Live data from Hacker News

Technology Preview: Signal Private Group System

signal.org

31–40 of 153 posts

Re: Technology Preview: Signal Private Group System

#31
post #6

Earlier quoted context omitted.

It's really an engine for revealing people's true preferences for messaging, which, for many people, tend to be that they want all the ergonomics of Slack a lot more than they want cryptographically sound secure messaging. What's hopeful in all this is that Signal is, slowly, catching up. Slack can roll out new features just by assigning a couple developers to it, and Signal has to coordinate new cryptographic resear…

My biggest annoyance with Signal is that getting a new phone ends up wiping out all conversation history with apparently no way to transfer it. This loss of user data is not advertised well enough up front, and leaves users feeling tricked. In many contexts loss of user data is an even bigger sin than weak security.

Personally, I'm happy to lose the data. I found it odd that with both phones and the SIM on the desk in front of me, I couldn't figure out how/if I could vouch for my key changing in any way.

Needing to say I have a new phone just trust me largely defeats the purpose.

Re: Technology Preview: Signal Private Group System

#32
post #2

Again, in the theme of "features every group messaging system had already, but Signal didn't, because they hadn't figured out a way to implement it without turning Signal's central servers into a database of who's talking to who about what". Signal didn't even have user profiles until recently, for the same reason. Here, they've slightly expanded the state of the art in MAC-based anonymous credentials to accomplish t…

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

Yes, there are a lot of us out there who use Signal and have this single missing feature as our largest pain point. My previous phone (iOS) would have been donated or sold to someone who could make better use of it, had I been able to actually get years and years of Signal conversations (with media) and memories out of it. But I can't (without prohibitive amounts of manual work), so it lies unused in a drawer waiting for the day I might.

The Signal devs don't discuss their roadmap, as is their prerogative. The result is of course that no one knows if such features are even planned, let alone worked on. Half a decade (?) of sad and frustrated forum posts and GitHub issues attest to that. I scan through them from time to time to see if there's any word.

But! There was actually a tweet from Moxie just a few weeks ago in a thread started by Matthew Green, I think, hinting that they might be working on it. It did make me a little happier. But yes, five years is a long time to wait for this feature, and we don't know for sure if or when it's coming. Me, amidst all the frustration I am very happy for the software they are giving me almost for free (I've donated a little bit).

By the way, Josh, props to you for your patience and professionalism in the debian-devel thread about librsvg the other day.

Re: Technology Preview: Signal Private Group System

#33
post #16

Earlier quoted context omitted.

You either have to trust the server operator not to keep logs, or assume they are keeping logs and _do_ know what groups you’re in. In either case, what is this fancy crypto scheme actually buying you?

The fancy crypto is what allows them not to (effectively) keep those logs in the first place. If you build this feature without the fancy crypto, then even if you say you're not logging this stuff, you (effectively) are, because your system depends on durable access to that metadata in order to function. This is, for instance, the major security difference between Signal and Wire. One strong indication you have that…

To verify the claim that my group message content is protected, I can examine the Signal client. I don’t have to trust the server operator whatsoever; I can independently confirm there is no way for them to see the content of my messages.

In contrast, I cannot verify this new claim that my group memberships are protected. I have to trust them.

I think you are basically saying: ‘well, they built all this crypto that is only useful if you believe they’re not logging, so I believe they’re not logging.’

Re: Technology Preview: Signal Private Group System

#34
post #32

Earlier quoted context omitted.

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

Yes, there are a lot of us out there who use Signal and have this single missing feature as our largest pain point. My previous phone (iOS) would have been donated or sold to someone who could make better use of it, had I been able to actually get years and years of Signal conversations (with media) and memories out of it. But I can't (without prohibitive amounts of manual work), so it lies unused in a drawer waiting…

> Me, amidst all the frustration I am very happy for the software they are giving me almost for free (I've donated a little bit).

Complete agreement. I'm glad for the work going into Signal, both in development and in research.

> By the way, Josh, props to you for your patience and professionalism in the debian-devel thread about librsvg the other day.

(OT)

The other year? That conversation took place late last year. Thank you, though.

Re: Technology Preview: Signal Private Group System

#35

Earlier quoted context omitted.

My biggest annoyance with Signal is that getting a new phone ends up wiping out all conversation history with apparently no way to transfer it. This loss of user data is not advertised well enough up front, and leaves users feeling tricked. In many contexts loss of user data is an even bigger sin than weak security.

Personally, I'm happy to lose the data. I found it odd that with both phones and the SIM on the desk in front of me, I couldn't figure out how/if I could vouch for my key changing in any way. Needing to say I have a new phone just trust me largely defeats the purpose.

If you are on an Android device you can export an encrypted backup and scan a QR code / type in the password to the encrypted archive to transfer messages / group memberships with only a safety number change in most cases.

https://support.signal.org/hc/en-us/articles/360007059752-Ba...

No dice for iOS unfortunately.

Re: Technology Preview: Signal Private Group System

#36
post #32

Earlier quoted context omitted.

Yes, there are a lot of us out there who use Signal and have this single missing feature as our largest pain point. My previous phone (iOS) would have been donated or sold to someone who could make better use of it, had I been able to actually get years and years of Signal conversations (with media) and memories out of it. But I can't (without prohibitive amounts of manual work), so it lies unused in a drawer waiting…

> Me, amidst all the frustration I am very happy for the software they are giving me almost for free (I've donated a little bit). Complete agreement. I'm glad for the work going into Signal, both in development and in research. > By the way, Josh, props to you for your patience and professionalism in the debian-devel thread about librsvg the other day. (OT) The other year? That conversation took place late last year.…

Oh, wow. I stumbled over the thread just the other day and mechanically just read the month and day... Since it was November I somehow assumed it was recent without reacting. Thanks for the correction! Well, belated props to you then. =o)

Re: Technology Preview: Signal Private Group System

#37
post #16

Earlier quoted context omitted.

The fancy crypto is what allows them not to (effectively) keep those logs in the first place. If you build this feature without the fancy crypto, then even if you say you're not logging this stuff, you (effectively) are, because your system depends on durable access to that metadata in order to function. This is, for instance, the major security difference between Signal and Wire. One strong indication you have that…

To verify the claim that my group message content is protected, I can examine the Signal client. I don’t have to trust the server operator whatsoever; I can independently confirm there is no way for them to see the content of my messages. In contrast, I cannot verify this new claim that my group memberships are protected. I have to trust them. I think you are basically saying: ‘well, they built all this crypto that i…

No, what I'm saying is that without the cryptographic protections, a messaging provider can't claim not to be logging, because their serverside logic requires the log.

Prior to doing this cryptographic work, Signal simply went without having these features at all.

Re: Technology Preview: Signal Private Group System

#38
post #29

Earlier quoted context omitted.

My biggest annoyance with Signal is that getting a new phone ends up wiping out all conversation history with apparently no way to transfer it. This loss of user data is not advertised well enough up front, and leaves users feeling tricked. In many contexts loss of user data is an even bigger sin than weak security.

What's ironic here is that in the adversarial setting the application is designed for, unexpected retention of user data (on end-user devices) is a sin.

That’s fine. But Signal should then advertise itself as unsuitable for general-purpose communication, primarily relevant when someone is specifically worried about adversaries reading the communication.

I can see how this makes sense for journalists, dissidents, diplomats, criminals, corporate executives, etc., but if data is under threat of disappearance, regular people should be warned away and told to use something else for day-to-day communication.

Re: Technology Preview: Signal Private Group System

#39
post #35

Earlier quoted context omitted.

Personally, I'm happy to lose the data. I found it odd that with both phones and the SIM on the desk in front of me, I couldn't figure out how/if I could vouch for my key changing in any way. Needing to say I have a new phone just trust me largely defeats the purpose.

If you are on an Android device you can export an encrypted backup and scan a QR code / type in the password to the encrypted archive to transfer messages / group memberships with only a safety number change in most cases. https://support.signal.org/hc/en-us/articles/360007059752-Ba... No dice for iOS unfortunately.

I think that's the opposite of what I want? I want to inform people of the new safety number using the old channel and purge all data like a good user.

In this respect a keybase like model makes more sense to me.

Re: Technology Preview: Signal Private Group System

#40

Earlier quoted context omitted.

My biggest annoyance with Signal is that getting a new phone ends up wiping out all conversation history with apparently no way to transfer it. This loss of user data is not advertised well enough up front, and leaves users feeling tricked. In many contexts loss of user data is an even bigger sin than weak security.

Personally, I'm happy to lose the data. I found it odd that with both phones and the SIM on the desk in front of me, I couldn't figure out how/if I could vouch for my key changing in any way. Needing to say I have a new phone just trust me largely defeats the purpose.

I’m talking about transferring archival data from one phone I own to a different phone I own.

This is different from whether other users are told that my security keys just changed.

Post reply on HN