Live data from Hacker News

Privacy is priceless, but Signal is expensive

signal.org

341–350 of 965 posts

Re: Privacy is priceless, but Signal is expensive

#341
post #24

Earlier quoted context omitted.

Phone numbers have become the de facto version of "Internet stamps" for identity verification. They are near-ubiquitous on a per-user level, but hard to accumulate without significant cost. (Unlike email addresses.) But the down side is that phone verification tends to be on a per-service level. So, for instance, Signal incurs these costs when they verify their users, and every other service incurs these same costs w…

Phone number verification is used to verify the user's registration intent, so not really.

"Sign in with $Clearinghouse" could bring you to a page that prompts whether you want to share a user ID or the phone number, as required, with that service.

The clearing house verifies you only once, or once a year, instead of every time. If the clearing house were to be a nonprofit, perhaps even set up by Signal themselves to spread costs with similar services, that has to be cheaper.

It also gives users confidence that only a randomized user ID was shared, so it won't be used for cross-service correlation and tracking, if the service didn't actually need your phone number but only some identifier.

Re: Privacy is priceless, but Signal is expensive

#342

Earlier quoted context omitted.

If only someone would release a universal protocol that the app's native messaging apps could utilize to eliminate the need for these 3rd party messaging apps. Oh, right, it's called RCS and Apple refuses to support it.

Literally nobody wants RCS except Google and a handful of HN commenters. It’s so unwanted that Google had to scrap their original plan of making the carriers host the infrastructure and do it themselves, because the carriers didn’t give a shit. (And even Google doesn’t really have any love for RCS, they crawled back to it as a fallback plan with their tail between their legs when their own proprietary lock-in messagi…

> with their tail between their legs when their own proprietary lock-in messaging apps didn’t work out

For what it's worth, they've worked tirelessly to ensure their failure.

Re: Privacy is priceless, but Signal is expensive

#343

Earlier quoted context omitted.

This does not reduce the overall cost, it just shifts it to the clearinghouse. Who pays the clearinghouse so that they can cover their own exorbitant SMS costs?

You miss the crux of it: the second time onward the clearing houses uses email to authenticate the previously-SMS-verified account.

The clearinghouse may not have the user’s most recent email address, which is common amongst non-tech people. My mom and aunts have lost many email addresses this way and forcing them to use an older email would cause many issues.

Re: Privacy is priceless, but Signal is expensive

#344

Ok, have they decoupled my identity from my phone number yet? I mean, to donate to them I'd have to use it. I don't need another WhatsApp.

almost, usernames and phone number privacy are in testing now

That’s only phone number privacy from other users. Registration would still require a phone number, which is what GP seems to be unhappy about.

Re: Privacy is priceless, but Signal is expensive

#345
Does anyone else think that this strategy of growing the userbase with a "free" product and then start panhandling for donations is outright dishonest?

There are tons of smaller XMPP or Matrix providers that didn't get access to millions in funding from these big corporations like Signal did. Who have to run a business in a way that requires paying customers from the start. But now that cash is tight (and after they built a sizable user base) and they can no longer just outspend the competition, suddenly they remind you of TANSTAAFL and are asking you to cough up the cash.

It is the same shitty playbook used by VC-funded companies, except that is now dressed as some virtuous thing of "looked at how much it cost to build all this..." It makes some emotional appeal but it tries to hide from the audience that these costs are solely due to them insisting on controlling everything.

If it is so expensive to run Signal, then open it up to let other people run their own servers instead of trying to control everything. Don't give me this bullshit of "we are a non-profit but we are in the same lane of big tech corporations". You are there because it served you. You can not have it both ways.

Re: Privacy is priceless, but Signal is expensive

#346

Earlier quoted context omitted.

Funny, because that's the reason I can't use Signal - I don't have a phone number.

In case one isn't aware, you can get a $1/month throwaway phone number from Twilio for that purpose.

Aren't these VoIP? Almost every service blocks VoIP numbers for sign ups these days, but perhaps Signal is an exception.

Re: Privacy is priceless, but Signal is expensive

#347

Wish they provided some numbers of actual messages, type etc. per day. Seems like a good game plan would be. 1) Get off the major cloud providers that charge insane egress fees. 2) Remove SMS verification. A simple solution might be the app gives you a code and then you dial in to them and punch in the code to them. Like a reverse voice based authentication. 3) Remove voice and video calling for non donating users. 3…

You can charge for SMS. You send a message to signal, charged at an amount to cover the return message which contains a code.

Re: Privacy is priceless, but Signal is expensive

#348
post #294

Earlier quoted context omitted.

I'd be happy to pay $1/year for signal, and I'd pay $2/year if it were decoupled from my phone number.

If you pay Signal $1/year, they'll realistically see about 60-70 cents of that – and that's only considering payment processor fees. Now add the cost of providing support (it's a paid product now!), payment handling on their end (in a privacy-preserving way, which excludes most common payment methods), and top it off with the immense damage to the network effect by excluding all the users that can't or simply don't w…

You can also charge for a 10 year minimum and get to a higher retained %

You don't need to provide support, even much more expensive consumer services live without a proper one, so being explicit about the fact that you only pay for infrastructure could suffice

Not sure why payment privacy has to be so strict for everyone

The network effect damage is real, but maybe it could be limited with donations :)

Re: Privacy is priceless, but Signal is expensive

#349
post #36

Signal had 40 million active users in 2021 [1]. With 14 million in infra cost, that comes to .35 per user/year. Total expenses are about 33 million, so about .825 per user/year. All in all that seems very reasonable. [1] https://www.businessofapps.com/data/signal-statistics/

Definitely reasonable but the ultra privacy-conscious/paranoid can't easily donate or pay privately.

Sure, but privacy isn't black or white. A donation to signal does not compromise the content of your messaging.

So what you've leaked is the information that you have an interest in private conversations. This might be a problem in some countries, but I think it's fair to ask folks in affluent countries with working (sorta) democracies to shoulder that burden. I.e. you don't donate if there's elevated threat to your safety, there are enough people who aren't under elevated threat.

There's also the possibility of using a donation mixer like Silent Donor, though I'd evaluate that very carefully. (There's a record of the transfer in, and the mixer needs to keep temporary records for transferring out. There's also the question how you verify the mixer doesn't skim.)

Some donation mixers accept crypto currency, so for maximum paranoia, I suppose crypto->crypto mixer->donation mixer->charity might be workable. Or hand cash to a friend who donates in your stead.

As always, the best path is to set aside paranoia and build a threat model instead to see what the actual risks are.

Re: Privacy is priceless, but Signal is expensive

#350

Earlier quoted context omitted.

You miss the crux of it: the second time onward the clearing houses uses email to authenticate the previously-SMS-verified account.

The clearinghouse may not have the user’s most recent email address, which is common amongst non-tech people. My mom and aunts have lost many email addresses this way and forcing them to use an older email would cause many issues.

The app has to ask for email/phone to begin with (see step 1), if the email doesn't match then phone would be used as fallback, or potentially as a "Didn't Receive Code?" gesture.
Post reply on HN