Live data from Hacker News

Signal Secure Backups

signal.org

381–390 of 460 posts

Re: Signal Secure Backups

#382
post #360

Earlier quoted context omitted.

What's your alternative? Keep doing voluntary donations and wait for rich people to throw 50mil at it again?

Personally, I eat the cost of self hosting a small matrix homeserver. For developing a commercial project, I don't have an alternative, because e.g. being upfront and saying that you will eventually screw over your users eventually, is not an option in this economy.

Signal ain't exactly commercial project.

They didn't screw over anyone, for the past 8 years Signal was and remains free for everyone.

That service is not mandatory and didn't even exist before, so who exactly is screwed over?

Also, let me know where me and my friends can sign up on your particular matrix instance. What's your ToS anyway?

Re: Signal Secure Backups

#383
post #382

Earlier quoted context omitted.

Personally, I eat the cost of self hosting a small matrix homeserver. For developing a commercial project, I don't have an alternative, because e.g. being upfront and saying that you will eventually screw over your users eventually, is not an option in this economy.

Signal ain't exactly commercial project. They didn't screw over anyone, for the past 8 years Signal was and remains free for everyone. That service is not mandatory and didn't even exist before, so who exactly is screwed over? Also, let me know where me and my friends can sign up on your particular matrix instance. What's your ToS anyway?

Okay, I mistakenly thought that Signal was burning on investor money like any run-of-the mill startup, but apparently they manage to run on donations similar to Wikipedia.

I also just learned that you can still backup without a subscription. That's great!

> Also, let me know where me and my friends can sign up on your particular matrix instance. What's your ToS anyway?

I said that was my personal solution and not an alternative to centralized platforms.

Re: Signal Secure Backups

#384

Earlier quoted context omitted.

That's a weird and crappy arbitrary limitation when I could move an arbitrary amount of data between the two devices otherwise. It's the worst part of Signal.

It also does not work on Windows clients but errors out. Android and Linux are fine.

It does for me, sure why it errors out for you

Re: Signal Secure Backups

#386

Earlier quoted context omitted.

Hi there, Signal dev here. The new backup format is indeed cross-platform. I've successfully restored backups on an iPhone, we're just stabilizing things :) If you're curious, the reason that Android's current local backups aren't cross platform is because it was made a long time ago, and it's literally a dump of all the sqlite statements that can be used to recreate Android's sqlite database (encrypted with a strong…

Hey, please get signal to release all the infrastructure automation code so someone could audit all of signal's infra and even fork if we ever needed to because of U.S. laws or so on. There's no reason to keep it secret and no reason why signal won't speak to this point. Thanks!

What a ridiculous request.

Re: Signal Secure Backups

#387
post #238

Earlier quoted context omitted.

I'm confused, what's stopping you from using one of the backup services you already have on the file after it's done? Since Signal would backup to a file in your phone? Couldn't you just point your service to it and automatically sync every day for example?

The existing backup feature on Android doesn't do an incremental backup. I just ran a backup, and it was 850MB. So having my phone upload something of that size every day would be a bit annoying. Most of the major cloud storage platforms don't offer sync on Android. It's not really a good fit for how the filesystem is used by Android apps. I currently only do a Signal backup every few months (when I remember), and ma…

> I just ran a backup, and it was 850MB. So having my phone upload something of that size every day would be a bit annoying

It may be inconvenient but this can be solved by using the features in the app to review your storage and save those thousands of images/audio/file sequestered inside the app out to the filesystem, then delete them from the app. You're not backing up "chats" you're backing up your image library being stored inside a chat app.

(yes I get the argument that you need to store them "in context" so save those and do the rest. there's no way 100% of that 850MB is "must have saved inside the app in chats" data, I'll bet $10 USD on it)

Re: Signal Secure Backups

#388
post #142

> In the past, if you broke or lost your phone, your Signal message history was gone. this and completly useless multi-device support is the reason I don't use Signal... Telegram is not fully e2ee but it's way more convenient here. Even XMPP with PGP would be lightyears ahead.

>"Telegram is not fully e2ee but it's way more convenient here." Yeah convenient way to hand your data to a Russian oligarch. PGP has no forward secrecy and OTR in XMPP lacks future secrecy, multi-device support etc. Signal introducing end-to-end encrypted backups is exactly how Telegram should've done it decade ago.

Everything boils down to the thread model.

Not everyone is paranoid at extremum.

> PGP has no forward secrecy and OTR in XMPP lacks future secrecy, multi-device support etc.

Have you ever considered that perfect-forward-secrecy is not needed by 99% of the people? And PGP (OX) can be enough of encryption that gives you multi-device support.

Btw. OTR is long dead…

Re: Signal Secure Backups

#389
post #335

Earlier quoted context omitted.

Future secrecy? PGP does multirecipients natively, so any restrictions there would be in the XMPP client. I have actually tried out PGP over XMPP and is was nice once it was set up. Absolutely no state. If the message somehow gets to you it just works. Sucked when the keys expired though: * https://articles.59.ca/doku.php?id=pgpfan:expire PGP support on XMPP isn't really that great. Forward secrecy might be a nice ad…

>Future secrecy? Meaning --if-- when your keys get compromised the system recovers. PGP lacks even forward secrecy, meaning key compromise alone allows retrospective decryption of every message you've ever sent. OTR fixed that in... ...2004 https://dl.acm.org/doi/10.1145/1029179.1029200 Using PGP for secure communication in 2025 when you have option to use stateful E2EE over stuff like Signal is just bonkers.

And if you lose your device your messages are compromised as well.

Forcing your paranoidal perception "is just bonkers".

Re: Signal Secure Backups

#390
post #335

Earlier quoted context omitted.

Future secrecy? PGP does multirecipients natively, so any restrictions there would be in the XMPP client. I have actually tried out PGP over XMPP and is was nice once it was set up. Absolutely no state. If the message somehow gets to you it just works. Sucked when the keys expired though: * https://articles.59.ca/doku.php?id=pgpfan:expire PGP support on XMPP isn't really that great. Forward secrecy might be a nice ad…

>Future secrecy? Meaning --if-- when your keys get compromised the system recovers. PGP lacks even forward secrecy, meaning key compromise alone allows retrospective decryption of every message you've ever sent. OTR fixed that in... ...2004 https://dl.acm.org/doi/10.1145/1029179.1029200 Using PGP for secure communication in 2025 when you have option to use stateful E2EE over stuff like Signal is just bonkers.

If your keys get compromised then you would need new keys in any case.

I think that the sort of people that use PGP are more interested in not having any messages compromised, ever, while still retaining access to their old messages in a secure way. Contrast that with, say, Signal where a forensic tool like Cellebrite will allow access to retained Signal messages[1]. Sure, most of that is due to the inherent insecurity of encrypted instant messaging over, say, encrypted email, but the users in the end don't care. They just want to be able to communicate privately.

[1] https://web.archive.org/web/20201210150311/https://www.celle...

Post reply on HN