Live data from Hacker News

Signal Desktop

whispersystems.org

101–110 of 288 posts

Re: Signal Desktop

#101

Earlier quoted context omitted.

As much as I agree with your overall sentiment, the sad truth is that centralized architectures enable many of the UX affordances that users take for granted today in a modern chat app, many of which are much more difficult, sometimes simply impossible, to implement in a decentralized architecture (think features like automatic contact discovery, offline messaging, etc). Without some of these affordances, a chat app…

What kind of things are impossible?

The two features I mentioned, automatic contact discovery and robust offline messaging, are examples of features that I have concluded to be impossible to build without some degree of centralization (there are probably more, but those two were the only ones I could recall off the top of my head). Though it is certainly possible that I simply haven't put enough thought into it.

Toc's original goal was to be a decentralized messaging app that makes no compromises in terms of UX compared to a centralized messaging app. Toc managed to tackle decentralized cross platform sync, but to this day I still have no idea how to approach automatic contact discovery and robust offline messaging.

Re: Signal Desktop

#102
post #79
post #69

Earlier quoted context omitted.

> go out of your way to use Signal With that mindset we will never get secure communications to the masses but will repeat the PGP dilemma again and again. UX is of utmost importance. We would still be on 99.99% HTTP websites if HTTPS required going out of one's way.

Signal is an order of magnitude easier to use than PGP. It's not even close. The GP was comparing two apps that are actually both very easy to use, one maybe slightly moreso. (That said, PGP isn't THAT hard either.)

I've been actively using PGP for about 2 years with a few friends that all use keybase, but I still don't feel like I really know what I'm doing, or if I'm really doing the right thing. A lot of the terminology and best practices I learned while first setting it up are lost on me now. It still works though! Well, somewhat... since I switched to KDE thunderbird no longer remembers my pgp password. I miss the gnome keyring.

Re: Signal Desktop

#103

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

I just found it unreliably slow. Principles are all good, but if I message my gf saying "see you at the bus stop in 20 minutes" and she doesn't receive the message for 2 hours, that's majorly annoying and it happened so often I had to leave it. The basic functionality isn't fit for purpose, for me.

Re: Signal Desktop

#104
>Don't leave your friends behind, invite them to signup with this unique link. The more friends that join, the further you will advance in line for the beta.

That's annoying.

Re: Signal Desktop

#105
post #32

Why are all these encrypted chat programs (Signal, Telegram, &c.) still centralized and not TOR-style onion-routed?

What about Ring and Tox?

https://tox.chat/

https://ring.cx/

AFAIK both offers p2p communication and discovery. I don't think that they are entirely tor compatible though, maybe if you only use the chat part.

Re: Signal Desktop

#106
post #25

I don't understand why it prompts me to invite other people after putting me in line. Why would I email/tweet my friends to join this service if it isn't even ready for me? Seems rude to bother a friend with joining an internet line just so that I can get a better position in the line. I love signal on android and have been looking forward to this, kind of rubs me the wrong way when I'm put in "line"

The app is still in beta testing. I think this is their way to drum up support. Forces all the die-hards who want in to try and get some people interested. An app like this is only as useful as the number of people who use it.

Invite them to... not use it? That seems like a solid way to turn people off from using a service, not a way get them excited about it.

Re: Signal Desktop

#107
post #61

Earlier quoted context omitted.

The central server in Signal does not have the same role as the Telegram's. If you care first and foremost about UX, use Telegram. If you care first and foremost about the security of your communications, use Signal; go out of your way to use Signal.

Tbh, Signal's UX on Android is pretty good. Is Telegram just better on iOS or am I missing something when you say it has better UX?

Enh. Signal's UX is still not effortless.

For example:

* Does not make it clear it's a point to point mapping (on iOS) right now. I discovered this the hard way.

* Unclear failure modes (see above). It's entirely possible to have messages be silently dropped.

* Texting vs. call methods unclear. I.e. there's a phone icon but no text icon (select name instead).

* Contacts list has some text only, some phone only, some both.

* The whole contacts list arguably needs to be rethought. It only shows others that have installed Signal/RedPhone/Textsecure. There is no easy way to see if someone does NOT have Signal installed and have the functionality to send a link to invite other person to add the app. I think this would help tremendously in the virality of the app.

* There used to be easy ways to invite people to the app within the app, seems to have gone away with only a tweet an invite to app store function remaining.

* There have been several instances when I can't see someone after they install Signal. They have to initiate a message to me in order for the contact to show up in the list.

* Signal has poor handling for contacts with multiple numbers. It's not clear which number is being used and you can't switch selection of numbers.

So what I'm saying is don't necessarily ape what Telegram/WhatsApp etc. is doing but I think Signal would do well to study hard the onboarding workflows of those apps.

Re: Signal Desktop

#108
post #47

Requiring a google email address and chrome for a secure messaging system? Very strange move.

They're using Google groups to manage the beta testing program. Make sense since that's how you sign into the Chrome app store to download the app.

"Make sense since that's how you sign into the Chrome app store to download the app."

I don't think it makes any sense at all.

Even if you do use gmail/google in some places (I don't) it's not a given that you want to tie that identity to this app or these activities.

A throwaway google account is getting very difficult since google automatically flags an account with no mobile phone number attached to it as a "suspicious activity" account, immediately forcing you to add a mobile number.

Google is not the Internet. Their app store is not the Internet. I can't believe that the people I know to be behind this project have tied it to google in such a necessary and intimate way.

Re: Signal Desktop

#109
post #104

>Don't leave your friends behind, invite them to signup with this unique link. The more friends that join, the further you will advance in line for the beta. That's annoying.

Even more annoying is that it tells you how many people are ahead of you in line, so you get to watch that number grow as you move further down the list...

I was pretty excited about this when I saw the title, now I'm just annoyed.

Re: Signal Desktop

#110
post #102
post #79

Earlier quoted context omitted.

Signal is an order of magnitude easier to use than PGP. It's not even close. The GP was comparing two apps that are actually both very easy to use, one maybe slightly moreso. (That said, PGP isn't THAT hard either.)

I've been actively using PGP for about 2 years with a few friends that all use keybase, but I still don't feel like I really know what I'm doing, or if I'm really doing the right thing. A lot of the terminology and best practices I learned while first setting it up are lost on me now. It still works though! Well, somewhat... since I switched to KDE thunderbird no longer remembers my pgp password. I miss the gnome key…

70% of the UX complaints people have about PGP stem from the huge number of options it has and the lack of guidance it gives you for which options matter.

Which is a shame, because none of the options actually matter.

If you're encrypting messages to a public key, and not with a passphrase, and you're signing the messages you encrypt, you're getting 98% of the value PGP has to offer.

If you want to do things more advanced than that, you probably shouldn't use PGP. PGP has lots of advanced options, but it lacks a lot of fundamental features you'd want from a secure messaging system.

But for the basic use case it supports without options, PGP is just fine.

Post reply on HN