Live data from Hacker News

Signal Introduces Stories

signal.org

441–450 of 480 posts

Re: Signal Introduces Stories

#441

Earlier quoted context omitted.

I imagine it's a lot of hassle to maintain and outside of the US SMS is basically as dead as landline phones. They probably consulted their usage statistics when they made that decision.

Why? It hasn't changed in years. It's easy to use and glaringly obvious that it's a non-secure conversation. Sometimes I go to add a reaction to an SMS conversation before remembering that those don't work on SMS - the only problem I have ever had with it. > outside the US that's a 330m-person population, which is also home to Signal. Not only do I get SMS from people like neighbors and so that I don't especially wan…

> Why? It hasn't changed in years.

It has though. RCS has come along, which means that you might send an SMS to someone, and their response gets "upgraded" to RCS. If your app doesn't support RCS (and it's impossible to support RCS right now, because the APIs aren't available), you'll never see it.

The choice is between "Keep maintaining the functionality and have people get progressively angrier that their messages are going missing" or "drop it entirely".

Re: Signal Introduces Stories

#442

Earlier quoted context omitted.

Well.. Signal was literally sponsored by the CIA from the beginning. OTF gave Signal 3 million USD: https://www.opentech.fund/results/supported-projects/open-wh... The OTF was created in 2012 as a pilot program of Radio Free Asia (RFA), an asset of US Agency for Global Media (USAGM)/CIA, which is in turn funded by US Congress. The algorithm for signal/whisper was developed next door to the NSA headquarters in Hawaii.…

What are your alternatives? The signal protocol is basically the gold-standard. If the NSA has a backdoor (and yes, they might), I don't know of any other protocols that wouldn't.

[deleted]

Re: Signal Introduces Stories

#443

Earlier quoted context omitted.

Well.. Signal was literally sponsored by the CIA from the beginning. OTF gave Signal 3 million USD: https://www.opentech.fund/results/supported-projects/open-wh... The OTF was created in 2012 as a pilot program of Radio Free Asia (RFA), an asset of US Agency for Global Media (USAGM)/CIA, which is in turn funded by US Congress. The algorithm for signal/whisper was developed next door to the NSA headquarters in Hawaii.…

What are your alternatives? The signal protocol is basically the gold-standard. If the NSA has a backdoor (and yes, they might), I don't know of any other protocols that wouldn't.

"gold-standard", lol. Provide a source for that claim.

So far you have provided zero evidence for your statements and yet demand others for them.

Good approach.

Re: Signal Introduces Stories

#444
post #428
post #326

Earlier quoted context omitted.

Even a cynic like me wouldn't go so far as to assume bad intent here. Signal is open source so the file format should be readable and likely this is just an oversight, I guess it's not a highly requested feature. Have you filed an issue?

Repeatedly refusing to fix this widely reported issue with non-sensical explanations does imply bad intent. In the beginning, it might have been an oversight. Now moxie is just making seriously misleading arguments on behalf of people he doesn't know to make their service worse.

> Repeatedly refusing to fix this widely reported issue with non-sensical explanations

What are you referring to? An option to choose your backup location got added two years ago. It works on Android 10 and above.

https://github.com/signalapp/Signal-Android/commit/ee3d7a9a3...

Re: Signal Introduces Stories

#445
post #428

Earlier quoted context omitted.

Repeatedly refusing to fix this widely reported issue with non-sensical explanations does imply bad intent. In the beginning, it might have been an oversight. Now moxie is just making seriously misleading arguments on behalf of people he doesn't know to make their service worse.

> Repeatedly refusing to fix this widely reported issue with non-sensical explanations What are you referring to? An option to choose your backup location got added two years ago. It works on Android 10 and above. https://github.com/signalapp/Signal-Android/commit/ee3d7a9a3...

Please explain how do I configure Signal for people in my family so they won't lose any message, photo or group membership if their phone falls out of the pocket.

This means:

* Backup must be automatic.

* Backup must be done off device.

* Backup must be common enough that messages aren't lost.

* Restore must be available to person of average technical ability.

* Restore must not require a person to remember typing in a 20+ character pregenerated number they probably lost in last 2 years of having Setup signal.

This is the bar other messaging apps have set.

Re: Signal Introduces Stories

#446
post #429
post #182

Earlier quoted context omitted.

To give a counter example, here in Sweden, SMS&MMS are used quite a lot. Including bidding for housing. And it's not due to a lack of alternatives.

But the same question applies: why? It feels very weird to have both a very good end-to-end encryption (the Signal encrypted messages) and a very bad system (SMS) together in the same app. People should just move away from SMS, it's not like it's hard.

I have no idea (and not living here long enough). But if I had to guess, it could be that cheap/free SMS texting came before cheap/free mobile internet and thus it was already established.

Re: Signal Introduces Stories

#447
post #430

Earlier quoted context omitted.

What I don't understand here (though admittedly I haven't been following the iOS discussions closely) is why backups are possible on Android but not on iOS?

The backups on Android are near useless as well - they expect users to remember and save a massively long string of numbers (that are pre-generated, so they can't even choose a password they remember) and then they only do backup manually and onto device storage where it'll be gone together with everything else on the device if it breaks or dies. Getting that backup off the device is yet another manual process for mo…

That was not my question.

In any case, I actually prefer it the way Signal does because

1) I don't have to sign up for / rely on a cloud provider,

2) if need be, I can decrypt the backup on my own and export it to some other format.

> then they only do backup manually

Wrong. The backup can be done automatically (i.e. every day).

Re: Signal Introduces Stories

#448
Reading the comments here I believe there is one detail that needs to be mentioned. Many seem to uphold the opinion that, while the feature is not for them, they aren't mad about it as they feel it brings Signal closer to the masses and is hence a good thing.

One key aspect to consider, however, is the fact that at the end of the day the feature requires code in order to work. Code can contain flaws. When working in encryption it's usually the less code the better, as it limits the attack surface.

It begs the question, just like with the introduction of their payments feature, whether the additional amount of code, which could realistically introduce new flaws, is justified by the benefit it brings to a platform that's main focus is private, encrypted communication?

To put it differently: Will citizens, dissidents and journalists in authoritarian regimes be benefitting enough from this feature to justify the additional attack surface its code has introduced?

Re: Signal Introduces Stories

#449

Earlier quoted context omitted.

Same. Only now I will be "forced" to ditch Signal as well, for the exact same reason. And I'm an uber-paranoid privacy nut who uses GrapheneOS on my phone. Thing is, I have all of 2 close contacts who use Signal. The rest use the default messaging app on their phone. So I already had to accept the fact that most of my texts were non-encrypted while I continued to try to persuade people to install Signal. Which was ea…

Are you short of space on your phone? As a "uber-paranoid privacy nut" why wouldn't you keep it installed and continue to message those two contacts securely?

1) Both of those contacts are not "uber-paranoid privacy nuts" so they will be dropping Signal too for the same reason.

2) The inconvenience factor. I don't really like smart phones and would live without one if I didn't need one for very specific purposes. Being able to text close family and friends is one of those specific purposes. I have zero interest in having to juggle different text-ing apps for different contacts.

I should also add that I'm way more concerned about

a) spyware that comes pre-installed with phones that sends data to 3rd parties that have bought it

b) malware (I don't install many apps for this reason, and I like to use FOSS software for the same reason)

b) being in control of a device that I own (same reason I use Linux on my desktops and laptops)

I'm less concerned about SMS messages being intercepted, except for things like MFA codes. So of all the "contacts" that I would like to use Signal, it would be situations where the content is security-sensitive, which [unfortunately] currently accounts for virtually 0% of e2e encrypted messages coming into Signal.

Re: Signal Introduces Stories

#450

Earlier quoted context omitted.

Signal's "ongoing linkage to phone numbers" is one of their more powerful security features .

Why is that? Not disagreeing but genuinely curious. One of the issues I face sometimes is wanting to stay in touch with someone I met. I'd like to do that over Signal (I don't use any of the popular social media platforms) but I don't feel comfortable sharing my phone number with them. It would be nice if I could use a unique user handle instead.

It allows Signal to work similarly to the messaging services it replaces without having to keep serverside contact lists. Those contact lists, which practically every other "secure messenger" keeps, are the most valuable metadata the service keeps, in many cases more than the content itself: they're a record of who talks to who. Signal's phone number system means they can keep those contact lists clientside by piggybacking on the device contact list, which is keyed by phone number.
Post reply on HN