Live data from Hacker News

Technology Preview: Signal Private Group System

signal.org

21–30 of 153 posts

Re: Technology Preview: Signal Private Group System

#21
post #5

Earlier quoted context omitted.

I love Signal, and upsell it whenever I can. Signal has its ideosyncratic parts, some of which are being worked on, others not so much. Some of the more visible ones are IMO: Signal forces users to use phone numbers; some people don't like this because they want to use multiple ephemeral usernames so they can be 'Joe' to friends, 'kleptoclown' to their github group, 'dungeonmaster42' to their DND group, 'joesolutione…

"Signal forces users to use phone numbers" Which is number one reason why I'm not even considering it "some people don't like this because they want to use multiple ephemeral usernames" That's not my reason: I don't want people I don't know to get my phone number through other people I know and trust, but are used to share everything online. Of course that would be possible without any social application as well, tho…

The day I would be comfortable giving out my phone number to stranger is when it becomes mandatory to whitelist all callers, much like how just about any non-PSTN systems work.

Maybe this is because of the social expectations of that it will work without such overhead but I just simply can't notice how all the "countermeasures" phone industry (and governments as this is a heavily regulated industry) are ignorance to elephant in the room...

Re: Technology Preview: Signal Private Group System

#22
post #20
post #18

Earlier quoted context omitted.

Why would Signal (a drop-in SMS replacement) be compared to Slack?

Because we're talking about group messaging here.

Why would group Signal messages (a drop-in replacement for group texts) be compared to Slack?

Re: Technology Preview: Signal Private Group System

#23
post #2

Again, in the theme of "features every group messaging system had already, but Signal didn't, because they hadn't figured out a way to implement it without turning Signal's central servers into a database of who's talking to who about what". Signal didn't even have user profiles until recently, for the same reason. Here, they've slightly expanded the state of the art in MAC-based anonymous credentials to accomplish t…

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

> ability to keep identity and full message history when moving to a new device.

I would love that. But even with WhatsApp it never worked for me.

Last three device switches:

Windows Phone to Android: Not supported. Android to Android: something went wrong. Android to iPhone: Not supported.

Re: Technology Preview: Signal Private Group System

#24
post #2

Again, in the theme of "features every group messaging system had already, but Signal didn't, because they hadn't figured out a way to implement it without turning Signal's central servers into a database of who's talking to who about what". Signal didn't even have user profiles until recently, for the same reason. Here, they've slightly expanded the state of the art in MAC-based anonymous credentials to accomplish t…

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

Maybe the concern is exfiltration? Making it easier to move phones may also make it easier for a hacker to exfil your data from a local hack or your phone's cloud (i.e., just hack your Icloud and trigger restore to a new phone)

Re: Technology Preview: Signal Private Group System

#25

I really want Signal to succeed. Or rather, I want anything that has decent cryto and is not FAANG to succeed. The problem is not which messaging app I want to use, it's which messaging app my friends are using. That said, if I had to choose, I think Matrix has a slight edge in my books because it's a protocol rather than a silo. Even though Signal is private and open source, they are hostile towards people running t…

This is why I think Keybase is so awesome. I've gotten some of my friends on it and so far the encryption/exploding messages and all is working great.

Re: Technology Preview: Signal Private Group System

#26
post #6
post #5

Earlier quoted context omitted.

I love Signal, and upsell it whenever I can. Signal has its ideosyncratic parts, some of which are being worked on, others not so much. Some of the more visible ones are IMO: Signal forces users to use phone numbers; some people don't like this because they want to use multiple ephemeral usernames so they can be 'Joe' to friends, 'kleptoclown' to their github group, 'dungeonmaster42' to their DND group, 'joesolutione…

It's really an engine for revealing people's true preferences for messaging, which, for many people, tend to be that they want all the ergonomics of Slack a lot more than they want cryptographically sound secure messaging. What's hopeful in all this is that Signal is, slowly, catching up. Slack can roll out new features just by assigning a couple developers to it, and Signal has to coordinate new cryptographic resear…

My biggest annoyance with Signal is that getting a new phone ends up wiping out all conversation history with apparently no way to transfer it.

This loss of user data is not advertised well enough up front, and leaves users feeling tricked. In many contexts loss of user data is an even bigger sin than weak security.

Re: Technology Preview: Signal Private Group System

#27
post #24

Earlier quoted context omitted.

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

Maybe the concern is exfiltration? Making it easier to move phones may also make it easier for a hacker to exfil your data from a local hack or your phone's cloud (i.e., just hack your Icloud and trigger restore to a new phone)

Unencrypted data/keys should never be in the backup, only data encrypted to some passphrase. It's perfectly fine (and necessary) to require a passphrase to recover backed up logs on the new device.

Re: Technology Preview: Signal Private Group System

#28
post #25

I really want Signal to succeed. Or rather, I want anything that has decent cryto and is not FAANG to succeed. The problem is not which messaging app I want to use, it's which messaging app my friends are using. That said, if I had to choose, I think Matrix has a slight edge in my books because it's a protocol rather than a silo. Even though Signal is private and open source, they are hostile towards people running t…

This is why I think Keybase is so awesome. I've gotten some of my friends on it and so far the encryption/exploding messages and all is working great.

Keybase is awesome, it's really improved over the years.

Re: Technology Preview: Signal Private Group System

#29
post #6

Earlier quoted context omitted.

It's really an engine for revealing people's true preferences for messaging, which, for many people, tend to be that they want all the ergonomics of Slack a lot more than they want cryptographically sound secure messaging. What's hopeful in all this is that Signal is, slowly, catching up. Slack can roll out new features just by assigning a couple developers to it, and Signal has to coordinate new cryptographic resear…

My biggest annoyance with Signal is that getting a new phone ends up wiping out all conversation history with apparently no way to transfer it. This loss of user data is not advertised well enough up front, and leaves users feeling tricked. In many contexts loss of user data is an even bigger sin than weak security.

What's ironic here is that in the adversarial setting the application is designed for, unexpected retention of user data (on end-user devices) is a sin.

Re: Technology Preview: Signal Private Group System

#30

I really want Signal to succeed. Or rather, I want anything that has decent cryto and is not FAANG to succeed. The problem is not which messaging app I want to use, it's which messaging app my friends are using. That said, if I had to choose, I think Matrix has a slight edge in my books because it's a protocol rather than a silo. Even though Signal is private and open source, they are hostile towards people running t…

The one thing I don't like about Signal is that it's tied to a phone number. Sure, you can tie the account to a VoIP number but that's not the same as Wire which allows you to sign up with an email address and your account id based on a username, which cannot be SIM-attack hijacked.
Post reply on HN