> how we think about concepts like privacy, security, and trust I was disappointed to see that a mobile number is needed and that this number is shown by default in groups. Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily. So I now prefer Telegram because at least it hides numbers in groups by default.
As I understand it, the purpose of using telephone numbers is that it can use the contact list stored on your phone without having to store contact lists on their servers. Contact lists can be useful information for an attacker. If Signal doesn't have it, it can't be taken from them.
Looking back at how Signal works
141–150 of 301 posts
Re: Looking back at how Signal works
#142I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…
I never had a single one of those you listed here.
Re: Looking back at how Signal works
#143Is it worth trying to move my friends from WhatsApp to Signal? As I understand it, they're both e2e encrypted. I'm also trying to move my chats from SMS and Gchat to something encrypted, but am torn between WhatsApp and Signal. The former has more of a buy-in with my contacts already. I realize WhatsApp is owned by Facebook, but isn't the whole point of e2e encryption that you don't have to trust the intermediate inf…
If the client app is open source. There's no way to know FB isn't just copying your keys or doing something else nasty. That whole spiel on their site about how E2EE protects you/makes the world a better place/yada yada is completely moot since they use a closed-source client.
Re: Looking back at how Signal works
#144I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…
Seriously... I do not understand how they keep investing in this gold-plating when the plumbing keeps getting clogged up.
Re: Looking back at how Signal works
#145I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…
Mabe they just don't have the problems? I never had a single one of those you listed here.
Re: Looking back at how Signal works
#146> how we think about concepts like privacy, security, and trust I was disappointed to see that a mobile number is needed and that this number is shown by default in groups. Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily. So I now prefer Telegram because at least it hides numbers in groups by default.
This is a fair concern, and I hope Signal Addresses it at some point, but Telegram is no replacement. From Telegram's Wikipedia page "The default messages and media use client-server encryption during transit.[19] This data is also encrypted at rest, but can be accessed by Telegram developers, who hold the encryption keys," and "the desktop clients (excluding macOS client) do not feature end-to-end encryption, nor is…
Re: Looking back at how Signal works
#147I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…
But they have stickers! Who needs good sync when you have stickers! Oh, and arbitrary emoji reactions! Seriously... I do not understand how they keep investing in this gold-plating when the plumbing keeps getting clogged up.
EDIT: Those are two different people.
Re: Looking back at how Signal works
#148Re: Looking back at how Signal works
#149* It's "Custodial E2EE"
* Needs a phone number
(I'm not going to bother with his complaints about the crappiness of the desktop client or convenience of the design because those are non-sequiturs to the security of the app)
I asked him to define "Custodial E2EE". His words: "They have ownership of my keys, use phone number auth to access them and I cant expatriate them"
I managed to suppress my xkcd-386 instinct and go to bed, but my intuition is still that he's quite wrong about that. I may or may not resume my arguement with him; I got the impression that his disagrements were rooted in a Matrix fanboyism, but I'd like to be equipped to refute such arguments in the future.
I can somewhat sympathize with the phone number argument, and I think it comes from a concern about metadata leaks or opsec. I think that concern ultimately stems from a wrong threat model, but I'm not sure how to refute that. I have however, come across a number of tutorials which cover how to register a Signal account without using your phone numbers, so I feel confident I can refute the argument that signal must have your phone number, even if I can't refute the underlying wrong thinking.
Regarding the "Custodial E2EE" argument, I'm not sure where to begin. Anyone have any suggestions?
Re: Looking back at how Signal works
#150Earlier quoted context omitted.
They purport they are against fascism. But if you look at what they do sometimes, it amounts to little more than looting, rioting and vandalism. Not always, but sometimes. They don’t seem to have a designated modus operandi.
You are being downvoted because the current understanding here, AFAIU, is that there is no good identifier of the "they" where you say "they purport" because there does not currently exist an organized group that identifies themselves as "ANTIFA". If you are aware of sources that indicate otherwise, would you mind sharing them?