re: Twilio incident: What Signal users need to know
#228Earlier quoted context omitted.
It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.
Why are server-side contact lists needed to support identities not linked to phone numbers?
1. Support phone number contact discovery, with persistence provided by the contacts provider. This is seamless and causes the least amount of complaints.
2. Support username discovery, with persistence provided by passphrase-encrypted online storage. This is painful and risks backlash from people losing access to data. Also, now the threat model must account for or ignore weak derived keys (which is probably most of them).
- 2a. Enforce strong passphrase requirements. Many users will abandon the product.
- 2b. Sync usernames between linked devices (using a generated key). Requires multiple devices, risks people losing data, more complaints.
- 2c. Sync usernames using custom contacts provider fields (e.g. email). Nobody is accustomed to doing this, but it might work. Automatic discovery rates would be low. Possibly requires an odd workflow for people adding Signal contacts by their email/username.
Re: Twilio incident: What Signal users need to know
#229Earlier quoted context omitted.
After countless discussions of Signal on HN, I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list. Surely, in either case the identifier can be treated as an opaque string, right? Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Sign…
> Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Signal's current design would break? I feel like you're mis-analyzing a social problem or some other design goal as a low-level technical problem. I don't know their real reason, but I can say that my email contact list is waaay messier and less curated than my phone contact list. It wou…
One of the reasons I wish I could use something other than my phone number and access to my contact list to work with signal is these notifications creep me the fuck out and I would rather never get them, or have anyone get them about me.
I'm fine with it being a feature for people who want it, but I don't. I want to make my own damn choices about who I talk to through it.
Re: Twilio incident: What Signal users need to know
#230Earlier quoted context omitted.
I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so. I haven't done a deep dive, but as far as I can tell in most cases it's legal to 3d print too, though admittedly that's something that there are some semi-serious efforts to change. In other words I'd suspect the classification of "self defense advocate" to be a self serving branding effort since there a…
>I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so. Outside of the United States, that's usually not the case. Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous. And even within the United States, there are individual s…
Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous". And i think most non-Americans would agree that adding some friction to a fringe case (owning a personal firearm for protection or fun is not something most people do, even in the US) is worth it if it nearly eliminates blatant misuses of firearms - either making suicides easier and more terminal, enabling easier revenge murders, or making your average school/public place shooting easier.
What would you consider a just middle ground between "onerous requirements" and "everyone can buy any weapon without any requirements but paying for it"?