Live data from Hacker News

Signal Introduces Stories

signal.org

321–330 of 480 posts

Re: Signal Introduces Stories

#321
post #288

Earlier quoted context omitted.

I'm pretty technically inclined and I lose my Signal history every time I get a new phone because I just can't remember to transfer it. (I don't use it a ton.) I really wish this was more seamless. (I understand the complexity of the security issues around it.)

Here's an easy way not to forget (on Android): 1) Enable daily backups in Signal 2) Set up Syncthing to automatically send these backups to your laptop/whatever. 3) Profit.

On iOS, but thanks!

Re: Signal Introduces Stories

#322
post #55

Earlier quoted context omitted.

About once a week I get a notification that random person X I haven't talked to in a decade is now on signal. About two months ago the super at my old apartment building got on signal and I got a notification. My late coworker's phone number finally got recycled and the new person using it is on signal too. They appear to be reaching critical mass. Still really mad about them dropping SMS support. I'll be deleting it…

> About once a week I get a notification that random person X I haven't talked to in a decade is now on signal. Settings > Notifications > Notify when... > turn off "Contact joins Signal"

That let's me turn off annoying notifications from other people. Guess what, it doesn't help someone who would prefer not to advertise their adoption of Signal to everyone who ever had their contact details.

Really, is it so hard to think about both sides of this equation?

Re: Signal Introduces Stories

#323

Signal has done a lot of nice work on building a UI that conveys what nerds/paranoid people want to know for private messaging (e.g. "Your safety numbers with so-and-so have changed") while still providing a usable app. But for the most part, the threat model of "private messaging" is one that software can defend against pretty well; everybody understands that when Signal provides "privacy," they don't mean in the fa…

> Or does everybody already understand that auto-deletion is best-effort and shouldn't be treated as on par with the strength of assurance that Signal provides for privacy?

No, but this is what we should teach. Even "best effort" is misleading. Auto-deletion should be considered a UX feature that only affects your own experience, not those you talk to.

That said, in a high trust relation you can assume that auto-deletion is best effort, same as with your own devices. It should be seen as "this is a hint that helps your peer to delete messages, so that they don't stick around for everyone's sake".

Re: Signal Introduces Stories

#324
post #69

Earlier quoted context omitted.

same. unless Signal has public metrics to suggest its reached a real critical mass, the lack of basic SMS functionality kills the app for me.

> same. unless Signal has public metrics to suggest its reached a real critical mass, the lack of basic SMS functionality kills the app for me. Did its SMS feature support encryption somehow? Because sounds like a bad idea to include unencrypted messaging in a secure app: it's a giant footgun.

But isn't, because there's a giant icon that clearly Signals it and it pops up a warning the first time you send a message to someone new over SMS, every time. In over 5 years of using Signal, I have never sent an SMS message in the mistaken belief that it was secure, and I typically get hundreds of incoming messages per day and typically send out 100 or so.

'We're taking features away for your security' is a lowkey way of telling users that they're idiots who can't be trusted to operate their own devices. This is really pretty offensive to the people who have been evangelists for Signal for the last 6-7 years.

Re: Signal Introduces Stories

#325
post #164
post #77

Earlier quoted context omitted.

It means I need an extra app now. Signal replaced my SMS app. I'm not going to stop using SMS completely, so if Signal drops it I need to use one more app.

One comes preinstalled with every major mobile OS...

And one that I have been able to happily ignore for years because Signal handled all my messages. If you are not a long-time Signal user then maybe you don't remember how they made a big song and dance out of offering this feature in the first place to make Signal more usable and accessible.

Re: Signal Introduces Stories

#326

Earlier quoted context omitted.

I don't know about other platforms, but Signal on Android supports backing up to a file, as well as direct transfer of data to another phone.

It supports backing up to a file that you can't specify. This is unhelpful in many use cases. Example: I am running out of space on my phone. I look, and see Signal is taking 4gb of space. But I would like to preserve a lot of that media. So I buy a mini-SD card and install it in my phone. Yay! Now to turn on Signal chat backups! Oh, but the backups are hardcoded to a location on your primary storage that you can't c…

Even a cynic like me wouldn't go so far as to assume bad intent here. Signal is open source so the file format should be readable and likely this is just an oversight, I guess it's not a highly requested feature. Have you filed an issue?

Re: Signal Introduces Stories

#327

Signal has demonstrated product-death (loss of cohesive product vision), what do we use next?

Session seems OK. I sort of like the look of Matrix but it's a lot harder to establish a security policy when 10 different people might be using 10 different Matrix clients, and nobody can do technical support for anyone else.

Re: Signal Introduces Stories

#328

Earlier quoted context omitted.

Why use multiple apps to text people? I don't us FB messenger, WhatsApp, Telegram, or any of that. I use Signal. Signal lets me send a message to ANYONE else with a phone number protocol agnostic. That's very useful, especially when I'm talking to committed iMessage users.

I get you but it feels like a weird hill to die on. Questionable why SMS support was added to Signal in the first place but removing it makes sense in the context of where they want to take Signal (e.g. usernames).

> where they want to take Signal (e.g. usernames)

Any day now (for the last 5 years)

Re: Signal Introduces Stories

#329

Earlier quoted context omitted.

Because they haven’t figured out how to do that securely?

Then do it insecurely and warn the user. 'We can't figure out how to do this securely' is their BS excuse for every bad design decision or unimplemented feature. You might say 'but they don't want to make people less secure, people will get the wrong idea!' But they do this already, in ways that are much worse than allowing the user to make a security decision for themselves. You can change a setting to prevent scree…

Your former examples are things that quite simply can’t be mitigated in any case. If you want to send a message to someone there is no way to prevent them from storing it in a way you control.

Your latter example is also a security concern they can’t address. A jurisdiction that allows a message about a settings change being used as a basis for obstruction of justice can rule the use of signal as the same (though I do agree that former is problematic on its face).

I dont know the ins and outs of the problems with backups, but it doesn’t take a phd in cryptography to envision a case where your settings about backups open all your contacts to automated dragnet surveillance. In that case it doesn’t make sense for a single user to downgrade everyone else’s security settings.

Re: Signal Introduces Stories

#330

Earlier quoted context omitted.

Then do it insecurely and warn the user. 'We can't figure out how to do this securely' is their BS excuse for every bad design decision or unimplemented feature. You might say 'but they don't want to make people less secure, people will get the wrong idea!' But they do this already, in ways that are much worse than allowing the user to make a security decision for themselves. You can change a setting to prevent scree…

Your former examples are things that quite simply can’t be mitigated in any case. If you want to send a message to someone there is no way to prevent them from storing it in a way you control. Your latter example is also a security concern they can’t address. A jurisdiction that allows a message about a settings change being used as a basis for obstruction of justice can rule the use of signal as the same (though I d…

I'm not saying they can be mitigated, I'm saying that casual users have the illusion of security through settings that seem to mitigate security concerns, but don't.

The disappearing message timer history could absolutely be mitigated by simply not retaining that information or timestamping it.

If you could export/back up single conversations, you would have much more granularity than exporting or backing up your entire message database. Other people could also get a message that the conversation had been exported. there are lots of cases where you might want to do this by mutual agreement, but it isn't possible.

Post reply on HN