Live data from Hacker News

Removing SMS support from Signal Android (soon)

signal.org

401–410 of 649 posts

Re: Removing SMS support from Signal Android (soon)

#401
post #4

I completely disagree and am disappointed in this decision. One app on my phone to handle all my messages is easier than making a context switch per-contact. I also think it'll hurt the value proposition when getting people to join signal. Not overcomplicating the messaging scenario was a big winner to do that.

> all my messages is easier than making a context switch per-contact A user already has: - WhatsApp - Telegram - Facebook Messanger - Instagram that has direct messages - the good old email, or better, many of them - Microsoft Teams for company communications - Discord for communications with group of friends - the old SMS (that I didn't even know that in some parts of the world were still used, since I receive them…

Does anyone actually have all those? I certainly don't. I have Signal, Element, Telegram and I even think that's excessive. I can at least manage it, most RL contacts I know would not.

Re: Removing SMS support from Signal Android (soon)

#402

That sucks. The data fee argument makes no sense – you could just have a setting or warning or something for those who live in places where you have to pay for sms (I know every setting introduces complexity, but I that's got to be nothing compared to the level of engineering needed for all those other fancy features in Signal).

It's completely backwards for me. When I'm out of data for a month, SMSs still work. I've had to press and hold the send button to revert to SMS on many occasions.

What's even worse is that for you (and I) removal of SMS support will mean that out message history will suddenly be inconsistent as existing SMS messages will be removed.

Re: Removing SMS support from Signal Android (soon)

#403

Earlier quoted context omitted.

So when the server has the key, how can you say it's encrypted? I mean in context of signal we don't just talk about some form of transport encryption but e2e

It's various levels of encryption that are acceptable depending on your risk level. I'm mainly concerned about SMS spoofing and mass surveillance. iMessage protects against that. The only way the government can read your messages is by serving Apple with a warrant to obtain your iCloud backup. If I had a lower risk tolerance, I would disable iCloud backups to improve my security.

I don't think people are only concerned about the government, but rather the corporations that own your data (via storing the encryption key to use whenever they want, to look through whatever they want)

Re: Removing SMS support from Signal Android (soon)

#404

Earlier quoted context omitted.

> I have chat history that goes back years that it's often convenient to be able to search. > but instead the Signal backup just keeps getting larger and larger... One begets the other. > I'd love to be able to move it off the device If you don't want infinite history, set a conversation length limit. It is in the storage settings. If you want to backup messages on iOS go complain here[0]. For Android, you already ha…

Being rude to people by dismissing feature requests as invalid isn't helpful.

Sorry, I'm not trying to be rude. But I am confused at what they want. We have continued the discussion and the picture is clearer to me. Though I'm not sure exactly how Signal can help with it. It still appears to me that the user wants both reduced storage but to maintain search history, which are at odds with one another. Unless they expect Signal to store their history, which those expectations should be shot down because that is against their core philosophy. I did suggest a hack that might fit their needs (full history on desktop but not phone).

Re: Removing SMS support from Signal Android (soon)

#405

Earlier quoted context omitted.

People usually want both and that's what causes most people to ignore good tools.

Signal is in a weird place where they can do no right by users. It's a team of like 25 developers building extremely complex software criticized by people that don't understand security and trivialize everything. Reddit has a lot of evangelists that can't even program. Their community forums are a dumpster fire where users act like "my way or the world is going to end" (see the current username discussion. Most peopl…

What do you "Matrix is always better for every single purpose"? Are you saying that you really believe that, or characterizing others as saying that wrongly? I don't know much about either, but I thought both had somewhat new (less-tested) encryption algos (one is 'double-ratchet' or something? that recently has shown security vulnerabilities?)

Re: Removing SMS support from Signal Android (soon)

#407

Earlier quoted context omitted.

It makes me yearn for the days with Pidgin where I had IRC, Google Chat (XMPP back then), AOL and whatever else chat protocols all running through the same client. That's what is nice about signals implementation is it stands. It supports acting as the SMS default app on android and defaults to signal when it can.

This is why we are building https://www.beeper.com

FYI Part of your website is broken on Firefox for Android. (Broken layout, content not shown etc.)

Now to my actual question: How is Beeper compatible with the ToS of platforms like Instagram and Facebook that, to my knowledge, don't allow their users to use 3rd-party apps? Case in point: I recently wanted to use a FOSS 3rd-party messaging app for Instagram and my account got promptly banned.

Question 2: Do you support full message backups in a well-documented format?

Re: Removing SMS support from Signal Android (soon)

#408
post #405

Earlier quoted context omitted.

Signal is in a weird place where they can do no right by users. It's a team of like 25 developers building extremely complex software criticized by people that don't understand security and trivialize everything. Reddit has a lot of evangelists that can't even program. Their community forums are a dumpster fire where users act like "my way or the world is going to end" (see the current username discussion. Most peopl…

What do you "Matrix is always better for every single purpose"? Are you saying that you really believe that, or characterizing others as saying that wrongly? I don't know much about either, but I thought both had somewhat new (less-tested) encryption algos (one is 'double-ratchet' or something? that recently has shown security vulnerabilities?)

I'm saying that people put Matrix/Element in competition with Signal. These used to be dominating voices here. I do think the Matrix == Slack and Signal == Text philosophy has become more prominent now (the philosophy I prescribe to). But there are also major discussions about decentralization and users would suggest Matrix was more secure because of that even though at the time group chats were not encrypted (they are now) and E2EE was not enabled by default.

These are purely my observations of the discourse around Signal and should not be taken as a universal truth. Only my subjective reality.

I'm not aware of any major vulnerabilities in Matrix (but I'm not following) closely. I'm also not aware of any in Signal, which I know is frequently audited. There is an SGX attack, but it is often blown out of proportion (highly technical attack that requires an unlocked phone to be in the physical hands of the attacker).

Re: Removing SMS support from Signal Android (soon)

#409

Earlier quoted context omitted.

Doing so comes at a cost to privacy — by signal having a hosting server, even if the contents are E2EE, retrieving and storing these contents creates a metadata trail. I actually go over these drawbacks and tradeoffs in a recent blog post: https://cassieheart.substack.com/p/notes-on-e2ee

Who said anything about a hosting server? Why isn't there a simple option to export a conversation to local storage , encrypted or unencrypted, along with a warning that 'your conversation is now leaving the secure Signal zone.'

For starters, signal retains a conversation for the length of time you grant. That can be indefinite. The way it is retained is in a local storage database. It is intentionally guarded against export (although this is somewhat unavoidable with backup features on phones), so as to avoid companies like Cellebrite making it easy for LE to overstep their bounds and pull the message database when they take your phone. If you want some kind of export interface, your best option is a screenshot — signal does not take any action that threatens the mutual security between parties as explicitly agreed.

Re: Removing SMS support from Signal Android (soon)

#410

Earlier quoted context omitted.

Counter point most people think Telegram is e2ee secure messaging, but Telegram never said they were.

And that doesn't get clarified by UI that distinguishes between encrypted messages and SMS, because Telegram doesn't have such a thing to distinguish between. My point is that all of this is orthogonal to whether Signal can successfully make UI show users when they are sending encrypted messages vs unencrypted SMS. Most of the confusion you are citing is about whether an app does encryption or not, and that is a tota…

You’ve failed to make a distinction between e2e encryption and TLS encryption, how do you explain that in UI?
Post reply on HN