Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

281–290 of 512 posts

Re: Twilio incident: What Signal users need to know

#281
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

I don't think it's stated enough just how easy signal is as a drop in replacement for WhatsApp, the main communication method for a significant portion of the world. The ability to install a new app, use your phones contact database, and be able to use the app nearly exactly the same way you used WhatsApp is an incredible feature. With almost zero effort you can significantly reduce (capitalist or nationstate) surveillance against you. It's not perfect but it's a lot of value for little effort.

All of these feature requests require less knowledgeable users to do new things or weigh alternative options which involves time spent developing onboarding. Having "one way," an opinionated way, to do a particular type of thing is a very useful engineering value especially if you have limited engineering resources. Simplicity is an extremely underrated feature.

Being 80% perfect for 20% of the work is laudable.

What's even better about Signal is that Facebook's competitive data is the list of people you know. Facebook wins every time a person adds a friend without adding their contact info to their phone. That means Facebook is the source of truth for who you know and Facebook is the intermediary for communicating with someone else. That's why, in retrospect, whatsapp was an obvious competitor worth spending a lot of money acquiring. WhatsApp drove people to use their phones contact list as the source of truth for you who communicate with, not Facebook's friend list.

Re: Twilio incident: What Signal users need to know

#282
post #254

Earlier quoted context omitted.

This doesn't make any sense. My assertion is that Signal would not be Signal if it has usernames. The subtext that I did not state specifically is exactly the question of why more people don't use Keybase regularly. Maybe it's not the winning UX? You don't get to look over at Signal and say "wow what a great user base I need to be a part of that" and then draw the conclusion that "Signal needs to support my idealogic…

fwiw I am a user of signal and I am expressing my need. Allowing it access to my contact list and my phone number is a privilege I extend nearly uniquely to it among similar apps and I want that gone. Because I can't just "not use signal," because signal is where the people I need to talk to are. Users are a key feature of any social product, you can't just "all else equal" them away. It's not really my problem if it…

I don't know whether or not it has always been the case, but Signal works fine without "access to my contact list". The Android app does seem pretty persistent in asking for it, though!

Re: Twilio incident: What Signal users need to know

#283
post #168

Earlier quoted context omitted.

I'm not saying its an amazing experience or solves the problem systematically. Again, some people simply don't need these features. You can literally just take part of the public key and that's it. That is totally fine for some use-cases.

Then use urbit. It already exists.

Yeah but the whole point of Signal is to allow secure very secure communication. With little effort they could allow this usecase. It would address a major criticism and they already have the underlying infrastructure.

But I guess you can just keep moving the goal post.

Re: Twilio incident: What Signal users need to know

#284
assigning accounts to numbers is the dumbest thing. I remember when I got a new phone number a few years ago I managed to login into someone else's venmo account. Numbers are like dynamic IPs, why would anyone use this to authenticate you is beyond me.

Re: Twilio incident: What Signal users need to know

#285

I absolutely do not understand why I have to link my very sensitive Signal account to a very insecure and hard to change ID: my phone number (which can be traced to my identity in too many ways). Why Signal does not allow fully anonymous IDs (like Threema does) is a mystery to me. Signal is fine for most users, but it is inherently _unsafe_ for high-value sensitive communications where participants can expect targete…

Anonymity isn't part of Signal's risk model. If you need to stay anonymous, then there are more suitable options.

It's not about that, it's pretty much the same as using a dynamic IP to authenticate you

Re: Twilio incident: What Signal users need to know

#287
post #148

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I wouldn't even call it bad. In may ways it's good, actually. It's good because it allows signal to build a product that is relevant and usable. Phone numbers only connect people and are a bridge to allow all the perfect crypto to do the legwork. The knee jerk "phone bad" reaction is understandable, sure. But I don't think it's warranted for Signal. Signal would look like Keybase without phone numbers. Keybase (or th…

People use telegram more and more which is based on usernames...

Re: Twilio incident: What Signal users need to know

#288
the recommended fix here is to add a PIN + enable registration lock

IIRC signal PIN was very controversial back in the day because they were 1) forcing users to do it and 2) forcing them to opt in to some data collection as part of creating a PIN. Signal backed down on requiring a PIN, but now it's unclear from their settings page whether setting a PIN will share data as well. The marketing copy on my droid device says:

> PINs keep information stored with signal encrypted so only you can access it. your profile, settings and contacts will restore when you reinstall

For a company with relatively good cred, this is a shady way of saying 'we will upload your contacts and encrypt it with a short string'

Re: Twilio incident: What Signal users need to know

#289
post #284

assigning accounts to numbers is the dumbest thing. I remember when I got a new phone number a few years ago I managed to login into someone else's venmo account. Numbers are like dynamic IPs, why would anyone use this to authenticate you is beyond me.

Yes, it's a horribly dated idea, as-is receiving any kind of 2FA code via SMS.

Re: Twilio incident: What Signal users need to know

#290
post #202

Earlier quoted context omitted.

Try Element. Effectively the same crypto as Signal but you can be anonymous as needed. Also decentralized with many app options.

And if Element is not the desired application to use matrix, then there are plenty of others, and available across many device and OS platforms: https://matrix.org/clients/ ...Of course, Element remains the oldest and likely still most feature-full app.

I haven't really looked into Matrix. I appreciate the nudge!
Post reply on HN