Live data from Hacker News

Registration without a phone number on Signal will use zero-knowledge proofs

community.signalusers.org

121–130 of 208 posts

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#121
post #2

Signal still uses proprietary blob and uses google/apple service for notifications. Use molly.im instead which has solved these problems.

Can you point where Signal uses proprietary blobs? Also, I'm using Signal without the play services notifications just fine. Notifications that don't contain any message content while transiting anyway. The display of the notification was the issue with iOS bug and that would have affected molly as well (if it was on iOS).

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#122
post #99

Earlier quoted context omitted.

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims abou…

Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

https://matrix.org is used by public agents of France's central administration, Germany's national healthcare system, Germany's armed forces, the Swedish Social Insurance Agency and more: https://en.wikipedia.org/wiki/Matrix_messaging

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#123
post #25

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

I’m not sure their tax status is the justification your argument needs.

It's just an additional argument.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#124
post #99

Earlier quoted context omitted.

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims abou…

Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

Realistically nothing is ever perfect, but XMPP comes very close. You've got Signal-introduced double-ratchet encryption if forward secrecy is your jam (so it's as "E2E-secure" in practical terms) and you've got a healthy ecosystem of independent client and server implementers, and service providers to choose from.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#125
post #97

Earlier quoted context omitted.

Ugh wtf so I need a Google account on Android? That's not going to happen. For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet. Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

> Just allow monero payments or something. This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.

Wouldn't a payment of about $0.05 do the trick? My understanding of most kinds of spam is that it relies on being able to deploy hundreds of thousands of bot accounts just to get a few hits.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#126
post #99

Earlier quoted context omitted.

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims abou…

"Federation freezes the technology" https://signal.org/blog/the-ecosystem-is-moving/

That's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/

In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardize and document, 3- I reserve the right to change the deal for whatever reason if I ever feel the need" which is not a good look

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#127
post #28

Earlier quoted context omitted.

You can already do that without being a trusted device.

For the longest time, you couldn't. It wasn't until this release I realised that had changed. If it changed before, it wasn't well communicated to me as an Android signal user. I was on beeper and then molly precisely because there was so little traction on changing this. You could install signal fine, but you couldn't QR code or secret phrase mesh it with your android handset. Oddly, iPad meshed fine with iPhone or…

Definitely under 18 months.

If I’m not fully mistaken, I checked for the combination of iPhone as main device/Android tablet as iPad-like second device sometime in the past six months, at most since the beginning of the year, and it wasn’t possible (unlike phone + iPad as tablet, which seemed quite strange to me).

In any case, it’s a recently released change.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#129

Earlier quoted context omitted.

> And yes, using a VPN will get you knocked up as well. Well, damn.

For reference: In Britain, and presumably India: "get you knocked up" = "get your door knocked on". In the US: "get you knocked up" = "get you pregnant".

In Britain it means get you pregnant too.

Source : I'm British

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#130
post #120

Earlier quoted context omitted.

'Apple' was a metaphor to Newton. 'Open'AI was meant as a promise; one that they've since broke both to some of their founders as well to the general populace. Reminding people of that broken promise doesn't seem that wild.

> 'Apple' was a metaphor to Newton “Apple” was a non-intimidating name that would appear early in the phone book. It had nothing to do with Newton, that logo came after the name. https://en.wikipedia.org/wiki/History_of_Apple_Inc . > According to Wozniak, Jobs proposed the name “Apple Computer” when he had just come back from Robert Friedland's All-One Farm in Oregon. Jobs told Walter Isaacson that he was "on one of…

Either way, it wasn't intended to be a promise to the public to be held to the same way as OpenAI's name was.
Post reply on HN