Live data from Hacker News

Session is shutting down in 90 days

getsession.org

181–190 of 196 posts

Re: Session is shutting down in 90 days

#181

I've built many apps throughout the years. One thing that I've learned is that privacy is a secondary concern. It's never a primary one. If your app's main differentiation is privacy, it won't sell. Users just don't care about it that much.

Inauthentic activity benefits from privacy though. Inauthentic activity is a primary use case of ChatGPT, which is way more successful than anything you've ever made. Do you think kids using ChatGPT to cheat on homework would care if their chats were "private" but educators could check if submitted essays matched generated content? Uh, yes. So privacy isn't as simple of an idea as you think it is, and is certainly ex…

It is certainly extremely valuable as an ideological construct, i.e. a fake notion to mislead people into self-defeating behaviors.

"Why not use $COP_APP?" "It's not private" "Well it's by a private company, it's not run by the government or anything - what the fuck are you talking about, corporal?"

Re: Session is shutting down in 90 days

#182
post #110

That’s not really a big deal since the session encryption was insecure anyway. It feels almost like a honeypot after they've removed forward secrecy. If you’re looking for a decentralized alternative SimpleX Chat is a more secure option.

My issue with SimpleX is that the company is in the UK, and it's developed in the UK under UK law. https://simplex.chat/transparency/ Considering how fiercely anti-encryption the UK is/has become (because "only child molesters care about encryption!"), this is sadly reason enough for me not to trust it. Do I believe they have a backdoor in their software? No. But if the UK passes a law demanding they introduce one...

Its FOSS so such a change would be visible.

What government are you certain will never introduce a backdoor requirement?

Re: Session is shutting down in 90 days

#183
post #95
post #68

Earlier quoted context omitted.

I primarily use a nearly-bottom end android phone that's a few years old and just recently switched to an even older, even lower end android phone that is six years old. Neither has that issue. Obviously, I'm not really claiming that it's not possible people are experiencing this issue, but it can't possibly be widespread. I feel like most likely people are using android skins that aggressively kill apps in the backg…

I have that exact issue on a couple of not exactly low end Samsung phones. Holding them side by side with signal open. Delivery times vary wildly. Whereas WhatsApp just works (though I hate it for other reasons)

I can see why that would be incredibly frustrating. Have you reported it to them, either via github or email?

Re: Session is shutting down in 90 days

#184

Earlier quoted context omitted.

Well, I and a lot of the people I'm going to talk to through things like Signal are going to have a state ID regardless as I live in a country where one practically needs to drive a car to function in society. On top of that so many other things just inherently expect one to have a phone number. It would be somewhat odd to not have a phone number for most of the people I know and talk to through platforms like Signal…

That's not what I asked.

You asked which is easier, and I gave my answer. It's easier for me and many many many millions (billions?) of others to have a phone number and state ID, because we'll have already had a phone number and state ID on hand for decades beforehand and have shared that number with the people we're already talking to while making a new identifier and sharing it would be quite a bit more work.

What's easier, using a tool that's already in your hand or going to the tool store, searching for a new one, and swapping to that one? Just using the tool already in your hands, that you're already using, that you've been using for a long time.

It's exactly what you asked, just not the perspective you cared to look at.

Re: Session is shutting down in 90 days

#185
post #121
post #48

Earlier quoted context omitted.

Source?

It would've taken you less time to Google, but sure: https://www.bleepingcomputer.com/news/security/signal-fixes-... Send a GIF to Contact A, Contact B receives random private images? Absolutely inexcusable slop code project. This class of state management bugs should not be possible with a well-architected client, period. Signal's E2E encryption is more like End 2 Random End.

Or why not include the source of your claim up front?

From GitHub comments: https://github.com/signalapp/Signal-Android/issues/10247

Greyson:

> Hi there, sorry, this issue was fixed in 5.17 (which hit 100% production on 7/21)

They had a difficult to reproduce problem reported in late December 2020, and got the fix rolled out seven months later.

Not sure your criticism "absolutely inexcusable slop code" is well considered.

Re: Session is shutting down in 90 days

#186

Earlier quoted context omitted.

The problem with XMPP is that most clients use an outdated and insecure implementation of OMEMO. This includes popular clients such as Conversations and Gajim. Currently only Profanity and Kaidan use the latest version and you must always assume that the encryption has been secretly downgraded because the other person is using an insecure client. I highly recommend Soatek's blog post on this topic. https://soatok.blo…

Does that blogger discuss metadata, at all? I'm not saying the stuff pointed out in various non-Signal tools isn't valid, but I don't see any discussions on the dangers of metadata.

Yes, I do. See my review of Signal for more: https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...

Re: Session is shutting down in 90 days

#187

Earlier quoted context omitted.

That's not what I asked.

You asked which is easier, and I gave my answer. It's easier for me and many many many millions (billions?) of others to have a phone number and state ID, because we'll have already had a phone number and state ID on hand for decades beforehand and have shared that number with the people we're already talking to while making a new identifier and sharing it would be quite a bit more work. What's easier, using a tool t…

In the time it took you to selectively bring various outside context "for perspective" (instead of answering the question as asked) you could've registered a brand new account with username, password, email confirmation, and OTP 2FA, on any service that supports those.

If you insist that 2+2 equals "3 or 5 depending on perspective", ok sure let's work with your scenario of comparing registering a pre-existing state/telco ID with creating a brand new user/pass account (again: instead of what I asked you to compare). Well, suppose you were to lose your ID and/or your SIM - do you think you'd be able to renew them and regain access to your stuff in the same amount of time it's taking me to write this now?

Plus, I guess you've never seen bad actors buy fake ID/SIM accounts faster than you can block 'em - and much more quickly than any individual good-faith actor (with a single ID/SIM honestly linked to meatspace) would able to get out of harm's way in such a scenario.

>What's easier, using a tool that's already in your hand or going to the tool store, searching for a new one, and swapping to that one? Just using the tool already in your hands, that you're already using, that you've been using for a long time.

Hammers, nails... You're trying to make it make sense by dumbing it down.

In the end (again conforming to your framing), the "easier thing" is the one that fewer people will expend energy to prevent you from doing. And this last consideration kinda-sorta makes your reply be an answer to my question, except that I had to do the work of connecting the two, so now you owe me 100EUR.

Re: Session is shutting down in 90 days

#188

Earlier quoted context omitted.

You asked which is easier, and I gave my answer. It's easier for me and many many many millions (billions?) of others to have a phone number and state ID, because we'll have already had a phone number and state ID on hand for decades beforehand and have shared that number with the people we're already talking to while making a new identifier and sharing it would be quite a bit more work. What's easier, using a tool t…

In the time it took you to selectively bring various outside context "for perspective" (instead of answering the question as asked) you could've registered a brand new account with username, password, email confirmation, and OTP 2FA, on any service that supports those. If you insist that 2+2 equals "3 or 5 depending on perspective", ok sure let's work with your scenario of comparing registering a pre-existing state/t…

> instead of answering the question as asked

I've answered it twice. Its easier to use the thing you already have than it is to make something new. Is that really difficult to understand?

> you could've registered a brand new account with username, password, email confirmation, and OTP 2FA, on any service that supports those

And then spend the many, many, many hours to share that new unique identifier with all the people I want to talk to. Or I can just continue using the same identifier they already know me by and have known me by for decades.

> I guess you've never seen bad actors buy fake ID/SIM accounts as quickly as you can block 'em

Whaaaa I thought you just told me a phone number is such an incredibly hard and challenging thing to get, now you're telling me anyone can easily get them anytime they want?

So phone numbers are incredibly challenging to get and yet people get them all the time easily. Otherwise, if phone numbers aren't hard to get and anyone can just freely get them what are we even really debating about?

For billions of users, having a phone number as their identifier isn't a challenge and is for sure the easier process and having to make a new unique identifier is a bigger deal and introduces far more roadblocks to effectual adoption. Its why WhatsApp uses it, its why iMessage uses it, its why Telegram uses it, its why WeChat uses it, and many others.

Re: Session is shutting down in 90 days

#189

Earlier quoted context omitted.

In the time it took you to selectively bring various outside context "for perspective" (instead of answering the question as asked) you could've registered a brand new account with username, password, email confirmation, and OTP 2FA, on any service that supports those. If you insist that 2+2 equals "3 or 5 depending on perspective", ok sure let's work with your scenario of comparing registering a pre-existing state/t…

> instead of answering the question as asked I've answered it twice. Its easier to use the thing you already have than it is to make something new. Is that really difficult to understand? > you could've registered a brand new account with username, password, email confirmation, and OTP 2FA, on any service that supports those And then spend the many, many, many hours to share that new unique identifier with all the pe…

>Its easier to use the thing you already have than it is to make something new. Is that really difficult to understand?

I asked which is easier to make.

This is, evidently, an extremely difficult question to understand.

>Whaaaa I thought you just told me a phone number is such an incredibly hard and challenging thing to get, now you're telling me anyone can easily get them anytime they want? >So phone numbers are incredibly challenging to get and yet people get them all the time easily.

Not phone numbers; accounts gatekept by them.

Not anyone; only bad actors.

>I thought you just told me

What I just told you is written in the parent post.

You have the right to misread it any way you like, and think whatever comes to your mind easiest. But since that's not how a conversation works, I will ask you to exercise that right somewhere I can't see you - and by the way you still owe me 100EUR, but since I'm not an actual cyberstalker, I won't be chasing you down to collect. So relax.

Re: Session is shutting down in 90 days

#190

Earlier quoted context omitted.

> instead of answering the question as asked I've answered it twice. Its easier to use the thing you already have than it is to make something new. Is that really difficult to understand? > you could've registered a brand new account with username, password, email confirmation, and OTP 2FA, on any service that supports those And then spend the many, many, many hours to share that new unique identifier with all the pe…

>Its easier to use the thing you already have than it is to make something new. Is that really difficult to understand? I asked which is easier to make . This is, evidently, an extremely difficult question to understand. >Whaaaa I thought you just told me a phone number is such an incredibly hard and challenging thing to get, now you're telling me anyone can easily get them anytime they want? >So phone numbers are in…

> I asked which is easier to make.

Which is easier to make? The one I don't even have to make, I already have.

Which pizza is easier to make, the premade pizza that's already ready to eat and is right in front of you, or the pile of ingredients in the pantry and fridge? Uhh...the pizza in front of you ready to eat? Put it on a plate and eat, it's there, it's ready to go. And practically everyone already bought their pizza and it's already in front of them.

And no, you didn't ask which is easier to make.

> What's easier: to obtain state ID, or to sign up to a website with your preferred username and password?

Where's the word "make" in that?

> Well, suppose you were to lose your ID and/or your SIM - do you think you'd be able to renew them and regain access to your stuff in the same amount of time it's taking me to write this now?

Well, I'll end up wanting to replace that ID and SIM for once again a multitude of other reasons, so having that identifier tied to that really doesn't increase any complexity. Its really not that big of a challenge for billions of users, its something they're going to already do. When the school needs to urgently get a hold of me, they'll call my phone number not refer to me by some handle on a jabber server with a population of one. This same thing applies over and over and over and over for tons of people.

Meanwhile if I've got other accounts tied to other processes that get lost in their own unique ways, I'll have separate issues to get those unique identities recovered. Sounds like more work, not less work.

You now owe me 20,000,000,000,000,000,000EUR, but since I'm not an actual cyberstalker, I won't be chasing you down to collect. So relax. Such a useless thing to add to the conversation.

Post reply on HN