Live data from Hacker News

Technology Preview: Signal Private Group System

signal.org

141–150 of 153 posts

Re: Technology Preview: Signal Private Group System

#141
post #77

Earlier quoted context omitted.

Yes, you are an exception. Just look at how popular books of letters are: https://www.goodreads.com/list/show/100260.Best_Books_of_Let... Or look at how popular "Letters of Note" is: https://twitter.com/lettersofnote Conversation is connection.

I'm going to keep digging this hole for myself because I think there is some amount of treasure to be found. I'm also interested to see how far out of touch I am. There are tiers of conversation. Letters between famously literate people or during times of war have a value proposition on an entirely different scale to group chat messages. It's about the value that the individual assigns to the content of the conversat…

> It feels as if the point that I'm trying to make is that mindful archiving is a better solution than to just 'keep all the things'

On the topic of plain text things (such as text messages) - how much data are you actually hoarding?

Let's say you type 100 words per minute for the next 40 years (and each word is 10 bytes). No sleep, no breaks, just 40 years of typing. Congratulations, you just produced 21GB of data. This fits on an SD card (I don't like the term "hoarding" for this. Hoarding has a negative connotation. Storage of plaintext is so incredibly cheap (and search so fast) that I feel that option value of retaining the text is almost always greater than the miniscule cost of storage and slower retrieval.

I don't think are any valid analogies between storing physical items and digital items, as digital storage and search is orders of magnitude cheaper. Consider the same experiment where one writes with pen and paper for 40 years, and then wishes to search for the name "George".

Making a decision of what to keep must be more expensive and time-consuming than just keeping everything.

Re: Technology Preview: Signal Private Group System

#142

Earlier quoted context omitted.

I actually going in the other direction with Signal I turned on timer (1 week) for all of my conversation. Nothing stays more than a week and I do not keep any backup. It's not for security or privacy reasons. I feel like I don't need a full history of all my conversations with everyone from the beginning of time. This fits more to the real life model of having a conversation with someone. I don't record my conversat…

Interesting that that model works for you, but that doesn't mean it works for everyone. Persistent history that lasts many times longer than the lifetime of any one device is a required feature to fully replace chat apps that have such history.

Whatsapp doesn't have that feature when you switch between iOS and Android however.

Re: Technology Preview: Signal Private Group System

#143
post #108

Earlier quoted context omitted.

> To allow for recovery of message history, you have to escrow the secret somewhere. You seem to be missing the point here: this isn't even about storing your data on someone else's computer with some kind of key escrow, this is about local backups not even working. Apple only recently implemented iMessage "sync", but before that (and still now), iMessage data was backed up to your Mac and accessible in your backup,…

Yeah that’s true. They should allow encrypted backups to be stored in iCloud backups (they intentionally exclude this for some reason). But even then, this is a feature that will only ever be used by highly motivated individuals. The Android backups are useless if you lose your 30 digit secret. I agree their position on this is shit, but I can’t imagine it’s a barrier to mainstream adoption.

It is a massive barrier, people won't switch to secure messaging if it's unusable.

Re: Technology Preview: Signal Private Group System

#144
post #5
post #3

Earlier quoted context omitted.

> This is either a reason you love Signal (raises hand) or can't stand Signal. Eh? Why either or? (and why are there people who can't stand it?)

I love Signal, and upsell it whenever I can. Signal has its ideosyncratic parts, some of which are being worked on, others not so much. Some of the more visible ones are IMO: Signal forces users to use phone numbers; some people don't like this because they want to use multiple ephemeral usernames so they can be 'Joe' to friends, 'kleptoclown' to their github group, 'dungeonmaster42' to their DND group, 'joesolutione…

> Signal cannot have multiple mobile clients, only one mobile client and a single desktop version

You are right about the mobile client, but that's not true of desktop. I have Signal installed and setup on every desktop/laptop that I use without any issue.

Re: Technology Preview: Signal Private Group System

#145
post #14

Earlier quoted context omitted.

Matrix and Signal aren't comparable from a security perspective. Because Matrix is a protocol rather than a silo, many (most?) of its implementations don't even support E2E, and because Matrix has its roots in an ecosystem where E2E was a nonstandard add-on, Matrix will never be as safe as Wire or Signal.

Matrix project lead here; fwiw we’re aiming to turn on E2E by default for private rooms by end of Jan. It’s not really a non-standard add-on; it’s in the core of the protocol and has been designed for from the outset. It’s a pain in the ass to get right in a decentralised world though, hence the delay in forcing it on for everyone. p.s. support for ephemeral msgs was released on the server in RC yesterday.

The way these conversations are structured, I'm always going to come across like I'm rooting for Matrix to fail, which is not at all the case. Like I said, I use Slack more than any other group messaging system, and while Slack does have some security assets that Matrix lacks, nobody can say that it has a more coherent encryption story. I wish Matrix all the best; I just don't think it's reasonable to suggest it as an alternative for people who need secure messaging that reliably works in groups of people.

Re: Technology Preview: Signal Private Group System

#146

Earlier quoted context omitted.

What you're asking for is exactly how Telegram works, you can add someone with a phone number or by username, but if you add someone via username they don't see your phone number. Of course, Telegram chats are not encrypted by default, and there is some controversy over the encryption protocol. https://telegram.org/faq#q-if-someone-finds-me-by-username-m...

Last time I checked, the only option to login was using a phone number. And at least the web client only has the phone number as login. I do not want to give them my phone number. Full stop. They can tie my account to my email, to my domain, to a chosen username, whatever. But if your service requires a phone number to use it, it’s not something I will use.

It's still true. Telegram still uses your phone number to login, even if you never give your phone number to anybody. At least usernames are an option unlike Signal and WhatsApp.

I dislike it too, but understand the reasoning behind spam prevention and account authentication.

Re: Technology Preview: Signal Private Group System

#147

Earlier quoted context omitted.

Yeah that’s true. They should allow encrypted backups to be stored in iCloud backups (they intentionally exclude this for some reason). But even then, this is a feature that will only ever be used by highly motivated individuals. The Android backups are useless if you lose your 30 digit secret. I agree their position on this is shit, but I can’t imagine it’s a barrier to mainstream adoption.

It is a massive barrier, people won't switch to secure messaging if it's unusable.

As a messaging service, it’s certainly not ‘unusable’. You’re claiming that the ability to permanently archive message history is an absolute minimum requirement for consumers (and that a service that does not offer this is ‘unusable’). I’m going to put a big citation needed on that.

Re: Technology Preview: Signal Private Group System

#148
post #120

Using a throwaway for obvious reasons... I am grateful these are being worked on because they are extremely needed for some use cases. I have been part of a group organizing protest in Beirut and I was surprised there was no clearly go to app that provided the security features we need. We started off with WhatSapp because that's what everyone used before security became a concern. We then moved to Signal mostly to g…

Telegram is good enough, no?

We thought so. The lack of auto destructing messages is inconvenient but not a deal breaker.

But it uses SMS to authenticate new sessions... we were a target of attack that exposed our group.

A few users had not set up two factor authentication so they woke to a warning from telegram that someone is logged in to their account from across the world.

Re: Technology Preview: Signal Private Group System

#149
post #122

Is it a coincidence this came up on HN at the same time Telegram is getting dissed on HN? Can't help but think it was coordinated...which is sad for HN

People don't like Telegram because it's a centralized thing and maybe not trustworthy. I'm not sure if I'd trust the Telegram founders, and their commitment to open source seems questionable to me (no server, outdated clients). People advocate for Signal because it's arguably the least offensive of the available e2e options. Also the founder for Signal has a long history of doing good work in this area.

> People don't like Telegram because it's a centralized thing and maybe not trustworthy.

Just like Signal.

> I'm not sure if I'd trust the Telegram founders, and their commitment to open source seems questionable to me

Meanwhile Moxie Marlinspike's opposition to free software is evident. You use the client he dictates or fuck off. There's closed source software that respects freedom more than Signal.

Re: Technology Preview: Signal Private Group System

#150
post #101

I think I know the answer already, but just in case: is there a way to use Signal to communicate with users using Whatsapp? IOW, can I receive Whatsapp messages in Signal? The only reason I use Whatsapp is because it's what all my contacts use. It's everywhere . It's the de facto standard for text communication. And I hate the app. I hate its guts. I read that whatsapp implemented the signal protocol, does that mean…

Neither the Signal guy nor Facebook like interoperability, so no.
Post reply on HN