Live data from Hacker News

Looking back at how Signal works

signal.org

21–30 of 301 posts

Re: Looking back at how Signal works

#21
post #2

> how we think about concepts like privacy, security, and trust I was disappointed to see that a mobile number is needed and that this number is shown by default in groups. Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily. So I now prefer Telegram because at least it hides numbers in groups by default.

My belief is that Telegram excels at security theatre

Re: Looking back at how Signal works

#23

What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be downloaded if they do not add the backdoor in? Is there a workaround that will allow people to use it still? I've heard people mention locating the servers in other countries, but wouldn't the various App stores be bound by US law and still not allow them?

I don't think that the earn it act will affect Signal - they aren't a publisher by any reasonable standard so they don't need the 230 exemption in the first place.

Re: Looking back at how Signal works

#24

The only reason I don't use Signal is because it still uses your phone number for ID. What is even the point of verifying by number?

I suspect you are massively outnumbered by people who do use it because it integrates with their existing phone book, and is a drop-in replacement for the default SMS app. Without those things it'd be just another niche app for weird nerds.

Re: Looking back at how Signal works

#25
post #2

> how we think about concepts like privacy, security, and trust I was disappointed to see that a mobile number is needed and that this number is shown by default in groups. Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily. So I now prefer Telegram because at least it hides numbers in groups by default.

> Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily.

This is why I refuse to have Whatsapp and Signal, especially when you live in 3rd world country. It just take ONE SCREENSHOT of you saying something controversial in group chat, that screenshot goes viral to certain radical group, then your phone get spammed death threat.

Not to mention you can and will go to jail if those radical group sue you, thanks to draconian laws (UU ITE) here in Indonesia. You didn't get to jail because you said something that actually insulting someone, you get jailed because you are TRANSMITTING something that can be interpreted as an insult.

Re: Looking back at how Signal works

#26
post #6

Earlier quoted context omitted.

Burner sim to setup and throw away addresses this concern. Telegram, messages in plaintext on the server? Encryption that isn't open? Yeah telegram is a bit of a non-starter if you have these kinds of concerns as far as I'm aware.

In most European countries you need to submit your ID to get any sort of working SIM card.

If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway?

Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers.

As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up.

These other apps send your social graph to their servers, track and store metadata, don’t have encryption on by default, roll their own cryptography, or some combination of all of these things.

The phone number obsession on HN seems dumb to me - a meaningless thing for people to repeat and complain about that doesn’t actually matter so they can sound like they know what they’re talking about.

I don’t get it.

The only real criticism I have for signal is that they’re not federated so they’re vulnerable to shutdown. I think that’s okay though because we have Matrix working on that problem and having both is probably a good thing.

It’s also a thoughtful and intentional choice: https://signal.org/blog/the-ecosystem-is-moving/

The response from Matrix: https://matrix.org/blog/2020/01/02/on-privacy-versus-freedom

Re: Looking back at how Signal works

#27
post #16
post #6

Earlier quoted context omitted.

Burner sim to setup and throw away addresses this concern. Telegram, messages in plaintext on the server? Encryption that isn't open? Yeah telegram is a bit of a non-starter if you have these kinds of concerns as far as I'm aware.

Don't you have to keep paying for the sim, otherwise someone else might "steal" your account once your phone number gets reused?

Signal has an option to prevent this by locking the number with your PIN. This capability introduces plausible deniability that a phone number assigned to a SIM is actually associated with the number of a Signal account. Don't know if that matters legally or not.

Also the people doing shady things are generally hopping accounts regularly anyway.

Re: Looking back at how Signal works

#28

What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be downloaded if they do not add the backdoor in? Is there a workaround that will allow people to use it still? I've heard people mention locating the servers in other countries, but wouldn't the various App stores be bound by US law and still not allow them?

Signal’s official statement on the EARN It Act is here: https://signal.org/blog/earn-it/

Re: Looking back at how Signal works

#29

Earlier quoted context omitted.

In most European countries you need to submit your ID to get any sort of working SIM card.

If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers. As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up. These other apps send your social graph to their servers, track and store metadata, don’…

I feel comfortable with giving my Telegram username out to random people on the internet and posting it on my website because it doesn’t mean anything outside of Telegram. I wouldn’t post my phone number publicly.

Re: Looking back at how Signal works

#30

Earlier quoted context omitted.

In most European countries you need to submit your ID to get any sort of working SIM card.

If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers. As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up. These other apps send your social graph to their servers, track and store metadata, don’…

> roll their own cryptography

Signal did the same thing. They invented their own cryptographic algorithms. https://en.wikipedia.org/wiki/Double_Ratchet_Algorithm

And the social graph IS sent to servers by Signal. It's protected only by hashing (trivial to circumvent) and by the Intel SGX technology (a bit harder to circumvent, but I doubt that the US govt can't do it).

Post reply on HN