I absolutely do not understand why I have to link my very sensitive Signal account to a very insecure and hard to change ID: my phone number (which can be traced to my identity in too many ways). Why Signal does not allow fully anonymous IDs (like Threema does) is a mystery to me. Signal is fine for most users, but it is inherently _unsafe_ for high-value sensitive communications where participants can expect targete…
Anonymity isn't part of Signal's risk model. If you need to stay anonymous, then there are more suitable options.
Twilio incident: What Signal users need to know
271–280 of 512 posts
Re: Twilio incident: What Signal users need to know
#272Earlier quoted context omitted.
>I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. I understand your concerns, and if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either. But, like the vast majority of us, I am not any of those things. As such, for my (and most…
Those of us that do not need high privacy today might need it tomorrow, or maybe someone we frequently communicate with. We also have a responsibility to favor tools and practices that make those that really need privacy not stand out. Element or other Matrix clients are easy to use and lack the serious flaws I outlined for Signal.
When it comes to that sort of messaging ("I'm running a few minutes late and will meet you inside the restaurant," or similar) I don't (and won't) separate those out. I just use Signal for all such messages.
Which makes for inconvenience when (especially iPhone users) install Signal and still use iMessage.
I'd add that if I have something to discuss that I don't want recorded (don't forget that it's not just your device that puts you at risk, anyone who's received such messages do so as well), I'll use encrypted voice calls (with the assumption -- valid or not -- that the other participant(s) aren't recording that conversation) with Signal or Matrix.
In both my personal and professional life, I've always made sure to only put in writing that which I wouldn't care if it was shared with the world.
Which is no different than it's ever been. I'm not sure why anyone thinks this is a new thing or that somehow "technology" obviates the need for good OpSec. It never did and still doesn't.
Re: Twilio incident: What Signal users need to know
#273Earlier quoted context omitted.
It's unsafe. They could lock you out from your Signal account and impersonate you. Someone who does not know you changed your number, forgot about it or does not think about this could then send a message to the person who has your old phone number thinking it's you at the other end. Most people don't bother with the warning about the security number having changed. I also personally assume that the phone number of a…
Thanks for the link. I have been way too lazy after having the new number for nearly a year. I just couldn't not do it after someone on the internet did the heavy lifting for me.
Re: Twilio incident: What Signal users need to know
#274Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
> don’t store any messages on their side Google Play services are still required for the official builds because of the (unverifiable to be really) encrypted backups. > everything is client-side Signal's FOSS fork developers would disagree. They got outright legal problems after they wanted to implement an open source alternative. Most APIs in regards to contact management are server-side. There's Molly as a younger…
??? I use the official build with encrypted backups without Google services, and have been doing so for at least 3 years. I've been forward-carying my backup since 2016, too.
Re: Twilio incident: What Signal users need to know
#275Earlier quoted context omitted.
where does Telegram fit in your opinion? genuine question from someone oblivious to messaging advances in the last decade.
Telegram only provides e2e encryption for one-to-one conversations and only if you specifically create a "secret chat" largely because of usability and discoverability reasons with regard to their major point of focus. Its probably better discussed in comparison to other services like IRC, Matrix, Discord, or Slack that concentrate on feature rich group chat implementation with easy discoverability, organization, and…
Re: Twilio incident: What Signal users need to know
#276Earlier quoted context omitted.
> If this is the product you want, then go use it. This is great advice if your goal is to send messages to yourself. In the real world, though, a messaging app that you're the only one using is about as useful as a bag of ice in a snowstorm. People don't need "like signal but with usernames," they need "signal with usernames (or email addresses or...)" so they can communicate with people who use signal.
This doesn't make any sense. My assertion is that Signal would not be Signal if it has usernames. The subtext that I did not state specifically is exactly the question of why more people don't use Keybase regularly. Maybe it's not the winning UX? You don't get to look over at Signal and say "wow what a great user base I need to be a part of that" and then draw the conclusion that "Signal needs to support my idealogic…
It's not really my problem if it's hard. That's for them to figure out. Until they do I will continue to be an unhappy user of their product, and no amount of people on the internet willing to defend their choices as if they were their own is going to change that.
Re: Twilio incident: What Signal users need to know
#277Earlier quoted context omitted.
Thanks for the link. I have been way too lazy after having the new number for nearly a year. I just couldn't not do it after someone on the internet did the heavy lifting for me.
Happy to know I had a (hopefully) positive impact :-)
Re: Twilio incident: What Signal users need to know
#278Earlier quoted context omitted.
That seems like a problem that could easily be solved by sending fewer notifications. Do I really need to know if somebody has joined Signal until I actually want to talk to them? Isn't it better to have a larger pool of people with whom I can communicate securely using Signal? I'm mostly just confused because this is being presented as a technical limitation: using email addresses would supposedly "require Signal to…
> That seems like a problem that could easily be solved by sending fewer notifications. Do I really need to know if somebody has joined Signal until I actually want to talk to them? I don't know what the real reason is, what I said was just something that popped into my head. Another comment mentioned spam-prevention as a reason (by making it infeasibly expensive), and that actually makes more sense. Honestly, there…
What I meant was: "it's better if I can use Signal to communicate with people even if all I know is their email address".
Re: Twilio incident: What Signal users need to know
#279Earlier quoted context omitted.
This doesn't make any sense. My assertion is that Signal would not be Signal if it has usernames. The subtext that I did not state specifically is exactly the question of why more people don't use Keybase regularly. Maybe it's not the winning UX? You don't get to look over at Signal and say "wow what a great user base I need to be a part of that" and then draw the conclusion that "Signal needs to support my idealogic…
fwiw I am a user of signal and I am expressing my need. Allowing it access to my contact list and my phone number is a privilege I extend nearly uniquely to it among similar apps and I want that gone. Because I can't just "not use signal," because signal is where the people I need to talk to are. Users are a key feature of any social product, you can't just "all else equal" them away. It's not really my problem if it…
Re: Twilio incident: What Signal users need to know
#280Earlier quoted context omitted.
This doesn't make any sense. My assertion is that Signal would not be Signal if it has usernames. The subtext that I did not state specifically is exactly the question of why more people don't use Keybase regularly. Maybe it's not the winning UX? You don't get to look over at Signal and say "wow what a great user base I need to be a part of that" and then draw the conclusion that "Signal needs to support my idealogic…
fwiw I am a user of signal and I am expressing my need. Allowing it access to my contact list and my phone number is a privilege I extend nearly uniquely to it among similar apps and I want that gone. Because I can't just "not use signal," because signal is where the people I need to talk to are. Users are a key feature of any social product, you can't just "all else equal" them away. It's not really my problem if it…