Live data from Hacker News

Looking back at how Signal works

signal.org

161–170 of 301 posts

Re: Looking back at how Signal works

#161

Earlier quoted context omitted.

But they have stickers! Who needs good sync when you have stickers! Oh, and arbitrary emoji reactions! Seriously... I do not understand how they keep investing in this gold-plating when the plumbing keeps getting clogged up.

Signal doesn't have arbitrary emoji reactions, that is one feature I do wish it had. Though obviously I'd prefer a better desktop client first.

They're coming, currently in beta (source: am using the beta, it's public, check the play store page)

Re: Looking back at how Signal works

#162

Earlier quoted context omitted.

Maybe, but I have them every single time I use Desktop, so I'm puzzled that you don't.

It's not just me. My SO, her mother and my parents doesn't either.

This is semi-unrelated, but indicative: I posted a bug about photos taken in landscape showing up as portrait (ie sideways) if the screen is locked, and it was closed as "we'd like to have this fixed at some point".

How is rotating photos properly not a priority for a messaging app? It's really annoying to have half your photos rotated sideways, and it screams "buggy app" to both participants of the conversation.

Re: Looking back at how Signal works

#163

Somewhat tangential, I got into an argument about Signal last night. The other guy claimed that Signal was insecure because: * It's "Custodial E2EE" * Needs a phone number (I'm not going to bother with his complaints about the crappiness of the desktop client or convenience of the design because those are non-sequiturs to the security of the app) I asked him to define "Custodial E2EE". His words: "They have ownership…

On the first point, their understanding of Signal's key management doesn't seem to be correct. The private key is held only by the client on the mobile phone, which is one of the reasons that the desktop client is rather clumsy - it is dependent on the mobile app for initial key setup. It's also just very slow compared to the mobile app. On the second point, I think they are quite correct. Yes, this depends on your u…

>I'm also, to be honest, somewhat baffled that your starting position seems to be that no criticism of Signal could possibly be valid, when attributing the other's viewpoint to fanboyism. Don't take that too seriously, it just stood out to me on reading. :)

Touche. That wasn't my position, but re-reading what I posted, I agree that's it unnecessarily implies that position. Part of me wants to correct that, but I think I'll own my words and leave it there.

Re: Looking back at how Signal works

#164

What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be downloaded if they do not add the backdoor in? Is there a workaround that will allow people to use it still? I've heard people mention locating the servers in other countries, but wouldn't the various App stores be bound by US law and still not allow them?

Signal started open-source, it was TextSecure, I'm sure there'll be an open-source alternative if the commercial entity fails, though I hope they do not.

Signal is still open source and is not a commercial entity.

Re: Looking back at how Signal works

#165

Earlier quoted context omitted.

But they have stickers! Who needs good sync when you have stickers! Oh, and arbitrary emoji reactions! Seriously... I do not understand how they keep investing in this gold-plating when the plumbing keeps getting clogged up.

Signal doesn't have arbitrary emoji reactions, that is one feature I do wish it had. Though obviously I'd prefer a better desktop client first.

You can now select any emoji for a reaction in the version that was just released (at least on Android).

Re: Looking back at how Signal works

#166

I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…

I knew Signal was against federation but I hadn’t realized they had pretty much banned third party clients. That would otherwise have been a really easy win for people that actually care about the system integration, performance, and architecture of desktop clients enough to shun electron “clients.”

The Signal team has always been open about the reason why they reject third-party clients: they claim that XMPP adoption was hindered by the inability of a user’s software to know if the software on the other end supports the same feature set. XMPP had grown into a large set of features that some clients supported and others did not.

If Signal introduces a new feature, it knows that all users’ devices will support that feature, because its own software is the only game in town.

Re: Looking back at how Signal works

#167
post #6

Earlier quoted context omitted.

Burner sim to setup and throw away addresses this concern. Telegram, messages in plaintext on the server? Encryption that isn't open? Yeah telegram is a bit of a non-starter if you have these kinds of concerns as far as I'm aware.

In most European countries you need to submit your ID to get any sort of working SIM card.

In the UK you can buy a SIM from a vending machine in the airport.

Re: Looking back at how Signal works

#168

I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…

I, for one, have a bigger problem with it forcing the use of phone numbers as a sign-in method. They're an arbitrary identifier from a legacy system that there's not really a point in continuing to extend, because if your device is capable of anything more advanced than SMS it's also capable of... well, this.

Also KaiOS and the like are making chat feasible even on feature phones.

Don't get me wrong, RCS will be a fine enough fallback (once it's E2E), but standardized chat is the dream.

Re: Looking back at how Signal works

#169

Earlier quoted context omitted.

I knew Signal was against federation but I hadn’t realized they had pretty much banned third party clients. That would otherwise have been a really easy win for people that actually care about the system integration, performance, and architecture of desktop clients enough to shun electron “clients.”

The Signal team has always been open about the reason why they reject third-party clients: they claim that XMPP adoption was hindered by the inability of a user’s software to know if the software on the other end supports the same feature set. XMPP had grown into a large set of features that some clients supported and others did not. If Signal introduces a new feature, it knows that all users’ devices will support th…

Backwards compatibility against a previous set of features isn't easy but it's certainly not impossible and graceful degradation is a thing.

Re: Looking back at how Signal works

#170
post #131

Earlier quoted context omitted.

The desktop was pretty terrible for me (on Linux) for until a few months ago, but now it works perfectly. The only thing missing is sms from the desktop but from what I understand Signal won't ever add that because sms isn't secure

there's still no call/video from the desktop, no?

There is an option in settings to enable camera and microphone, no? Have you tried that?
Post reply on HN