Live data from Hacker News

Registration without a phone number on Signal will use zero-knowledge proofs

community.signalusers.org

201–206 of 206 posts

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#202

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

Signal ghosts people or gets very evasive on other questions to. They've also refused to update their privacy police since they started permanently keeping sensitive user data in the cloud. They can only scream "Don't trust us" so loud.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#203

Is Signal still a trusted company in the industry? They are based in the USA.

Nope. They started permanently keeping sensitive user data in the cloud and have reused to update their privacy since.

see: https://web.archive.org/web/20250117232443/https://www.vice....

https://web.archive.org/web/20230519120156/https://community...

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#204
post #154

Is Signal still a trusted company in the industry? They are based in the USA.

Country of origin doesn't tell you much on its own. Linux is American too, and few question its trustworthiness. What matters is the code being open source and auditable, not where the maintainers live.

"Linux" doesn't keep centralized records that the government can get their hands on. The fact is that the government in the US can (and does) march into US companies and demand access to their data. The government will install their devices on the company's network and even take over entire parts of their offices. What your data sits, who has access to it, and what kind of record the local government has of abuses of their authority are very important things to consider. Much more important than if the code is open source.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#205
post #15

I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".

Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there. I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.

A bare minimum for a company that offers private communication services to people like whistleblowers and activities is that they clearly and plainly explain to their users what their risks will be when using the service. Signal fails at this. They outright lie to their users. They've started permanently keeping sensitive user data in the cloud, but they've refused to update their privacy policy to reflect that. Misleading or lying to users about their risks when their lives and/or freedom are on the line is unforgivable and disqualifies Signal as being a service anyone should consider.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#206
post #126

Earlier quoted context omitted.

"Federation freezes the technology" https://signal.org/blog/the-ecosystem-is-moving/

That's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/ In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardiz…

As a former XMPP believer, I will say that the extremely fragmented capability state of the XMPP ecosystem, whatever people may claim, is the exact proof that vindicates Signal's position.
Post reply on HN