This is overcomplicated to collect money IMHO. All modern OSs can happily backup app files. It is a well-solved problem. If you find this backup method not secure enough (as Signal authors do), fine, encrypt the backup with a special key, exactly as described in TFA, and leave the resulting archive in a location for my chosen phone OS to back it up as it would. All the goals are accomplished, and without charging me…
Signal Secure Backups
411–420 of 460 posts
Re: Signal Secure Backups
#412Earlier quoted context omitted.
Hi there, Signal dev here. You can sort of do this! You can restore on your new device, and while you will be unregistered on your old device, all of the data is still there. So if you see that something is amiss on the new device, you could re-register on your old device and you'd be right back where you started. This is actually one of the ways we test the feature with our own personal data.
Hey, i have a related question about this: I have an old iPhone that has all my old Signal messages still on it that I wasnt able to move with me when I switched to Android. Is there any way that I can use these new tools to move the old conversations on my iPhone over to my android phone without losing all the new messages that are on my android now? That is, I want to merge the two histories.
Re: Signal Secure Backups
#413Earlier quoted context omitted.
And if you lose your device your messages are compromised as well. Forcing your paranoidal perception "is just bonkers".
>paranoidal So either you're too young or too ignorant to have read the Snowden docs.
You are aware that majority of the communication happens via email, which has absolutely NO encryption and can go through whichever relay and noone gives a flying duck about it?
Again, for the overwhelming majority simple PGP encryption without pfs is more than enough. Not everyone works for government agencies and have to maintain perfect secrecy. If you do that in your private life then yes - you are paranoidal.
Re: Signal Secure Backups
#414Earlier quoted context omitted.
What's the specific use case that benefits from a shorter key? The only interaction I can ever see having with this key is putting it into and taking it out of my password manager....
The article specifically suggests writing the key down in a notebook. A single incorrect digit and the scheme fails much later in a way catastrophic to the user.
Re: Signal Secure Backups
#415Earlier quoted context omitted.
I was not talking about a security flaw. I was saying that maybe , Signal did not want to push their users to trust the Apple backup by default. Signal is a nonprofit foundation, it's not like they are trying to squeeze their users with their own secure backup.
We are unfortunately rehashing the same arguments from Github, nothing prevents Signal from distrusting Apple by default. But there is also nothing (except for some secret reason they refuse to elaborate) that prevents them from allowing users to actively chose to trust Apple. Except for their own internal reasons, that is. It's the user's data after all. The user should be able to control and access it. Sensible def…
Same as I said above: you are asking for a new feature. Their default is those 20 lines that "protect" the files. If they want to offer you a way to still enable it, someone has to do it. Someone has to work on the UX of it, maybe there is a need to explain to the users why it is less secure when this feature is enabled, and then there is work to do with the criticisms that will come next time someone shoots themselves in the foot because of this feature (because "Signal shouldn't have allowed that in the first place").
I know, you will say "it's not much". But everybody asks for their "small feature", and projects generally can't do everything that everybody asks them to do (and usually for free).
I find it totally valid if they choose that they won't offer features to lower their security, and instead they will work on features having sufficiently good security. Which in this case is the secure backup.
Re: Signal Secure Backups
#416Re: Signal Secure Backups
#417Earlier quoted context omitted.
While I understand (and share) your criticism, it does sound like they'll continue to support local backups: https://news.ycombinator.com/item?id=45171576 https://news.ycombinator.com/item?id=45172188
From your link, I wish they would answer this, and they've been asked numerous times, and to my knowledge have avoided the question (which is very concerning to me): >This is excellent news! Will there also be official documentation on the backup format, potentially even official tooling like signalbackup-tools[0] to access/parse backups offline? I'm asking because, having used Signal/TextSecure for 10 years now, my…
So you're like me :)
Greyson answered my question btw.
Re: Signal Secure Backups
#418Re: Signal Secure Backups
#419Why would you want to backup chat messages? To me they are worthless at least after a few months.
Re: Signal Secure Backups
#420Why would you want to backup chat messages? To me they are worthless at least after a few months.
I’m personally very glad that Signal finally implemented this. It’s been such a short sighted strategy to promote itself like a mass market messaging platform while not allowing people to keep, move and restore memories.
Since it’s opt-in, those who don’t want it don’t have to use it. They’re well served by the self-destructing message timers in chats.