Live data from Hacker News

Privacy is priceless, but Signal is expensive

signal.org

591–600 of 965 posts

Re: Privacy is priceless, but Signal is expensive

#591
post #585

Earlier quoted context omitted.

Would invites be a solution? Anyone can sign up if they provide a number, otherwise you need an invite from someone with a number linked. It would clump the identity/legitimacy for all invitees into origin number, but still allow disparate accounts.

It’s not about legitimacy but having a bootstrapped contact list to talk to along with other user friction reasons

In that case it doesn't make sense to make it required.

Sure, I don't mind if they ask for my phone number if they think that's a better default onboarding flow, but allow users to bypass it.

With all that said, I don't think it's really only about user friction.

Re: Privacy is priceless, but Signal is expensive

#592

Earlier quoted context omitted.

Can I operate my own Signal server and talk with people on the "main" one?

Federation can only make security worse and I do not want it. You can have something else.

Genuine question: Does Tor fall under the definition of federation? Either way, a Tor-like model would have security benefits over a centralized system like Signal, right?

Re: Privacy is priceless, but Signal is expensive

#593
post #489
post #456

Earlier quoted context omitted.

Phone numbers can be obtained anonymously in many countries. I have several anonymous Signal accounts, each with their own anonymous phone number.

It's possible in the US, but it's getting very difficult. I don't know anywhere you can buy or or borrow a DID with Monero anymore. Looks like they got to Telnum recently. You can still buy a SIM, a prepaid PIN, and a phone with cash, but you'd need to pay a non-correlated person to be seen on CCTV to do it, at a non-correlated time, and hope they don't just take your money and leave you nothing at the dead drop. The…

Why would you not need to be seen on CCTV? This has nothing to do with the privacy of Signal.

I buy all of my anonymous prepaid SIMs with cash at retail myself, and they are still anonymous.

The only time you’d need to stay off CCTV is if you were using them to commit crimes and expected a significant investigation to be undertaken.

Your casual assertion of malice on the part of Signal is not supported by any facts.

Re: Privacy is priceless, but Signal is expensive

#594

Personally, I refuse to financially support Signal so long as they're still holding my chat logs hostage on my old iPhone and seem not at all concerned about solving this problem, which has existed for years. There was (and still is, so far as I know) no upfront warning to users that if they don't first sync with a desktop client, and their phone gets lost or stolen, their iTunes backups do not (unlike most iPhone ap…

> It is absolutely unacceptable to have our own data held hostage by them

Most likely this is just one of the walls of the walled garden.

Re: Privacy is priceless, but Signal is expensive

#595

Earlier quoted context omitted.

A cashier's check doesn't.

Ah ok I didn't know those still existed. In fact even the named checks are long gone here in Europe lol.

Oh yeah, I have an old checkbook that I've had since like 2010 because the only ones I've ever used are for random landlords. Otherwise it's literally easier to get a cashier's check, which you can (in America) do at any bank or grocery store. Note that some are free and some aren't, so check beforehand. I don't think these will ever really go away tbh

Re: Privacy is priceless, but Signal is expensive

#596

Earlier quoted context omitted.

Not even that, because it is linked to phone numbers.

Username registration is currently being tested: https://community.signalusers.org/t/public-username-testing-...

> and register for a new account with a phone number (you can use the same one you’re using in Production).

I hope that they make it so you can register WITHOUT a phone number. Perfectly fine if it's not the default. This is post is currently implying that is not currently the case.

Re: Privacy is priceless, but Signal is expensive

#597

Personally, I refuse to financially support Signal so long as they're still holding my chat logs hostage on my old iPhone and seem not at all concerned about solving this problem, which has existed for years. There was (and still is, so far as I know) no upfront warning to users that if they don't first sync with a desktop client, and their phone gets lost or stolen, their iTunes backups do not (unlike most iPhone ap…

I completely agree with you, even though the situation is at least a tad better on the Android side... However, it's worth noting that Signal seems to consider this a feature and not a bug.

I hate that. I use signal to chat with my friends. We trade pictures of our cats. I am not a whistleblower who needs my data deleted instantly for safety. I provide the noise that acts as cover for those people. And I would have a LOT easier time bringing onto the network if they were able to keep that chat history. (I take a backup on Android and export it and clean my Signal install periodically because it gets large and starts taking up too much space on my device.)

I love Signal. I want it to succeed. I think they have a little bit of problem understanding who their users actually are though, or perhaps just a disconnect with telling us who the users they want to have are...

Re: Privacy is priceless, but Signal is expensive

#598

Earlier quoted context omitted.

Perhaps it was a bad choice of words. What I mean is that they say "you don't need to trust us", yet they require you to run through them. They refuse to build their system in a decentralized way, and the more that time goes by the more the decentralized alternatives are showing they are as secure as Signal without forcing us to accept their restrictions like mandatory use of phone numbers for authentication.

> "you don't need to trust us" you literally don't. It's a fully encrypted service. The literal purpose of encryption is to move data securely through insecure or even adversarial channels . Which you can verify, it's audited and open source. They refuse to build the app in a decentralized way because decentralization is an ideological obsession that is useless in this context, and because centralized organizations c…

Centralized supply chain, and metadata protection is anchored on SGX.

They can use their pick of SGX exploits to undermine the weak metadata protections and they (or apple/google) could, if pressured, ship tweaked versions of their centrally compiled apps to select targets that use "42" as the random number generator. No one would be the wiser.

Signal is a money pit with a pile of single points of failure for no reason.

Matrix is already proving federated end to end encryption can scale, particularly when users are free to pay for hosting their own servers as they like, which can also generate income.

Re: Privacy is priceless, but Signal is expensive

#599

Earlier quoted context omitted.

Perhaps Signal is not the right choice for you? It seems odd to be so concerned about data retention from a system which prominently features support for disappearing messages!

I expect messages to disappear when I turn on disappearing messages and not when I don’t turn them on. But yes, I agree it’s not the right choice for me and many others who want to have full ownership over our data, and they should make that clear in advance.

> But yes, I agree it’s not the right choice for me and many others who want to have full ownership over our data,

The whole point of Signal is you have full ownership of your data. You said you can transfer the data to another device, right? I get that inability to export cleanly is an annoying bug, but technically you have full control over your data the whole time. It seems to me that it's easier to guarantee no one else can get your data (at the expense of data export friction), than it is to provide "do anything you might want with your data" while still guaranteeing privacy.

Re: Privacy is priceless, but Signal is expensive

#600

You have to appreciate the complete transparency, gently nudging towards giving without ever begging for it. Refreshing compared to the alternative that Wikipedia is showing, with the tantrum-like emails we receive from their CEO like "LAST REMINDER" or "We've had enough" ; which they ironically send to people who gave.

Those are just non-profit fundraiser consulting tactics. Don't take them personally, just ignore them. The reason they exist is that Wikipedia has too much money, so they spend some on consultants who say they can raise more. It's weird, but that's how the world works. I would much prefer the Wikipedia endowment model of non-profit orgs. They have a standard operating procedure with a predictable budget, and endowmen…

> Those are just non-profit fundraiser consulting tactics. Don't take them personally, just ignore them. The reason they exist is that Wikipedia has too much money, so they spend some on consultants who say they can raise more. It's weird, but that's how the world works.

It's still shitty, even if it's a shitty "standard practice" and not a shitty thing being done to me particularly.

Honestly, it seems like Wikipedia's goodwill is seen as an exploitable resource, that people in Wikimedia are using to do other, unnecessary things (probably building little personal fiefdoms).

Sort of like Mozilla, actually. IIRC, they literally won't let you give them money to fund Firefox development, and any donations you give them go to fiefdoms almost certainty entirely unrelated to why you gave them money.

Post reply on HN