Live data from Hacker News

Signal Introduces Stories

signal.org

471–480 of 480 posts

Re: Signal Introduces Stories

#471
post #223

Earlier quoted context omitted.

I'm still of the opinion that encrypted private group chats are an impossible UX problem (1:1 chat is fine). But if I were to trust anyone to find a way to do it properly, it would be Signal.

What makes it impossible? Naively I would think that if you have a secure 1:1 communication protocol, then you can send N*(1:1) secure messages to a group of N people. To solve the "fake group message" problem where an adversarial member of the group sends different messages to different members of the group, or delays the message to some members, the protocol could simply allow for a 2nd level "vouch" message to be…

> Naively I would think that if you have a secure 1:1 communication protocol, then you can send N*(1:1) secure messages to a group of N people

IIUC this is what iMessage does (at least when Messages in iCloud or whatever it's called is disabled), except s/people/devices: say you have three devices and someone sends you one message, the message is encrypted once per recipient device, and three encrypted messages get sent. Whether it's 1 person with 3 devices, 3 people each with 1 device, or 2 persons with one having 2 devices and the other a single one becomes largely immaterial.

Re: Signal Introduces Stories

#472
post #106

Earlier quoted context omitted.

I agree i don’t see how you can knock signal in anyway for removing sms. What is the argument that this was some huge misstep i just don’t see it

It's fine if you don't use SMS in the Signal app much. But a lot of us only downloaded Signal because it could replace the built-in Android SMS app. By dropping the SMS feature, we now have to use N+1 apps just to receive the occasional shipping notification or 2FA message. I'm glad that dropping SMS means nothing to you. But "i don't see how you can known signal in anyway" for dropping a feature sounds disingenuous.

I mean thats a slight inconvenience at the cost of not letting people be confused that they are not actually having an encrypted conversation. I still stand by my original statement and don’t understand how people are so mad about that. Sure “it sucks” you need another app now but the comments about this in the threat are treating it like signal is doing something malicious

Re: Signal Introduces Stories

#473

The announcement says “give the people what they want”. You know what I really want in Signal for iOS? Backups, not stories. Congratulations for launching stories, but I honestly don’t understand why it has been prioritized over backups (E2E encrypted of course). That’s a major missing piece to replace WhatsApp and other messaging solutions.

I've lost my entire message history 3 times now in the past 6 years because they don't have backups. iOS -> iOS migration is buggy and prematurely wipes the old device every time.

Stopped recommending Signal because of this. Seeing stories, stickers, and crypto payments prioritized over basic data integrity makes me sad.

Re: Signal Introduces Stories

#474
post #305
post #209

Earlier quoted context omitted.

They kinda were forced to by Android limiting what they can do: https://community.signalusers.org/t/signal-blog-removing-sms...

This post seems say that they'd rather avoid the difficult programming challenges of working with the varied devices and protocols people use for communication generally, and just compete with other walled garden apps instead. I wish them luck, but it's a different trajectory than they were on a year or two ago.

> I wish them luck, but it's a different trajectory than they were on a year or two ago.

MobileCoin which is Signals self printed crypto (think what FTT was to FTX) was released: December 6, 2020

Their trajectory a year or two ago is no different

Re: Signal Introduces Stories

#475

Earlier quoted context omitted.

> Think about it: if Signal didn't know that A was messaging B, how would they route that message to B's phone? There is no need for signal to know because their servers are not involved to transport the message but only ip routing infrastructure in between and of course the two parties. That's P2P

Signal is not P2P. Signal servers relay messages to/from clients.

Thank you, TIL. I really thought their protocol is P2P

Re: Signal Introduces Stories

#476

Earlier quoted context omitted.

>How can there be no RCS API? Eww. Actually, there is an RCS API. However, Google restricts its use to themselves and specific OEMS only . IIUC, that's currently only Samsung[0]. [0] https://www.xda-developers.com/google-messages-rcs-api-third...

Could LineageOS flip a switchand turn it into a free for all? That would be fun and interesting. Not that RCS is a remotely good messaging protocol.

>Could LineageOS flip a switchand turn it into a free for all? That would be fun and interesting. Not that RCS is a remotely good messaging protocol.

IIUC, the RCS API is not part of AOSP[0], and as such, not part of LineageOS. As such, I believe the answer is "no."

[0] https://source.android.com/

Re: Signal Introduces Stories

#477
post #438
post #228

Earlier quoted context omitted.

so many people I've gotten to switch to signal have asked me about them discontinuing SMS support. my family members aren't going to keep using signal just to message a few others, when the majority still use text. still unsure how this decision made it through.

The stance of Signal is insulting to anyone who lobbied to friends and family for them. In addition to making us look like idiots, when they kill the feature it is very likely that we will be called to the rescue, because the Signal archived SMS messages will dissapear. As a growing company, I don't know how they expect to get away by alienating their staunch userbase. Even Meta made concessions when Whatsapp userbas…

They did same when they forced people into PIN code they didn't want with full screen or 1/3 screen unremovable nag message until you created PIN, it took them about week or two before they backpedalled from forcing it without option to opt out, but it was too late for me and my extended family, we all uninstalled this POS app.

Just for fun now I installed it to use as my default SMS app after this whole hullabaloo with SMS removal, I use Johann's fork, so I am just curious how long it will keep working as Signal messenger with no APK expiration. Though I am definitely not telling anyone I am using it, tried to isntall it on wife's phone, never received verifying message or phone call, no matter how much I tried and mind she has the regular phone with almost stock ROM, while I use Lineage with no gapps.

I will ditch it in a second, if there will be other IM with SMS support other than Facebook Messenger and Skype (Lite), ideally some Matrix client with SMS support, that I could promote even to my family.

Re: Signal Introduces Stories

#479
post #150

Earlier quoted context omitted.

https://getsession.org/ * Doesn't require users to provide a phone number. * Doesn't use centralized servers. Hopefully Session will stay legit for a while. Just when I get most of my contacts to use Signal, Signal moves to embed a cryptocurrency in the app and starts pushing Storytime. https://www.stephendiehl.com/blog/signal.html

F-Droid list them as having anti-features "the upstream source code is not entirely free" - how are we supposed to know if it does what it says it does if it's proprietary?

That appears to be because Session uses Firebase as a dependency.

https://github.com/opendocument-app/OpenDocument.droid/issue...

Per F-Droid's definition of "the upstream source code is not entirely free":

https://f-droid.org/en/docs/Anti-Features/#UpstreamNonFree

This seems to be a case of "damned if you do; damned if you don't". Session relies on Firebase to get faster notifications from Google servers. This can be disabled in the applications preferences but changes the behavior from push-notifications to polling Session's decentralized messaging network, which makes messages notifications slower.

https://getsession.org/faq#push-notifications

For the sake of clarity it would be nice if instead of making such a vague pronouncement, F-Droid would specify precisely what about the upstream source code is not entirely free.

https://forum.f-droid.org/t/the-upstream-source-code-is-not-...

Re: Signal Introduces Stories

#480
post #405

Earlier quoted context omitted.

Not sure I understand. My impression was that the end-to-end encryption algorithm was probably the most secure thing about Signal, allowing strong encryption between sender and recipient without relying on trust of the central server. Regardless of where or how it was developed, it's open-source.

99.9% of the algorithms are open source, that is still no reason for them to be trusted since it takes years and years (sometimes decades) until exploits included by design are revealed: https://www.theverge.com/2013/9/11/4718694/how-far-did-the-n... Trivia: What percentage of open source end-to-end encryption algorithms were developed by coincidence next door to the NSA headquarters?

Reading into that article, it looks like the NSA made a random-number generation algorithm standard, but upon inspection by cryptographers it was seen to be suspect due to its unclear origin of particular constants, and this was discovered as soon as the standards were published [0]. It was also slow compared to other standards, and as a result it was never widely adopted.

By contrast, I can't find any significant security criticisms about Signal's double-ratchet algorithm, nor anything that would suggest that some sort of bad actor is pushing it to become standard. It seems to me like it was widely adopted because it's a solid end-to-end encryption algorithm.

I also couldn't find where the algorithm was developed. If you have any sources for this I'd be glad to read it.

[0] https://www.wired.com/2007/11/securitymatters-1115/

Post reply on HN