Live data from Hacker News

Technology Preview: Signal Private Group System

signal.org

111–120 of 153 posts

Re: Technology Preview: Signal Private Group System

#111
post #2

Again, in the theme of "features every group messaging system had already, but Signal didn't, because they hadn't figured out a way to implement it without turning Signal's central servers into a database of who's talking to who about what". Signal didn't even have user profiles until recently, for the same reason. Here, they've slightly expanded the state of the art in MAC-based anonymous credentials to accomplish t…

Been using signal since textsecure I think (I even think there was another name before that). In all that time, one thing keeps me thinking about backing out: phone numbers. When a contact decides to uninstall signal, I lose contact. Signal still thinks that the recipient has a signal account, and hence won't deliver messages via SMS.

Former Signal users can unregister their phone numbers from Signal on this page:

https://signal.org/signal/unregister

Re: Technology Preview: Signal Private Group System

#112

Using a throwaway for obvious reasons... I am grateful these are being worked on because they are extremely needed for some use cases. I have been part of a group organizing protest in Beirut and I was surprised there was no clearly go to app that provided the security features we need. We started off with WhatSapp because that's what everyone used before security became a concern. We then moved to Signal mostly to g…

This list could be a helpful starting point:

https://en.wikipedia.org/wiki/Comparison_of_cross-platform_i...

You can sort the table by clicking on the column headers. The "E2EE group chat" column should be useful.

Re: Technology Preview: Signal Private Group System

#113
post #14

I really want Signal to succeed. Or rather, I want anything that has decent cryto and is not FAANG to succeed. The problem is not which messaging app I want to use, it's which messaging app my friends are using. That said, if I had to choose, I think Matrix has a slight edge in my books because it's a protocol rather than a silo. Even though Signal is private and open source, they are hostile towards people running t…

Matrix and Signal aren't comparable from a security perspective. Because Matrix is a protocol rather than a silo, many (most?) of its implementations don't even support E2E, and because Matrix has its roots in an ecosystem where E2E was a nonstandard add-on, Matrix will never be as safe as Wire or Signal.

Matrix project lead here; fwiw we’re aiming to turn on E2E by default for private rooms by end of Jan. It’s not really a non-standard add-on; it’s in the core of the protocol and has been designed for from the outset. It’s a pain in the ass to get right in a decentralised world though, hence the delay in forcing it on for everyone.

p.s. support for ephemeral msgs was released on the server in RC yesterday.

Re: Technology Preview: Signal Private Group System

#114

Earlier quoted context omitted.

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

> Is there something I'm missing that makes this a hard problem? Yes. Pretty much the entire security model of Signal underpinned by this UX compromise. The way signal works at the moment, you sign up for an account with your phone number, your device generates a secret, and that secret is used to secure all your communication. You can pass that secret around devices (as long as you have a device that has it - or jus…

How does Matrix/Riot accomplish this successfully then?

Re: Technology Preview: Signal Private Group System

#115

Earlier quoted context omitted.

Been using signal since textsecure I think (I even think there was another name before that). In all that time, one thing keeps me thinking about backing out: phone numbers. When a contact decides to uninstall signal, I lose contact. Signal still thinks that the recipient has a signal account, and hence won't deliver messages via SMS.

Former Signal users can unregister their phone numbers from Signal on this page: https://signal.org/signal/unregister

Yes i know that. So when people don't reply, I check three messages has not been delivered and try to find a why to tell my contacts how to unregister. Which is an unreasonable burden I put on people who try signal and decides it's not for them.

Re: Technology Preview: Signal Private Group System

#116
post #67

Earlier quoted context omitted.

Been using signal since textsecure I think (I even think there was another name before that). In all that time, one thing keeps me thinking about backing out: phone numbers. When a contact decides to uninstall signal, I lose contact. Signal still thinks that the recipient has a signal account, and hence won't deliver messages via SMS.

Assuming you're talking about the Android app, but you can actually force sending with SMS. The option to do so in a conversation/thread can be found by long-holding the send button, which then pops up a context menu to send via Signal or SMS.

This is not a long term solution :)

Re: Technology Preview: Signal Private Group System

#117
post #114

Earlier quoted context omitted.

> Is there something I'm missing that makes this a hard problem? Yes. Pretty much the entire security model of Signal underpinned by this UX compromise. The way signal works at the moment, you sign up for an account with your phone number, your device generates a secret, and that secret is used to secure all your communication. You can pass that secret around devices (as long as you have a device that has it - or jus…

How does Matrix/Riot accomplish this successfully then?

With passwords lol. When the weakest link in your chain is some terrible password your user picked, then all your fancy crypto is pointless. (It also still allows a user’s message history to be destroyed when they inevitably forget your password)

The best solution I’ve seen for this is the BIP39 mnemonics that crypto wallets use (because they face exactly the same problem - making the user the ultimate custodian of the keys). But it’s still terrible and barely usable.

You can also do the 1Password approach and have other users that you trust store all or part of your key material. But all any of the solutions mentioned in this comment do is spread the problem around a bit, not solve it.

Re: Technology Preview: Signal Private Group System

#118

Earlier quoted context omitted.

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

I converted several non-technical people to Signal, and a few were devastated to learn that getting a new phone meant that they lost their message history. They refuse to use it ever again. The other sticking point is the phone number requirement. A (female) friend shared her “Signal” contact info with a professional acquaintance who doesn’t understand boundaries. After ignoring him on Signal, that led to unwanted SM…

Does this hold for backup and restore to the new phone?

Re: Technology Preview: Signal Private Group System

#119
post #2

Again, in the theme of "features every group messaging system had already, but Signal didn't, because they hadn't figured out a way to implement it without turning Signal's central servers into a database of who's talking to who about what". Signal didn't even have user profiles until recently, for the same reason. Here, they've slightly expanded the state of the art in MAC-based anonymous credentials to accomplish t…

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

I don't see the issue as dramatic as you do as I probably don't change my device so often. Writing down a 30-digit code once every 2-3 years isn't that hard. I assume people for whom this is too much do already use whatsapp and wouldn't switch over because they don't care about the reasons for why you have to write down this 30-digits code.

Re: Technology Preview: Signal Private Group System

#120

Using a throwaway for obvious reasons... I am grateful these are being worked on because they are extremely needed for some use cases. I have been part of a group organizing protest in Beirut and I was surprised there was no clearly go to app that provided the security features we need. We started off with WhatSapp because that's what everyone used before security became a concern. We then moved to Signal mostly to g…

Telegram is good enough, no?
Post reply on HN