Live data from Hacker News

Privacy is priceless, but Signal is expensive

signal.org

461–470 of 965 posts

Re: Privacy is priceless, but Signal is expensive

#461
post #410

Earlier quoted context omitted.

Wikipedia is particularly insulting because they make enough money to cover the actual costs of running Wikipedia (the site) in days if not hours, and could operate for years without any additional donations: https://news.ycombinator.com/item?id=32840097

Is that including staff + trying to do new stuff or just the servers.

Why should Wikipedia do new stuff? Or rather, why is it okay for Wikipedia to lie to people to get funding for their new pet projects?

Re: Privacy is priceless, but Signal is expensive

#463

Earlier quoted context omitted.

> stubbornly use iMessange. Personally, I prefer it over downloading yet another client, dealing with additional credentials, wondering about who can access my messages, and so on and so forth… And all that just to message the handful of people that I know who use .

If only someone would release a universal protocol that the app's native messaging apps could utilize to eliminate the need for these 3rd party messaging apps. Oh, right, it's called RCS and Apple refuses to support it.

RCS the “universal protocol” is not end to end encrypted.

Google has made some proprietary extensions to RCS to support end to end encryption but this is not the same thing.

Re: Privacy is priceless, but Signal is expensive

#464

Wish they provided some numbers of actual messages, type etc. per day. Seems like a good game plan would be. 1) Get off the major cloud providers that charge insane egress fees. 2) Remove SMS verification. A simple solution might be the app gives you a code and then you dial in to them and punch in the code to them. Like a reverse voice based authentication. 3) Remove voice and video calling for non donating users. 3…

Removing essential features like voice/video calling for non-paying users would be a terrible choice IMHO. This is a communication app, which means it is only useful if others use it too.

And how are you going to convince others to pay for Signal when there are many free alternatives, including WhatsApp, which most people already have and while not as privacy focused as Signal, does have end-to-end encryption. If Signal makes people pay for voice calls, they will simply use WhatsApp, regular phone calls, or whatever is free and popular at the moment.

The success of Signal came from being very low friction, privacy is the "nice to have" feature, at least for most users. But add friction and they will look elsewhere, Signal is not WhatsApp, it doesn't have enough of a critical mass to keep users on its network.

All that will remain will be a small core of cypherpunks and people who really have something to hide. This is bad because one strength of Signal is that it is a mainstream app, making it hard to single out "interesting" people compared to those who just use it because their geek friend told them to and they like the shade of blue.

Re: Privacy is priceless, but Signal is expensive

#466

Earlier quoted context omitted.

> stubbornly use iMessange. Personally, I prefer it over downloading yet another client, dealing with additional credentials, wondering about who can access my messages, and so on and so forth… And all that just to message the handful of people that I know who use .

If only someone would release a universal protocol that the app's native messaging apps could utilize to eliminate the need for these 3rd party messaging apps. Oh, right, it's called RCS and Apple refuses to support it.

Apple announced today they are going to support RCS https://9to5mac.com/2023/11/16/apple-rcs-coming-to-iphone/

RCS is better than SMS no doubt but lets not pretend it is on the same level as iMessage. Lack of end to end encryption alone makes RCS a dated standard

Re: Privacy is priceless, but Signal is expensive

#467

Earlier quoted context omitted.

Can I operate my own Signal server and talk with people on the "main" one?

You're moving the goal post from "self-sovereignty" to supports federation with an infinite number of servers. Nothing is stopping you from compiling your own Signal server and modifying a Signal client to use your server. Given that Signal is free as a service, supporting federation only increases their expenses.

Without federation, Signal is still working with the advantage of network effects. So an open source server is not enough of a way out.

Element can do it for their Matrix servers. Process.one can do it for ejabberd. Prosody as well. Why can't Signal?

Re: Privacy is priceless, but Signal is expensive

#468

Earlier quoted context omitted.

Afaik you can crrate an account without a number.

No. You can just hide it from other users in group chats now (and perhaps 1:1, didn't yet check but you still need one to sign up)

Where is the option for group chats please?

Re: Privacy is priceless, but Signal is expensive

#470

Wish they provided some numbers of actual messages, type etc. per day. Seems like a good game plan would be. 1) Get off the major cloud providers that charge insane egress fees. 2) Remove SMS verification. A simple solution might be the app gives you a code and then you dial in to them and punch in the code to them. Like a reverse voice based authentication. 3) Remove voice and video calling for non donating users. 3…

About the SMS verification, it depends on the goal. If the goal is to verify a phone number, you can't trust the _sender's_ address in the phone network. So, you can't trust the address in the "From" on an SMS or the "From" of a phone call. That means a voice call to Signal would not work to validate phone numbers.

Good point, I guess we are proving why the resorted to using numbers in the first place. Unless you have a verification point that includes a "charge". Indirect or direct, your platform gets flooded with spam/bots. Does anyone have ideas of how this problem can be solved while also preserving privacy?

Problem: A system that enforces a monetary penalty to prevent sign up abuse while also not tying a users identity to said system.

Without doing some pain in the a crypto stuff it seems like there are no easy solutions other than the #

Post reply on HN