Live data from Hacker News

I asked Signal motivations for SMS removal

news.ycombinator.com

221–230 of 258 posts

Re: I asked Signal motivations for SMS removal

#221
post #190
post #176

Earlier quoted context omitted.

RCS might be a federated standard, but before Google not even Verizon at AT&T wanted to federate.

Not sure why you'd say "not even Verizon". Verizon is literally the worst carrier worldwide (ok maybe after NTT) with regards to interoperability.

I think they're saying that the two biggest US carriers didn't want to interoperate.

Which is insane. An SMS replacement where Verizon and AT&T users cannot message each other is insane.

Re: I asked Signal motivations for SMS removal

#222

Earlier quoted context omitted.

I haven't looked into the RCS protocol myself but what is preventing others from building their own RCS clients? As I understand the protocol, it's IP based rather than modem based, so external apps should work, right?

As far as I understand it right now its a lack of exposed APIs in Android to access the message stores. I suspect this is something that will be standardized and exposed in a future API revision, but as it stands right now using the official APIs I don't think you're able to make your own...

[deleted]

Re: I asked Signal motivations for SMS removal

#223
post #21

With Signal moving away from SMS, the required messaging app stack on my phone just to be able to receive everything sent do me will have to be: - Signal -> Close friends & family I've convinced to use it. - WhatsApp -> Most of my friends. - SMS -> School notifications, 2FA, shipping updates, etc. - Facebook Messenger -> Elderly relatives - Telegram -> That one relative who wants to use this instead of Signal. Is the…

I never understood Telegram. It's insecure by default, runs in a different jurisdiction. It's not even anonymous But somehow people started using it because it was "more secure" than whatsapp.

Telegram is now more to Discord than friends and family messaging app. You use Telegram and Discord similar on how you use Reddit or Hacker News.

Re: I asked Signal motivations for SMS removal

#224

Earlier quoted context omitted.

What security problems? Genuinely curious, not trying to be antagonistic.

Commentry from tptacek: https://twitter.com/tqbf/status/1575259743278563329 on this paper: https://nebuchadnezzar-megolm.github.io/

Thanks.

Worth reading the response from Matrix as well (https://matrix.org/blog/category/security).

My first reactions are to wonder how many of these issues are associated with federated (as opposed to fundamentally decentralized) group chat in general. Matrix seems to be taking the position that some of these issues ultimately relate to trust vs lack thereof in the homeserver as a bottleneck.

I also wondered if there was a good security model for federated or decentralized group chat at all at the moment. I can't remember offhand if Briar was adding groups or not, but that's not federated.

Re: I asked Signal motivations for SMS removal

#226

Earlier quoted context omitted.

Matrix has fundamental security problems that they seem unwilling to fix. Almost a polar opposite to Signal.

What security problems? Genuinely curious, not trying to be antagonistic.

https://arstechnica.com/information-technology/2022/09/matri...

Re: I asked Signal motivations for SMS removal

#227

Earlier quoted context omitted.

A bit weird for the "I don't use it so who cares" view to take a firm hold here. SMS is: 1. not controlled by a single company 2. a different network than the internet 3. a fail safe for people who don't use apps or are unable to at a given time for some reason (inc 2fa) 4. a fail safe for a "small group of people" who are suffering the consequences of a natural disaster. Though perhaps not economically feasible for…

And totally readable and accessible by any third party

I tried to imply that redundancy instead of privacy would be the reason to support SMS in my last sentence.

Is this the comment you would give when someone says they intend to take a notebook with them when travelling in addition to their phone?

Re: I asked Signal motivations for SMS removal

#228
post #25

Earlier quoted context omitted.

Matrix

Matrix has fundamental security problems that they seem unwilling to fix. Almost a polar opposite to Signal.

This is categorically not true, as per https://matrix.org/blog/2022/09/28/upgrade-now-to-address-en....

The only practical issue raised by https://nebuchadnezzar-megolm.github.io/ which we didn’t already fix is the question over whether servers or clients should control group membership. Our position is that it’s okay for the server to control it as long as clients are warned if malicious users/devices are added. Fixing it properly is Hard: for instance, if you are chatting in a room and it turns out that a remote user kicked another remote user, but the kick was delayed in reaching you, you could keep chatting away encrypting messages for a user who is no longer in the room and theoretically should not be receiving them. Is this a security flaw? Or is this just how causality works? So we’re dealing with problems similar to that; hopefully we will be able to switch to client controlled membership by end of year.

tptacek’s derision is not very constructive.

Re: I asked Signal motivations for SMS removal

#229
post #100
post #71

Earlier quoted context omitted.

It's down from the peak, but 40 billion SMSes were sent in the UK in 2021. I would be staggered if this number was majority B2C/2FA. https://www.statista.com/statistics/271561/number-of-sent-sm...

I would be staggered if it wasn't majority spam, OTPs, and automated reminders.

Born & raised in the EU, have had a phone for 25ish years. Have never encountered SMS spam. Most I've had is 3 or 4 cases of SMS phishing attempts (which isn't spam).

Re: I asked Signal motivations for SMS removal

#230

Earlier quoted context omitted.

>Being such a small operation, I think they're making a great decision by focusing on what matters most. Currently, it looks like they are focusing on social networking features: stories, emoji stuff, better link previews. Basically everything that competition already did. The roadmap is not public, so I wouldn't take guesses as what may come next. But... ..."dropping support of X as a feature" is some kind of new tr…

You seem very frustrated personally for the lack of SMS support on Signal. I don't agree with your take or arguments, and you seem to keep branching off pejorative comments on their organization and product instead of actually discussing the points. I think the conversation would be more productive if we focus on the same point, i.e.: * Focusing on what matters most is a good idea, as nobody serious about secure mess…

I'm not frustrated personally, but I know a lot of people who lost their faith in what the organization does.

No one is branching off, but a pretext that your personal take on things must comply with some sort of argumentation protocol that is the only valid blueprint for discussion isn't convincing. Moreover you've managed to somehow unwrap you single comment into a fully fledged dialog while ignoring that their roadmap (the big picture) is not exposed to the public. Given we can only judge isolated decisions, they seem what they are — rather not aligned with the expectations of the userbase.

Personally, I see a pattern of Signal making news in rather negative connotation rather than positive lately.

When it got traction, I felt like it's a new day and the future is bright. But since then, they went with a series of rather ambiguous decisions that sidetracked from previous claims.

EOS for SMS is again one of controversial decisions, I mean, we're in a thread started by a person that went above to clarify reasoning behind the press release. And before it was a year of server side repos without any commits, and then the public got a feature no one asked for — MobileCoin integration. And echoes of intent about it are still heard across the table.

Post reply on HN