Live data from Hacker News

Signal Introduces Stories

signal.org

391–400 of 480 posts

Re: Signal Introduces Stories

#391
post #223

I was worried about sharing broadly and leaking info from 1 contact to another, but it seems like the Signal team did all the right things here. When you create a story you can make it a group story or not. If you do not make it a group story, reactions and replies to stories get sent to you over your 1:1 chats and not shared across other recipients of the story. If you make it a group story, and share it with multip…

I'm still of the opinion that encrypted private group chats are an impossible UX problem (1:1 chat is fine). But if I were to trust anyone to find a way to do it properly, it would be Signal.

Any "secure" encrypted messenger that allows more than 1 to 1 connections will always have the potential for the "ghost user" problem.

System level some use additional connections/recipients for spam/moderation and the moment you allow any invisible/visible group users in, there is a massive potential for an exploit.

Additionally you have the potential for forking off messaging to other users at the system level for either oversight or spam/moderation/other. Some of the compromised systems out there use this very well.

A sneaky way some of these "secure" messaging apps are also doing this is ghost participants in the chat that can essentially syphon off the messages even without a compromised client. The ghost participant is always under the guise of moderation or anti-spam or telemetry or some other proprietary shim.

> The code shows that the messages were secretly duplicated and sent to a “ghost” contact that was hidden from the users’ contact lists. [1]

Lots of "secure" messaging apps do this for intel and surveillance and not just the white hats.

Other areas that "secure" messaging apps have holes in is the anti-spam/moderation systems that need to view messages and in the clients themselves who have access to the unencrypted content. This is also taking place in other client apps as well: VPN, password managers, extensions, wallets, even build systems and more. Many like VPNs have logs sent elsewhere but deleted locally -- access to entire machine and all network access. People are way too trusting of "secure" systems/apps that are very common today based on trust.

All of these apps/systems would pass code checks, reviews, security inspections and essentially be encrypted/"secure" though a copy is sent off to another area for review. At runtime the leak is in the direction of the data.

Then you also have governmental oversight that opens up holes that can be exploited.

On Ghost Users and Messaging Backdoors [2]

> to add a “ghost user” (or in some cases, a “ghost device”) to an existing group chat or calling session. In systems where group membership can be modified by the provider infrastructure, this could mostly be done via changes to the server-side components of the provider’s system.

> I say that it could mostly be done server-side, because there’s a wrinkle. Even if you modify the provider infrastructure to add unauthorized users to a conversation, most existing E2E systems do notify users when a new participant (or device) joins a conversation. Generally speaking, having a stranger wander into your conversation is a great way to notify criminals that the game’s afoot or what have you, so you’ll absolutely want to block this warning.

> While the GCHQ proposal doesn’t go into great detail, it seems to follow that any workable proposal will require providers to suppress those warning messages at the target’s device. This means the proposal will also require changes to the client application as well as the server-side infrastructure.

> (Certain apps like Signal are already somewhat hardened against these changes, because group chat setup is handled in an end-to-end encrypted/authenticated fashion by clients. This prevents the server from inserting new users without the collaboration of at least one group participant. At the moment, however, both WhatsApp and iMessage seem vulnerable to GCHQ’s proposed approach.)

[1] https://www.vice.com/en/article/v7veg8/anom-app-source-code-...

[2] https://blog.cryptographyengineering.com/2018/12/17/on-ghost...

Re: Signal Introduces Stories

#393

Earlier quoted context omitted.

'Stories' were made popular by Snapchat in 2013, and they became the most-frequently used part of the app. They're a good way to give life status updates to a lot of friends at once, and provides a good conversation starter. This revives friendships and keeps communications going. From my experience, they are a non-optional part of socializing. By my estimation, my social and professional networking has materially su…

> From my experience, they are a non-optional part of socializing I must not have much of a social life then, since I've apparently managed to go 9 years without having anything to do with them. Maybe I'm just getting old.

Rather being hooked on social media, I believe. I never seen this feature as useful or interesting at all anywhere and I'm in mid 30s. My friends who are either bit younger or slightly older and who are still sitting on fb for whatever reasons or ig appear to be using stories - at least that's what I've seen last time I've check facebook.

Re: Signal Introduces Stories

#394

Earlier quoted context omitted.

Making people juggle a different app for SMS is the opposite of being mainstream friendly.

I was only able to convince family to use Signal because they didn't need two apps for messaging. It's pretty much a dead app for me now and the decision makes my conversations profoundly less private and safe.

Did all of your family members only message you and not each other? I don't understand why they would move away from signal when they were messaging each other using signal. Each one would have several signal contacts.

Did they not see any value in signal over SMS? Didn't you have any group chats?

Re: Signal Introduces Stories

#395

Earlier quoted context omitted.

My family members will basically all stop using Signal now because they didn't want two apps for messaging. This will make all my conversations less private rather than more. It was a really dumb decision. I was able to convince a lot of people to switch because "it's just text and voice messaging except if we both have the app then it's more secure." I will basically be alone in my usage of Signal after the change g…

Same. Only now I will be "forced" to ditch Signal as well, for the exact same reason. And I'm an uber-paranoid privacy nut who uses GrapheneOS on my phone. Thing is, I have all of 2 close contacts who use Signal. The rest use the default messaging app on their phone. So I already had to accept the fact that most of my texts were non-encrypted while I continued to try to persuade people to install Signal. Which was ea…

Are you short of space on your phone? As a "uber-paranoid privacy nut" why wouldn't you keep it installed and continue to message those two contacts securely?

Re: Signal Introduces Stories

#396
post #352

Earlier quoted context omitted.

Assuming everyone you know isn't already using Signal, I think the most important "feature" for any existing Signal user is getting more users on there. As far as I can tell, lots of people love stories.

A lot of people love SMS too.

No one on this site should love SMS. It's just a huge security vulnerability and while it sucks having to reactivate the built-in SMS app I totally get their reasoning behind it. Having SMS integrated into Signal was damaging their reputation for something they could never have any control over, so why support it? Any business trying to stay alive would repeat their decision on this.

Re: Signal Introduces Stories

#397
post #209
post #155

Earlier quoted context omitted.

They recently announced they are removing Sms support on Android which feels vastly more useful for the non-tech crowd.

They kinda were forced to by Android limiting what they can do: https://community.signalusers.org/t/signal-blog-removing-sms...

There is (sometimes?) a way for Signal users to deregister from RCS which should presumably cause other devices to send messages via SMS instead of RCS.

People's Android devices can be opt in to receive messages via RCS based on phone number with either Google or their carrier. If the number is registered via Google, the number can be deregistered using a form. [1] For Verizon, it seems you can call Customer Support at 800-922-0204 to disable RCS. [2] Presumably other carriers have similar options.

Once RCS is disabled at Google/carrier level at the phone number level, other RCS compatible phones will fall back to SMS/MMS for delivering messages, which will cause the Signal app to be able to read messages via Android SMS APIs.

Seems like quite the hassle to set up an SMS app.

[1]: https://9to5google.com/2020/06/19/google-messages-disable-rc...

[2]: "How do I turn off Advanced Messaging" https://www.verizon.com/support/advanced-messaging-faqs/

Re: Signal Introduces Stories

#398
post #363

Earlier quoted context omitted.

Both tor and signal are funded By one or another branch of the American intelligence community. If you want more info i recommend googling "signal radio free Asia" It's original function was to allow CIA agents posing as reporters for the CIA mouthpiece called Radio Free Asia to be able to report their discoveries. I use the app but in many ways we are actually providing cover for the military and state intelligence…

> If you want more info i recommend googling "signal radio free Asia" Could you provide a link? All I can find with DDG is a reddit post and irrelevant stuff and I don't feel like using Google. > tor which is openly a project of naval intelligence Again, do you have a source? That's the first time I encounter these claims.

https://en.wikipedia.org/wiki/Tor_(network) in the first paragraph of History.

Re: Signal Introduces Stories

#399

Earlier quoted context omitted.

I really hope they change course, and keep SMS. That is the single best feature of the android App. They will lose a lot of people if they don't.

I imagine it's a lot of hassle to maintain and outside of the US SMS is basically as dead as landline phones. They probably consulted their usage statistics when they made that decision.

Why do people keep spreading these lies about SMS being dead outside the US?
Post reply on HN