Live data from Hacker News

You can change your number

signal.org

321–330 of 410 posts

Re: You can change your number

#321

It's been promised for years, but you still can't use a second phone as a linked/secondary device. As a result, it is literally impossible to have the same signal account on two iPhones. Since they already support using an iPad as a linked device, this would require little more than changing a flag and a recompilation. Maybe they have their reasons, but all they keep saying is 'soon'.

I think this is could be a rather complicated feature. It's easy if your second phone is just a linked device like iPad or desktop client, but I imagine this might be very confusing for users. Now you have two phones with signal installed, but one has fewer features and if you lose the main device, you're screwed. This is unexpected for most users.

On the other hand, if the second phone should have the same capabilities as the first one, key management suddenly gets extremely complicated. For instance, each device has to be able to revoke others; what happens if the revoked device had granted access to three other phones, are they revoked as well? Can a device revoke it's "parent" device? And so on. I imagine they avoid this while they can.

Re: You can change your number

#322

Earlier quoted context omitted.

> Well, if you're under attack, the 1-click link will reveal your identity to the first person to click on the link. That's true, but much easier to defend against. Since you can talk in a semi-synchronous manner and we can have a high _probability_ that the correct person will be be the one clicking on the link. So if it works: Godelski: Hey, let's chat on Signal, my link is signal.me/#one-time-code/jdjkerfe2r3rfwse…

> If it doesn't work: > Godelski: Hey, let's chat on Signal, my link is signal.me/#one-time-code/jdjkerfe2r3rfwseffre5ge5g > Thaumasiotes: Hey, link seems bad Sure, that interaction degraded gracefully. But your identity was also permanently compromised; it doesn't make sense to focus on how easy it was for me to say "hey, that didn't work". The reason the link went bad is that you disclosed your identity to someone…

> But your identity was also permanently compromised;

Only if I accepted the request. Clicking the link would presumably act the same way as a contact that you don't know. It asks before you accept. So I can wait till you respond.

Re: You can change your number

#323

Earlier quoted context omitted.

Discord has your full chat history in a conveniently searchable server side database. When new people join a channel in your discord server, they call see the full chat history so they can get fully caught up. You can use discord on multiple devices at the same time without the devices needing to directly sync with each other (because the state is stored on the server).

>When new people join a channel in your discord server, they call see the full chat history so they can get fully caught up. FYI there is a permission to disable this for a channel

The point is that's a feature that is possible because the chat history is stored on discord's servers.

Re: You can change your number

#324

This is fine, but signal still doesn't tell you when the person you're sending to has uninstalled signal. Instead, your messages go into ether and you think the person is ignoring you. It blows my mind they haven't prioritized this. https://github.com/signalapp/Signal-Android/issues/11164

Another pain point for me: when I send an SMS to someone, I expect to get replies on SMS not on Signal. Don't try to replace SMS. It's just really annoying to have half the conversation in the text messages app and the other half in Signal app.

Re: You can change your number

#325
post #48
post #12

Earlier quoted context omitted.

This website has an extremely awkward policy about titles that makes it so if you don't use the original title people get angry. The policy though just doesn't make sense, sadly, as the concept of titles is audience-specific (and even movies or books, which might feel more organized, sometimes have different audiences in different markets). FWIW, I did connect it together as I saw "(signal.org)" and that was sufficie…

It feels like the policy doesn't make sense because people only notice the cases they don't like. The cases where it works just fine, which are the vast majority, go unnoticed. That's by design, because it keeps things relatively smooth and happy, but it has this weird side effect that the annoyance cases build up like mercury in the 'policy' corner of the brain. Worst yet, the title edits that would annoy people if…

(I don't mind if you ignore this and I don't mind if you hide this or whatever. But I have thought about this specific issue in the context of this site quite a bit for almost a full decade now, and I feel like I have something interesting to contribute to your thought process given your response.)

FWIW, I think this is an unfair characterization of my complaint. Yes: I can and would (and once in a blue moon even do) make this complaint "as a user" of Hacker News, and you can certainly claim that I only notice the places where it is bad and am failing to notice all the places where it is good. I assure you: I understand this well enough to make your argument for you against me as a user and I agree we can bicker back and forth about whether this is a good idea without it mattering much. (I do think you are wrong there also, and I think that you are incorrectly associating one property of your platform you are tasked with defending as somehow being center of it, but that is again a separate argument we could have.)

However, what I think you are missing is that, when you are making arguments about content in general across this website and how most cases work, you are doing so from the vantage point of the moderator and have--in my eyes--become blind to the plight of publishers, some of whom run into this policy not every now and then but on every single post they are involved in due to their medium or other constraints of their audience. While on average it is maybe not so harmful, it disproportionately negatively affects some content that the readers of Hacker News do seem to greatly value more than other other content.

If you primarily publish changelogs or summary pieces (both of which can get a lot of play on Hacker News... but only for one subsection, not the whole article), publish to mailing lists or forums (where the titles are often under someone else's control or abnormal to use at all; we see a lot of great content these days on Twitter, and I would use it more often were it not for Hacker News and its title policy), or even technical articles on smaller blogs designed for closed audiences that would find a title for a "general" audience off-putting, you become permanently trapped in what to you is a disregarded corner case.

> On HN, we want the author of the article (or creator of a project) to have that power, not the submitter. That really is fundamental...

I am thereby very glad (though also quite a bit sad) you said this (and might have not bothered to respond had you not, btw), because I am an author making this argument first and foremost on behalf of my work as an author, and I feel this power dynamic issue deeply (on reddit, every now and then someone is egregious with an edit... and sure it might feel to you that that is a problem as you remember when it was a problem, but the vast majority it goes unnoticed ;P). And yet, I claim the policy as used and enforced isn't giving authors the power you might think they are being given, because--as I had indicated--the concept of titles is not anywhere near as well-defined as you make it out to be, and so as an author I think this policy is actually poorly designed.

About a decade ago I seriously got into a (quick, but so very memorable) argument with someone on Hacker News about the title of one of my own articles, one which--in its medium (Google+)--should not actually have a title. The article did have an official title that was used everywhere the article was linked, but it wasn't part of the article due to its medium. I think that was probably the first day I got angry at the policy, and it was "top of mind" as it was itself an article about policies (real name policies) that disproportionately affected certain users but are defended by moderators because it works for the majority... that was itself running into issues on another website due to a different policy with a similar kind of inherent design flaw falling into a similar blind spot (though of course the real name policy is much worse, I do want to make clear; that said, permanent unique user names are almost as bad, and Hacker News has those).

Over the years, then, I came to the point where I actually feel a need to give advice to people publishing content so it can be "Hacker News compatible", and that advice generally harms the person's "usual" audience :(. In particular: you need to publish things only on mediums that support titles (or if you must, add a title; yes: if you publish content on Twitter, if it might get linked by someone to Hacker News, I guess you need to dedicate part of your thread to give the thread a "title"), with "boring titles" for a general audience, with a separate top-level URL for each and every single topic.

BTW: I want to expand on the "boring titles" part of that. The best titles to choose in most contexts--and I am not saying that is true of Hacker News, as that is but one of many venues--are often "editorialized", because they are designed to be catchy and memorable and create a strong hook for the reader, who shares context that you have due to being part of your audience. And yet, Hacker News has a quirk in their policy whereby, if an upstream title is editorialized, then the author suddenly isn't supposed to be given the power. If you were consistent on that front I might find the policy more sympathetic.

As a local politician who pays careful attention to this kind of editorialization, I see this dynamic play out a lot with the local newspaper: the news articles in their print edition have highly editorialized titles designed to even be "misleading", while their online version?... not so much. That is because their audience in the physical paper is different from their audience on their site, the latter of which more often being random people linked to one post. One that was so memorable it has stuck with me for many years: online it said "UCSB Acquires Dublin’s, Precious Slut Property", while the paper copy said "UCSB Buys Precious Slut" (which doesn't even have the same meaning, but we get what they are after and it is funny).

And so after a full decade of dealing with this over and over again, I now find myself thinking about it every single time I publish anything anywhere. And it sucks: I spend most of my time on this website in this community (which I will note I absolutely do not believe is reliant on this policy to function any more than Facebook is reliant on a real name policy), and yet I also resent it deeply due to a rule that--at least in its exact implementation (which I bet could be fixable with minor changes)--almost no one in my circle thinks is a good idea: we just tolerate it because of network effect lock-in. I don't think I have published anything anywhere in the past decade without having to decide how to placate this policy. The best idea I have come up with so far is to use User-Agent detection tricks to give people on Hacker News a different title than anyone else, in my attempt to actually feel like I am in control as the author (which I clearly don't currently feel I have).

Re: You can change your number

#326
post #308

Earlier quoted context omitted.

There's always going to be tradeoffs when you're dealing with online anonymity. On the far anonymous end you've got 4Chan style anonymity, no permanent or any ID at all. Keeping track of individual people is nearly impossible. Conversations are chaotic and hard to follow. Pretty solid privacy. I guess the next step up would be per conversation/thread/group whatever ID, you trade a small amount of privacy for improved…

Also worth explicitly mentioning SSB-style cryptographic “implicit identity”. Connecting consists of exchanging public keys (which can be global per person, or compartmentalized per contact/conversation). Rather than a central server relating messages to the right peers, there’s a global feed where you attempt to decrypt everything and the ones which succeed are obviously addressed at you. The benefit here is that no…

I guess this gives you privacy (for the price of 7e9x-ing your compute/bandwidth effort), but only until you loose control of the private key. Then you get deanonymised completely, don't you?

Re: You can change your number

#327

Earlier quoted context omitted.

Signal stores your contact list on your phone (and not on their servers). Unlike other devices, people typically only have one active phone at any time, which means that your contact list on your phone can be your contact list on any linked device (its primary, they're secondary). If they didn't anchor to something that they knew you only had one of, then it's not clear which of your devices should be authoritative.…

Mobile telephone subscriptions passed global population 7 years ago.[1] More than 1 phone is not so unusual. End to end encrypted messages are harder than end to end encrypted contacts. Using phone numbers encourages people to use their phone's contacts app. Most people have theirs connected to Google or Apple. If they have other devices especially. [1] https://archive.fo/6je9z

To your first point, if you have two phone numbers then you're probably keeping them separate for a reason, and so their contacts should be kept separate by the app too.

As for your second: what are the "ends" you're taking about with this "end to end encrypted contacts" idea?

Certainly, a contact list has to be visible at the device--otherwise it's useless. Where else would you want it to be visible?

Re: You can change your number

#328
post #58

Earlier quoted context omitted.

Whatsapp can be configured to not save all the cat photos and memes to your library by default. You can still save the really good memes yourself if you want. Signal should just copy that feature. Also, what good is secure encryption if i have to give out my phone number?

> Also, what good is secure encryption if i have to give out my phone number? Actually how could you possibly deliver secure messaging if it doesn't work with simple identifiers you already have like your phone number? Everything should be secure, that's Signal's thesis. This reminds me of the people who were convinced HTTPS should only be used for "important" stuff that "needs to be secure" like banking and so it's…

> Actually how could you possibly deliver secure messaging if it doesn't work with simple identifiers you already have like your phone number? Everything should be secure, that's Signal's thesis.

It's tying my Signal identity to my phone number. To speak in US terms, you're safe from your comms being intercepted by the KGB, but now you're a person of interest to the CIA :)

Re: You can change your number

#329

It's been promised for years, but you still can't use a second phone as a linked/secondary device. As a result, it is literally impossible to have the same signal account on two iPhones. Since they already support using an iPad as a linked device, this would require little more than changing a flag and a recompilation. Maybe they have their reasons, but all they keep saying is 'soon'.

This is the feature I want most. I have my EDC and then I have a "if I drop it in the ocean, oops" phone.

The solution I use for this is group chats for my most important conversations, that have the other party and both of my phones in them.

Re: You can change your number

#330

I stopped using Signal, along with my adult tech-oriented friends, when we all had bad experiences migrating our accounts to new phones. That plus the phone number requirement, intrusive contacts integration, and the weird crypto side projects killed my interest in Signal entirely. My friends and I use Discord now.

Discord is not end to end encrypted, and Discord, along with whoever buys them, will receive the complete plaintext message history of all of your conversations with those friends.
Post reply on HN