Signal Secure Backups
381–390 of 460 posts
Re: Signal Secure Backups
#382Earlier quoted context omitted.
What's your alternative? Keep doing voluntary donations and wait for rich people to throw 50mil at it again?
Personally, I eat the cost of self hosting a small matrix homeserver. For developing a commercial project, I don't have an alternative, because e.g. being upfront and saying that you will eventually screw over your users eventually, is not an option in this economy.
They didn't screw over anyone, for the past 8 years Signal was and remains free for everyone.
That service is not mandatory and didn't even exist before, so who exactly is screwed over?
Also, let me know where me and my friends can sign up on your particular matrix instance. What's your ToS anyway?
Re: Signal Secure Backups
#383Earlier quoted context omitted.
Personally, I eat the cost of self hosting a small matrix homeserver. For developing a commercial project, I don't have an alternative, because e.g. being upfront and saying that you will eventually screw over your users eventually, is not an option in this economy.
Signal ain't exactly commercial project. They didn't screw over anyone, for the past 8 years Signal was and remains free for everyone. That service is not mandatory and didn't even exist before, so who exactly is screwed over? Also, let me know where me and my friends can sign up on your particular matrix instance. What's your ToS anyway?
I also just learned that you can still backup without a subscription. That's great!
> Also, let me know where me and my friends can sign up on your particular matrix instance. What's your ToS anyway?
I said that was my personal solution and not an alternative to centralized platforms.
Re: Signal Secure Backups
#384Earlier quoted context omitted.
That's a weird and crappy arbitrary limitation when I could move an arbitrary amount of data between the two devices otherwise. It's the worst part of Signal.
It also does not work on Windows clients but errors out. Android and Linux are fine.
Re: Signal Secure Backups
#385Re: Signal Secure Backups
#386Earlier quoted context omitted.
Hi there, Signal dev here. The new backup format is indeed cross-platform. I've successfully restored backups on an iPhone, we're just stabilizing things :) If you're curious, the reason that Android's current local backups aren't cross platform is because it was made a long time ago, and it's literally a dump of all the sqlite statements that can be used to recreate Android's sqlite database (encrypted with a strong…
Hey, please get signal to release all the infrastructure automation code so someone could audit all of signal's infra and even fork if we ever needed to because of U.S. laws or so on. There's no reason to keep it secret and no reason why signal won't speak to this point. Thanks!
Re: Signal Secure Backups
#387Earlier quoted context omitted.
I'm confused, what's stopping you from using one of the backup services you already have on the file after it's done? Since Signal would backup to a file in your phone? Couldn't you just point your service to it and automatically sync every day for example?
The existing backup feature on Android doesn't do an incremental backup. I just ran a backup, and it was 850MB. So having my phone upload something of that size every day would be a bit annoying. Most of the major cloud storage platforms don't offer sync on Android. It's not really a good fit for how the filesystem is used by Android apps. I currently only do a Signal backup every few months (when I remember), and ma…
It may be inconvenient but this can be solved by using the features in the app to review your storage and save those thousands of images/audio/file sequestered inside the app out to the filesystem, then delete them from the app. You're not backing up "chats" you're backing up your image library being stored inside a chat app.
(yes I get the argument that you need to store them "in context" so save those and do the rest. there's no way 100% of that 850MB is "must have saved inside the app in chats" data, I'll bet $10 USD on it)
Re: Signal Secure Backups
#388> In the past, if you broke or lost your phone, your Signal message history was gone. this and completly useless multi-device support is the reason I don't use Signal... Telegram is not fully e2ee but it's way more convenient here. Even XMPP with PGP would be lightyears ahead.
>"Telegram is not fully e2ee but it's way more convenient here." Yeah convenient way to hand your data to a Russian oligarch. PGP has no forward secrecy and OTR in XMPP lacks future secrecy, multi-device support etc. Signal introducing end-to-end encrypted backups is exactly how Telegram should've done it decade ago.
Not everyone is paranoid at extremum.
> PGP has no forward secrecy and OTR in XMPP lacks future secrecy, multi-device support etc.
Have you ever considered that perfect-forward-secrecy is not needed by 99% of the people? And PGP (OX) can be enough of encryption that gives you multi-device support.
Btw. OTR is long dead…
Re: Signal Secure Backups
#389Earlier quoted context omitted.
Future secrecy? PGP does multirecipients natively, so any restrictions there would be in the XMPP client. I have actually tried out PGP over XMPP and is was nice once it was set up. Absolutely no state. If the message somehow gets to you it just works. Sucked when the keys expired though: * https://articles.59.ca/doku.php?id=pgpfan:expire PGP support on XMPP isn't really that great. Forward secrecy might be a nice ad…
>Future secrecy? Meaning --if-- when your keys get compromised the system recovers. PGP lacks even forward secrecy, meaning key compromise alone allows retrospective decryption of every message you've ever sent. OTR fixed that in... ...2004 https://dl.acm.org/doi/10.1145/1029179.1029200 Using PGP for secure communication in 2025 when you have option to use stateful E2EE over stuff like Signal is just bonkers.
Forcing your paranoidal perception "is just bonkers".
Re: Signal Secure Backups
#390Earlier quoted context omitted.
Future secrecy? PGP does multirecipients natively, so any restrictions there would be in the XMPP client. I have actually tried out PGP over XMPP and is was nice once it was set up. Absolutely no state. If the message somehow gets to you it just works. Sucked when the keys expired though: * https://articles.59.ca/doku.php?id=pgpfan:expire PGP support on XMPP isn't really that great. Forward secrecy might be a nice ad…
>Future secrecy? Meaning --if-- when your keys get compromised the system recovers. PGP lacks even forward secrecy, meaning key compromise alone allows retrospective decryption of every message you've ever sent. OTR fixed that in... ...2004 https://dl.acm.org/doi/10.1145/1029179.1029200 Using PGP for secure communication in 2025 when you have option to use stateful E2EE over stuff like Signal is just bonkers.
I think that the sort of people that use PGP are more interested in not having any messages compromised, ever, while still retaining access to their old messages in a secure way. Contrast that with, say, Signal where a forensic tool like Cellebrite will allow access to retained Signal messages[1]. Sure, most of that is due to the inherent insecurity of encrypted instant messaging over, say, encrypted email, but the users in the end don't care. They just want to be able to communicate privately.
[1] https://web.archive.org/web/20201210150311/https://www.celle...