Live data from Hacker News

Improving first impressions on Signal

signal.org

11–20 of 100 posts

Re: Improving first impressions on Signal

#11

Signal was superb for a long time, and then received a hefty chunk of funding, and, although I may be wrong, has declined since then, and in fact jumped the shark about a year ago. They attempted ever more forcefully to make users to set a PIN to protect server-side state; it started with a dialog at the bottom of the screen, obscuring about 20% of the user list, which could not be dimissed, and then after a few week…

Correct me if I'm wrong, but I believe your comment is misguided.

The PIN is a security option that prevents a SIM-swapping attacker from registering a new device under your phone number unless they know the PIN. You can opt out of it (and it might be opt-in to begin with). You can also easily opt out of PIN reminders. Both of these options are in Settings -> Account.

As for server state - my understanding is that Signal attempts to be zero-knowledge overall, but they definitely store some state on the server. I believe it's encrypted using your private key that's not backed up to the server. Setting the PIN does not change that.

Server state comment aside, it seems your main complaint is about a pop-up PIN entry UI that can be opted out of? I get that it might seem annoying, but it feels like a fairly weak criticism of a messaging platform, certainly not one that should warrant an impression that Signal is "on the way out"?

Re: Improving first impressions on Signal

#12
post #11

Signal was superb for a long time, and then received a hefty chunk of funding, and, although I may be wrong, has declined since then, and in fact jumped the shark about a year ago. They attempted ever more forcefully to make users to set a PIN to protect server-side state; it started with a dialog at the bottom of the screen, obscuring about 20% of the user list, which could not be dimissed, and then after a few week…

Correct me if I'm wrong, but I believe your comment is misguided. The PIN is a security option that prevents a SIM-swapping attacker from registering a new device under your phone number unless they know the PIN. You can opt out of it (and it might be opt-in to begin with). You can also easily opt out of PIN reminders. Both of these options are in Settings -> Account. As for server state - my understanding is that Si…

My complaint with them is the whole thing with mobilecoin. They hid that integration for a year, by not pushing server updates and when the news hit, they promised to do an AMA explaining it all. Its been months since that has happened and the AMA never happened.

Moxies involvement is very muddy and never clarified, it was a pump n dump at best.https://amycastor.com/2021/04/07/signal-adopts-mobilecoin-a-...

That incident, they lost a lot of respect for me.

Re: Improving first impressions on Signal

#13
post #11

Signal was superb for a long time, and then received a hefty chunk of funding, and, although I may be wrong, has declined since then, and in fact jumped the shark about a year ago. They attempted ever more forcefully to make users to set a PIN to protect server-side state; it started with a dialog at the bottom of the screen, obscuring about 20% of the user list, which could not be dimissed, and then after a few week…

Correct me if I'm wrong, but I believe your comment is misguided. The PIN is a security option that prevents a SIM-swapping attacker from registering a new device under your phone number unless they know the PIN. You can opt out of it (and it might be opt-in to begin with). You can also easily opt out of PIN reminders. Both of these options are in Settings -> Account. As for server state - my understanding is that Si…

I think we may be talking about different PINs.

I am not talking about the PIN you would have to enter when starting Signal, to get into Signal.

I Googled a bit and found an approachable blog post from the time this all happened, here;

https://blog.cryptographyengineering.com/2020/07/10/a-few-th...

This has refreshed my memory of events.

In short, Signal wanted to store what had been purely client-side information (contact lists, for example) on their server, but - in principle at least - in a form Signal could not access.

The PIN in question is used to provide access to that information.

> Server state comment aside, it seems your main complaint is about a pop-up PIN entry UI that can be opted out of?

The dialog to force the user to set the server-side PIN disabled the app. You either had to do it, or stop using Signal. There was no opt-out.

I had a look at the app now. I found the settings you mentioned. It's not clear to me from what I see there is this if an app-locking PIN, a SIM protection PIN, or a server-side state PIN, or all three rolled into one.

In any event, at the time it happened, the presented dialog was full-screen and could not be dimissed; even if there had been options to disable this (and there were not prior to the full-screen dialog - I looked, in an effort to dismiss the permanent partial-screen dialog) you could not get to them, because it was a full-screen dialog which you could not dismiss; you could not get to the app, and so could not get to settings.

The only option was to stop using Signal or provide a PIN so your client-side state could be stored server-side.

Re: Improving first impressions on Signal

#14
Great, but...

Please let people allow Signal to automatically save their media to their photo roll (or whatever ios calls it). The number of people I have met who require this and left Signal _after starting to use it_ is astonishing.

Re: Improving first impressions on Signal

#15
Edit: I’m out of date for most of this. Way to go Signal team! See comments below my complainy post.

Forcing me to recite my PIN every few weeks is one of the most irritating UX I’ve seen.

I’m sure there’s some smart engineer explanation in terms of cryptography and being unable to recover it if lost. But just let me disable it if I’m okay losing my entire account if I forget it.

Also last time I checked the binding of a phone number to Signal was really bad. I had a friend abandon Signal and I could never sms them ever again.

Re: Improving first impressions on Signal

#16
post #14

Great, but... Please let people allow Signal to automatically save their media to their photo roll (or whatever ios calls it). The number of people I have met who require this and left Signal _after starting to use it_ is astonishing.

Do you think that's really the reason they are abandoning it? I think the bigger issue is probably that most of their friends are not on there and they use it less frequently until they abandon it.

Re: Improving first impressions on Signal

#17
post #11

Earlier quoted context omitted.

Correct me if I'm wrong, but I believe your comment is misguided. The PIN is a security option that prevents a SIM-swapping attacker from registering a new device under your phone number unless they know the PIN. You can opt out of it (and it might be opt-in to begin with). You can also easily opt out of PIN reminders. Both of these options are in Settings -> Account. As for server state - my understanding is that Si…

I think we may be talking about different PINs. I am not talking about the PIN you would have to enter when starting Signal, to get into Signal. I Googled a bit and found an approachable blog post from the time this all happened, here; https://blog.cryptographyengineering.com/2020/07/10/a-few-th... This has refreshed my memory of events. In short, Signal wanted to store what had been purely client-side information (c…

Fair. And I think I know what you're referring to.

Yes, they do upload your contact list, but I believe there's a prompt at setup time that allows you to opt out? It might even be an OS-level prompt to the tune of "Signal would like to access your Contacts". Not 100% sure on that one as I haven't set up a brand new Signal installation in years.

It's done to help their user acquisition. It uploads your contacts to match against other contact lists and let you know who's on Signal. I recall seeing a blog post explaining how they are doing it in a fully encrypted way, possibly using Secure Enclave (? though I think the 2021 version of that would probably involve ZK proofs/homomorphic encryption of some kind, and I hope they put some time into that).

I don't recall ever having to set a PIN specifically for that. And besides, a 4-6 digit PIN would be a terribly insecure way to "encrypt" anything server-side :) But yes, that would be a shame if it were the case.

Re: Improving first impressions on Signal

#18
post #2

Signal's message requests is a major selling point for me. I recently created a Signal account after having a bad experience in which someone used my phone number to harass me with SMS/calls (every time, from a different VOIP number). It's frustrating that, even in this era, there is no good way to filter out malicious actors from SMS/call. P.S. You can sign up with Signal via a VOIP number to avoid sharing your real…

It's complicated and can be expensive. Also people that has you real phone number cannot contact you on Signal, so you have to have two accounts, one with your real number to chat with your contacts and another one with the fake one to share with strangers that you don't trust, and as far as I know the Signal app doesn't support two account (yes on Android there are ways to have two instances of the app, on iOS you can't).

To me Telegram is superior to Signal because it gives you both options, use your phone numbers with people that already have you in the contacts, and don't share your number with strangers in a group.

Re: Improving first impressions on Signal

#19
post #3

Is it strictly-true that anti-spam algorithms must be hidden to be effective? It would seem that initially, spammers would have the upper hand, but in the long run, coordinated and open effort against spammers has the potential to pay off. Furthermore, to have a closed algorithm that cuts off the ability for people to communicate opens the door to institutionalized censorship -- designating a political opponent's com…

Depends how high is your bar for "effective". For example there's nothing secret in rate limiting and IP bans, and these are fundamental techniques.

However, there are plenty of opportunities to catch spammers when they make stupid mistakes. I've worked with web bot spam. I could catch a very popular bot brand by observing that it sent Accept header with content that was implausible for the User-Agent it sent. If the code was public, spammers could see `if (browser == safari && accept != safari-like) { spam }` and fix their header in minutes.

There's also a middle ground where the algorithm is public, but it's powered by secret data: blacklists, databases for classifiers, ML models. From accountability point of view data being secret is as problematic as secret code.

Re: Improving first impressions on Signal

#20
post #14

Great, but... Please let people allow Signal to automatically save their media to their photo roll (or whatever ios calls it). The number of people I have met who require this and left Signal _after starting to use it_ is astonishing.

This surprises me greatly, as it's my biggest annoyance with WhatsApp and Google Hangouts or whatever they call it now (I've not yet accepted the new app, so it still calls itself hangouts, but clearly is using the new chat app backend...)

I despise that it shows up in my main photos whenever someone sends a photo/gif/vid on these apps. Telegram segregates its local storage to a separate folder that Android doesn't seem to grab for the photo-roll and I want it this way; my photoroll should only be __my__ pictures, not random stuff my friends send me.

I talk to different people on different apps in very different ways; the ways I joke with my best friends is absolutely not appropriate for the ways I talk with the older people in my life, and vice versa. And it's absolutely not about me testing these waters; that's not for an App/OS to decide, that's for me to decide, and mixing these photos into one central location makes it more annoying and precarious for me to accidentally tap and share something I never meant to because the App/OS saved it to a central location that it never should have.

I don't even agree with "give people the option"; photocell/gallery/whatever are for __my pictures__. Downloads are for just that; Downloads. Apps should stay away from the pre-defined user space and put it in correctly named locations.

I realize I'm "reeeeee-ing" here, but it's honestly a huge pet peeve of mine to see all the photos from the chat apps I use to keep in touch with a small handful of people dump themselves into a user space that isn't theirs.

Telegram does it right, and apparently Signal does too -- I cannot understand why other chat-apps feel the need to behave otherwise; finding said photos is a matter of a single system call, so it's not like discoverability is a challenge for them. The users __will learn__, it's not hard to summon the file manager even with locked down permissions.

Post reply on HN