> Losing it means losing access to your backup permanently, and Signal cannot help you recover it. Oof... That's going to be tough to explain to normal users. "Sorry you've been paying for backups all this time, but you should have written down this code that you will only ever use once somewhere safe and remembered where it is. All your data is gone." Not the right security trade-off for most people.
The implementation feels uncharacteristically crude for Signal. Instead of seamless protections, you just get handed 64 characters you’re told to “store securely.” That’s not realistic: most people will screenshot it, and those screenshots will end up in unencrypted cloud backups.
Signal Secure Backups
311–320 of 460 posts
Re: Signal Secure Backups
#312I can't believe Signal is doing this. Signal is known for its cutting-edge cryptographic protocol, but this feature has the effect of throwing that out the window and replacing it with a single static key. If a device with this enabled goes through the whole advanced protocol to receive a message (double ratcheting etc), then turns around and uploads it back to Signal’s servers with a static key, isn't that a roundab…
You (and Signal) can't control how the recipient handles your messages if you're not using disappearing. They could be copying and pasting your messages or taking screenshots. I don't see how the backup feature is any different.
Re: Signal Secure Backups
#313What is the UX for the 64 characters key? Does it at least use a wordlist (e.g. like BIP 39)?
Re: Signal Secure Backups
#314This looks brilliant. I just hope they make it easy to do test restores. In particular, I want to test restore without perturbing my main device. Let me restore using the secret key on a new device. When I install Signal on a computer it won't show me message history. Will backups allow me to view _all_ my message history on a computer? A big screen is very helpful for browsing lots of messages.
Re: Signal Secure Backups
#315Earlier quoted context omitted.
Giving people a 64-character key also feels uncharacteristically crude for Signal. It's not realistic to hand people 64 characters and tell them to “store this securely.” Most people will screenshot it, and those screenshots will end up in unencrypted cloud backups. That's less of a problem when the backups are local, because access to the local backups implies access to the device, but if the backups are in the clou…
I get your point but is a large set of dictionary words or 5-digit numbers (see the current backup passphrase) so much better? At the end of the day, recording entropy will always be cumbersome and there is no way around it. > Most people will screenshot it, and those screenshots will end up in unencrypted cloud backups. At least on Android apps can disable screenshots, though, which might be a simple way to deter pe…
Yes, much easier to type
Re: Signal Secure Backups
#316> In the past, if you broke or lost your phone, your Signal message history was gone. this and completly useless multi-device support is the reason I don't use Signal... Telegram is not fully e2ee but it's way more convenient here. Even XMPP with PGP would be lightyears ahead.
>"Telegram is not fully e2ee but it's way more convenient here." Yeah convenient way to hand your data to a Russian oligarch. PGP has no forward secrecy and OTR in XMPP lacks future secrecy, multi-device support etc. Signal introducing end-to-end encrypted backups is exactly how Telegram should've done it decade ago.
PGP does multirecipients natively, so any restrictions there would be in the XMPP client.
I have actually tried out PGP over XMPP and is was nice once it was set up. Absolutely no state. If the message somehow gets to you it just works. Sucked when the keys expired though:
* https://articles.59.ca/doku.php?id=pgpfan:expire
PGP support on XMPP isn't really that great. Forward secrecy might be a nice addition, even if it was semi-manual. There are compatibility problems between clients for encrypted media. You don't end up with an always encrypted archive like you do with email, but that could be considered an inherent weakness of instant messaging...
Re: Signal Secure Backups
#317I can't believe Signal is doing this. Signal is known for its cutting-edge cryptographic protocol, but this feature has the effect of throwing that out the window and replacing it with a single static key. If a device with this enabled goes through the whole advanced protocol to receive a message (double ratcheting etc), then turns around and uploads it back to Signal’s servers with a static key, isn't that a roundab…
Re: Signal Secure Backups
#318Hi @greysonp > Once you’ve enabled secure backups, your device will automatically create a fresh secure backup archive every day, replacing the previous day’s archive. So IIUC backups will not be incremental and I will have to re-upload my 15 GB backup archive every day? Why is that? What's the security risk here? (Obviously I'm not suggesting encrypting & uploading each message & media file individually but splittin…
Hi there! > So IIUC backups will not be incremental Nope! It's very much incremental :) At least the media is. There's one blob of containing all of your messages+metadata which does have to be re-uploaded every night, but for most people that's gonna be somewhere in the low-tens of MB. Your attachments are uploaded incrementally one at a time, typically as they're sent/received, so you usually don't even have to wai…
That's great to hear, thanks so much!
Re: Signal Secure Backups
#319Earlier quoted context omitted.
Really? Ever since Android devices ceased to be regular USB storage devices and switched to MTP, this has never worked well for me. MTP is incredibly slow.
What method do you find to be faster?
Re: Signal Secure Backups
#320> If securely back up all* of your text messages and the last 45 days’ worth of media for free. > If you want to back up your media history beyond 45 days, as well as your message history, we also offer a paid subscription plan for US$1.99 per month. So after so many years of having a serious design flaw this poor substitute of a backup where you can't even save all your text for free is all they've managed to come u…
I guess the reason WhatsApp lets you save all your text for free is they are making money off sucking up your data. I think ultimately this model will win, but I sympathise with Signal's approach.