At the moment I share it with Google so I can share it with friends or family, which sucks.
Technology Preview: Signal Private Group System
81–90 of 153 posts
Re: Technology Preview: Signal Private Group System
#82Earlier quoted context omitted.
Why would group Signal messages (a drop-in replacement for group texts) be compared to Slack?
Why would a group communication tool be compared with another group communication tool? What's the part you're missing there? I have some friends I talk to in Signal groups. I have others I talk to in Slack. In both cases, the goal is the same: communicate privately with a known group of friends.
Signal's rationale is that if we actually secure this type of conversation, we can tell people not to accept insecure conversations because they're trading something you might want (actual privacy) for... not very much.
We've been here before on the Internet, at least twice now. When I was still (barely) a teenager Tatu Ylönen invented SSH and connecting to another machine was now secure instead of hopelessly insecure. And at almost the same time a bunch of people at Netscape invented SSL (which became TLS) and made the World Wide Web secure. It only took a few years for ordinary (relatively) people to _expect_ SSH not telnet and it took a bit longer for HTTPS but in both cases we got to a place where secure was the default and expected condition.
Re: Technology Preview: Signal Private Group System
#83What I really want from Signal is the ability to use it as an application transport. In particular, I want to authorise certain people to request my phone's location. At the moment I share it with Google so I can share it with friends or family, which sucks.
Re: Technology Preview: Signal Private Group System
#84Earlier quoted context omitted.
True. On the other hand, there are some aspects in which Signal will never be as safe as Matrix. The big one is SMS verification. If someone loses their keys and has to reauthenticate over SMS, Signal notifies their conversation partners, but legitimate users do this all the time (in part because Signal lacks good key migration mechanisms), so said partners usually don’t see this as suspicious and often don’t bother…
It seems that Signal is working on adding usernames: https://community.signalusers.org/t/signal-introducing-usern...
https://twitter.com/moxie/status/1174047779267604480
In theory they could keep using the native contact list and just stuff Signal usernames in there; iOS does have the APIs to do that, and I'd assume Android too.
Re: Technology Preview: Signal Private Group System
#85Earlier quoted context omitted.
I think I'm an exception in this instance, but I don't understand what value there is in message history. How often do you find yourself reminiscing by going back through a messaging log? If there are photos that should be kept then there are other ways to back them up. Is there valuable context in the conversation that was had around the delivery of the photo? Are messages backed up and restorable for other messagin…
Yes, you are an exception. Just look at how popular books of letters are: https://www.goodreads.com/list/show/100260.Best_Books_of_Let... Or look at how popular "Letters of Note" is: https://twitter.com/lettersofnote Conversation is connection.
There are tiers of conversation. Letters between famously literate people or during times of war have a value proposition on an entirely different scale to group chat messages.
It's about the value that the individual assigns to the content of the conversation (this is almost arguing against my stated position). But if that conversation is never re-visited anyway, the value is the status of Schroedinger's cat.
What content that is worthy of "Letters of note" is a) to be found in chat history? b) not already been saved elsewhere due to it's noteworthiness? c) going to be re-discovered by going back through hundreds or thousands of lines of conversation text on a mobile device screen? d) worth trawling back through hundreds or thousands of lines of conversation text on a mobile device screen?
Again, I'm aware that I'm an exception, but I think it's potentially natural human laziness to want to keep 'everything' in case it might be useful or valuable in a few years' time. Electronic hoarding.
I've recently setup an instance of NoteSelf to more easily track links to interesting articles and my own thoughts and ideas and various other things that I think are worthy of keeping. This is my form of targeted electronic hoarding. I'm in control of it, and it's robust enough to survive a mobile device theft, breakage, or some other kind of failure. Prior to that I write things down in journals, or other systems, some of which have been totally lost, but I don't find myself missing it or 'wondering what could have been'.
It feels as if the point that I'm trying to make is that mindful archiving is a better solution than to just 'keep all the things' - for me, primarily, it's the far improved wheat / chaff ratio.
Conversation is connection. Yes. But recorded conversation is just a reminder of connection, not the connection itself. I think my argument falls down when it comes to someone that's passed away, and keeping their flame alive to some extent. I don't work like that, but I wouldn't expect it of others.
Re: Technology Preview: Signal Private Group System
#86Very nice (seriously!). Now, please let people use the platform without needing a valid phone number. The one major issue I have is that. Phone numbers are the new SSN, just like SSN is being misused by traditional businesses, phone numbers are also misused thse days (due to how you generally can be tracked down to a physical area for antifraud and how "everyone" has a cell phone) to uniquely identify users. I don't…
https://telegram.org/faq#q-if-someone-finds-me-by-username-m...
Re: Technology Preview: Signal Private Group System
#87Earlier quoted context omitted.
Personally, I'm happy to lose the data. I found it odd that with both phones and the SIM on the desk in front of me, I couldn't figure out how/if I could vouch for my key changing in any way. Needing to say I have a new phone just trust me largely defeats the purpose.
If you are on an Android device you can export an encrypted backup and scan a QR code / type in the password to the encrypted archive to transfer messages / group memberships with only a safety number change in most cases. https://support.signal.org/hc/en-us/articles/360007059752-Ba... No dice for iOS unfortunately.
Re: Technology Preview: Signal Private Group System
#88> Note that a user who has acquired a group’s GroupMasterKey and then leaves the group (or is deleted) retains the ability to collude with a malicious server to encrypt and decrypt group entries. We deem this risk acceptable for now due to the complexities in rapid and reliable rekey of the GroupMasterKey.
Does this mean that the server and a deleted user can always collude to get the deleted user readded to the group? Also, is there no provable audit trail of who added or deleted whom? Unless I'm misunderstanding, it seems like deleting a user is therefore enforced only via server trust, but please correct me if I'm wrong.
Re: Technology Preview: Signal Private Group System
#89Earlier quoted context omitted.
Yes, you are an exception. Just look at how popular books of letters are: https://www.goodreads.com/list/show/100260.Best_Books_of_Let... Or look at how popular "Letters of Note" is: https://twitter.com/lettersofnote Conversation is connection.
I'm going to keep digging this hole for myself because I think there is some amount of treasure to be found. I'm also interested to see how far out of touch I am. There are tiers of conversation. Letters between famously literate people or during times of war have a value proposition on an entirely different scale to group chat messages. It's about the value that the individual assigns to the content of the conversat…
Second, time helps ("we were talking about it around this time of year").
Third, you don't necessarily know how valuable the conversation is when you first have it.
And fourth, pictures and video and similar.
> It feels as if the point that I'm trying to make is that mindful archiving is a better solution than to just 'keep all the things'
I used to carefully archive every email in an appropriate folder. Now I only have one folder, "Archive", which contains all mail, and I use search to find what I'm looking for. (Search is all I used back when I had folders, too.) That requires far, far less work at the time of receiving a message.
Consider the time taken to carefully file something away, the difficulty of keeping such things organized manually, the ease of just automatically storing everything organized by time and people, and the likelihood of you successfully predicting in advance what you'll want later.
Re: Technology Preview: Signal Private Group System
#90I noticed this from the paper: > Note that a user who has acquired a group’s GroupMasterKey and then leaves the group (or is deleted) retains the ability to collude with a malicious server to encrypt and decrypt group entries. We deem this risk acceptable for now due to the complexities in rapid and reliable rekey of the GroupMasterKey. Does this mean that the server and a deleted user can always collude to get the d…
No, the members of the group would be able to see that the deleted user is back, or whatever else has happened to the list. Signal's server isn't responsible for deciding who gets the group messages, only for storing the agreed list in encrypted form. So members don't need to trust that the server did as it was told.
Certainly if you have a group where you suspect a member of colluding with the Signal server to betray the group you should probably NOT remove that member but instead take the extra trouble to explicitly form a new group (without that member obviously).