Live data from Hacker News

Default disappearing messages

signal.org

81–90 of 187 posts

Re: Default disappearing messages

#81
post #67

Earlier quoted context omitted.

Secure systems are all alike; every insecure system is insecure in its own way. A messenger that has E2E encryption might not be secure, but a messenger that doesn't have E2E encryption is definitely insecure. Not caring about your messages being read, or being willing to trust the operator of the service, is fine, but in that case I struggle to see why you'd pick Telegram, given that their whole selling point was ab…

> A messenger that has E2E encryption might not be secure, but a messenger that doesn't have E2E encryption is definitely insecure. It is secure for my purposes. Throwing away threat models and the meaning of secure and encrypted just to be able to define something that competes for attention as "not secure" and "not encrypted" (from other threads) isn't very high level, it is basic framing. edit: > Not caring about…

> Throwing away threat models and the meaning of secure and encrypted just to be able to define something that competes for attention as "not secure" and "not encrypted" (from other threads) isn't very high level, it is basic framing.

It's basic, but it's valid. I was responding to all your "It doesn't matter if it is E2E-encrypted if xyz" points, which are faulty logic; if whether it's E2E-encrypted matters in your threat model, then whether it's E2E-encrypted still matters in your threat model even if other aspects of the system are secure.

> Remember, when Telegram came around WhatsApp was un-encrypted. Not point-to-point encrypted, just encoded. You didn't need to know or crack a key, you just needed toknow the protocol.

Citation? I don't remember it happening that way at all; Telegram marketed themselves by attacking WhatsApp on a couple of minor vulnerabilities in side features like video handling (which was legitimate in some ways, but extremely hypocritical given the bigger weaknesses in Telegram's own implementation). If message text was readable that would have been a much bigger deal.

Re: Default disappearing messages

#82
post #80

Sorry for the confused rant that follow (Hopefully HN will auto-delete it in 42 hours ): The variable duration of the message adds one additional layer of complexity to the already messy game of social communication. It's not like a session at the park or a phone call that once you close it, it's over. I already had trouble understanding the concept of ephemeral message, like you say something to me but expect me to…

I think you're making a wrong comparison here. Disappearing messages is not akin to forcing the other party to take memory-suppressant drugs (wtf?), it's more akin to asking them not to record your conversation.

If you remember something in your brain, you have recorded it. Electronic records are only different in scale/capability and guaranteed perfect recall.

Re: Default disappearing messages

#83
post #80

Sorry for the confused rant that follow (Hopefully HN will auto-delete it in 42 hours ): The variable duration of the message adds one additional layer of complexity to the already messy game of social communication. It's not like a session at the park or a phone call that once you close it, it's over. I already had trouble understanding the concept of ephemeral message, like you say something to me but expect me to…

I think you're making a wrong comparison here. Disappearing messages is not akin to forcing the other party to take memory-suppressant drugs (wtf?), it's more akin to asking them not to record your conversation.

Not recording the conversation would be something akin a no-log session, or the view-once message they already have.

Semantically here it's like the self destruct message they send in Impossible Mission but with a very long timer, it's a new primitive I'm not used to handled yet.

A garbage-collector for your memories like I am inviting the Langoliers into my phone.

Re: Default disappearing messages

#84
post #61

Earlier quoted context omitted.

My view is exactly the opposite. Having suffered from the "I thought you said..." problem (where other parties recall a verbal conversation differently than me, out of forgetfulness on either of our parts or to serve their interests) for so much of my life I welcome these ubiquitous devices that augment my memory and provide black and white clarity to what was actually said. I have no nostalgia for lossy recall and t…

When do you ever go back to double-check something someone has said, without them claiming they said something different? If you only do it to prove you were right, stop doing that, it's not a good look.

> If you only do it to prove you were right, stop doing that, it's not a good look.

It seems fine to me if someone makes an error in recollection to correct them (if it's about something material). I mean there are more and less nice ways to do it, and you don't necessarily want to do it about everything, but it seems like a very odd rule of thumb to me to say "it's not a good look". Maybe you have a particular personality archetype/pathological behaviour in mind that I'm not familiar with?

Is it about the awkward relational-imbalance that might be created between people who check records and people who can't be bothered? (the former able to use their spare time to reduce the status of the other party within the relationship, who lack the time/stamina/desire to reciprocate).

I know some super-pedantic people, who might engage in such correction pathologically. With those friends I actively resist ever making any distinction/categorisation that might be used against me in the future. It's a real arms race!

Re: Default disappearing messages

#85
post #61

Earlier quoted context omitted.

When do you ever go back to double-check something someone has said, without them claiming they said something different? If you only do it to prove you were right, stop doing that, it's not a good look.

> If you only do it to prove you were right, stop doing that, it's not a good look. It seems fine to me if someone makes an error in recollection to correct them (if it's about something material). I mean there are more and less nice ways to do it, and you don't necessarily want to do it about everything, but it seems like a very odd rule of thumb to me to say "it's not a good look". Maybe you have a particular perso…

> It seems fine to me if someone makes an error in recollection to correct them (if it's about something material).

What sort of error? The GP said "where other parties recall a verbal conversation differently than me", and what's the benefit there? You have two differing views of a conversation, you can say "oh well I meant X" and move on. There's no benefit in figuring out who got it wrong just to apportion blame. Just leave it ambiguous and clarify the intention when you realize there was a misunderstanding.

> Maybe you have a particular personality archetype/pathological behaviour in mind that I'm not familiar with?

It's nothing pathological, some people just tend to want to go back to prove they were right, but proving the other person wrong doesn't tend to be productive.

Re: Default disappearing messages

#86
post #81

Earlier quoted context omitted.

> A messenger that has E2E encryption might not be secure, but a messenger that doesn't have E2E encryption is definitely insecure. It is secure for my purposes. Throwing away threat models and the meaning of secure and encrypted just to be able to define something that competes for attention as "not secure" and "not encrypted" (from other threads) isn't very high level, it is basic framing. edit: > Not caring about…

> Throwing away threat models and the meaning of secure and encrypted just to be able to define something that competes for attention as "not secure" and "not encrypted" (from other threads) isn't very high level, it is basic framing. It's basic, but it's valid. I was responding to all your "It doesn't matter if it is E2E-encrypted if xyz" points, which are faulty logic; if whether it's E2E-encrypted matters in your…

> It's basic, but it's valid.

I wrote basic framing.

It is a valid and effective marketing technique but not something you should rely on in a technical discussion.

> if whether it's E2E-encrypted matters in your threat model, then whether it's E2E-encrypted still matters in your threat model even if other aspects of the system are secure.

Then we agree :-)

I've been communicating over email, irc and lots of other channels that were not E2E-encrypted for years and I still have to.

I'll have to live with the fact that my bank, my government and a number of others have unencrypted, realtime access to far more sensitive data than Telegram.

The fact that someone can read my Telegram messages consisting of perfectly innocent photos is way down on my list as long as they who do it has a lot to lose by doing it ;-)

(I.e. if you had access it would be a problem. If any serious agency has access they will never use it against me because then they give away that they have the capability. In the same way Telegram has everything to lose by letting employees snoop. Same as Google: I do not fear them snooping my mail, I fear their AI will kill my account and no one will tell me why.)

> Citation? I don't remember it happening that way at all; Telegram marketed themselves by attacking WhatsApp on a couple of minor vulnerabilities in side features like video handling (which was legitimate in some ways, but extremely hypocritical given the bigger weaknesses in Telegram's own implementation). If message text was readable that would have been a much bigger deal.

I've followed Telegram quite closely so I am fairly certain about their marketing message early on. As you can see it also put them in a bad light so thats something too.

I've been unable to find references for the point about just being encoded, not encrypted so take that with a grain of salt for now. Some evidence can probably be found in an old unofficial client repo or someone who wrote one of those can confirm.

I might be wrong but remember this was back in 2009. It was a whole different world back then.

I used and liked WhatsApp despite all this because just like with Telegram perfect security didn't matter for the kind of communication I have on messengers back then either.

Re: Default disappearing messages

#87
post #6

Earlier quoted context omitted.

This is one of the biggest things that stops me from using Signal. I don't have a phone number really any more (I'm a digital nomad, and pick up regional sims) I'm not really interested in the disappearing message either if I wanted that I could just use Slack Free edition :troll:. In all seriousness though, my messages are part of my memory. They're shared experience with my partner and a record of decisions. I unde…

Honestly you might want to look into Google Fi (Even though google is evil and just being under their umbrella makes me consider leaving) since their plans automatically work in most countries [1]. I want to find a better cell plan with a company I am not ethically opposed to but Fi is so good that it makes it really really hard to beat. [1]: https://fi.google.com/about/international-rates/

Google Fi has actually been reasonably useful despite the fact that I can't get it to work because I'm not in the US. They have a web messaging interface that I can collect 2FA from.

I avoid phone based 2FA where possible, but the few that I have are sent there.

But it's not really for non-US, and they've really started cracking down on people that use it exclusively internationally.

Which is a real shame. It's absolutely the service I want/need as digital nomad.

Re: Default disappearing messages

#88
post #54

Earlier quoted context omitted.

If you don't mind me asking, how do you handle 2FA and companies that require a phone number(eg. my bank)? Do you have to constantly cycle through numbers, do you have a VOIP number?

> If you don't mind me asking, how do you handle 2FA and companies that require a phone number(eg. my bank)? I'm note vertis, but I wont give out my cell phone number, so: Companies that require 2FA via phone just don't get my business and about all banks in germany offer chipTAN. The chipTAN devices are all made by shady companies and are less than open but I still trust them more than any smartphone or the mobile n…

Yeah, for the most part I use either time based tokens or my Yubikey. Where that's not possible and I can't avoid dealing with the provider as you mentioned it's Google Fi since they have a web gateway I can retrieve them on.

Re: Default disappearing messages

#89

Earlier quoted context omitted.

See Best WhatsApp alternatives that respect your privacy[1]. Signal has: Pros Free Very good encryption Almost no metadata kept Protocol independently audited Seamless to use on Android Disappearing messages E2EE text, voice, and video group chat Cons Requires a valid phone number to register Hosted on Amazon Web Services (AWS) [1] https://protonmail.com/blog/whatsapp-alternatives/

Google Play Services or microg is also required.

This hasn't been true for quite a long time. Signal works perfectly fine on a google-free phone.

Edit to clarify: Signal sets up a background connection instead, which still results in real-time notifications (the same way that Wire works on a phone without Google Play services)

Re: Default disappearing messages

#90

I dunno, I think being able to hoard your own data shouldn't be demonized or valorized? Fine with whatever the default is, but I feel like the subtext here is that Signal thinks people's phones are going to be increasingly compromised so this will be a more necessary, and the "remember the passing acoustic conversation" is just a way to put a less depressing spin on that.

> I feel like the subtext here is that Signal thinks people's phones are going to be increasingly compromised

They will, just now it's the supposed "good actors" that are doing it. See Apple's recent photo scanning announcement. I have no doubt governments will start "encouraging" even more phone monitoring software.

Post reply on HN