Live data from Hacker News

Looking back at how Signal works

signal.org

181–190 of 301 posts

Re: Looking back at how Signal works

#181
Lately I've been wishing Signal had a bridgefy type mesh mode that enabled operation peer to peer over wifi direct or bluetooth, either directly or via a mesh of such devices.

First I think it would be useful at protests, to preserve privacy (and whatever side of the political divide you are on, I hope we agree that covert government surveillance and tracking of people at a protest is wrong, here, in HK, or wherever).

But it would also be nice to have when outside the reach of cellular or wifi internet. Think camping, traveling, people living with intermittent power, or those who lost power in some sort of disaster or emergency.

I'm honestly not sure if this would be feasible, as I don't grok the signal protocol fully, but the signal protocol does support async messaging.

Re: Looking back at how Signal works

#182
post #94

Earlier quoted context omitted.

Putting aside Signal officially declining to the add option to discover or manually add a server via the client, theirs nothing stopping anyone from going to GitHub, downloading the code for the server and client, editing the code however they see fit as long as it follows the legal guidelines.

> long as it follows the legal guidelines. So like, as long as they add in the backdoor?

Nope. But following GPL open source license guidelines and releasing your changed codes. And not using signal name and their copyright materials.

Re: Looking back at how Signal works

#183
post #28

Earlier quoted context omitted.

Signal’s official statement on the EARN It Act is here: https://signal.org/blog/earn-it/

Signal should at least make itself available on F-Droid.

You can get apk if you want : https://signal.org/android/apk/

Re: Looking back at how Signal works

#185

Earlier quoted context omitted.

Backwards compatibility against a previous set of features isn't easy but it's certainly not impossible and graceful degradation is a thing.

It isn't clear if graceful degradation is possible in a security app.

Cases where a client is completely broken are never the problem: users will be forced to switch to a different client. It sucks, but it's no worse than the current state of affairs. A security-mandated change in protocol/behavior would fairly fall under that category.

Re: Looking back at how Signal works

#186

Earlier quoted context omitted.

But they have stickers! Who needs good sync when you have stickers! Oh, and arbitrary emoji reactions! Seriously... I do not understand how they keep investing in this gold-plating when the plumbing keeps getting clogged up.

Stickers are important for people like my sister and wife, who are put off if the messaging app doesn't support them. I wouldn't knock their importance, but yes, good syncing should come first. EDIT: Those are two different people.

Excellent edit is excellent

Re: Looking back at how Signal works

#187

I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…

I knew Signal was against federation but I hadn’t realized they had pretty much banned third party clients. That would otherwise have been a really easy win for people that actually care about the system integration, performance, and architecture of desktop clients enough to shun electron “clients.”

They also time bomb their own software, so if you don't take automatic updates from them it just stops working.

[Yes, you could manually compile it and update it... which is what I did for the first year I used signal, until it expired on me with no warning while I was away on a trip and had no way to update it.]

Re: Looking back at how Signal works

#188
post #146

Earlier quoted context omitted.

This is a fair concern, and I hope Signal Addresses it at some point, but Telegram is no replacement. From Telegram's Wikipedia page "The default messages and media use client-server encryption during transit.[19] This data is also encrypted at rest, but can be accessed by Telegram developers, who hold the encryption keys," and "the desktop clients (excluding macOS client) do not feature end-to-end encryption, nor is…

It really depends on your threat model: do you trust the people you are talking to but not Signal (though in practice this doesn't even work as they are way too centralized, but whatever), or do you not trust the people you are talking to but are willing to trust Telegram? Clearly we should be able to have something where we don't trust either, as there is nothing about these phone numbers that is critical to Signal'…

The fewer people who you're required to trust, the fewer breaches there will be, even if no one is malicious and those breaches are accidental.

And ultimately even if the people you are talking to and your messaging provider are 100% trustworthy and never make mistakes, they usually cannot resist a lawful government request for data. Signal just has virtual no data available to provide them; Telegram could give them entire chat histories, and could be required to provide access to in-progress chats.

Re: Looking back at how Signal works

#189

Earlier quoted context omitted.

there's still no call/video from the desktop, no?

There is an option in settings to enable camera and microphone, no? Have you tried that?

I have those enabled, but I don't see a way to make a voice or video call from the desktop. Maybe I'm missing something?

Re: Looking back at how Signal works

#190

Earlier quoted context omitted.

I just opened my Signal desktop app that I had synced previously. It asked me to resync again with my mobile device, which needs camera permissions to take a picture of a QR code. I had previously removed Signal from my mobile device. Low and behold, my account no longer existed and I had to sign back up with a phone number. I then clicked sync and most of my messages on my desktop are gone. I don't see how this is e…

If I understand your description, you reset your account. They delete the messages for safety when you reset. An attacker could reset by getting ahold of your phone number by sim jacking or the govt getting your text. It's a safety method so no one can take you texts. Of course many people want to carry their texts along, but this is a safety risk if you lost control over your number. So that's what signal is doing.…

Signal allows backing up messages (though the UI and workflow for it is still rather clunky), so you should be able to restore them even if you switch to a different phone number entirely.
Post reply on HN