Live data from Hacker News

Technology Preview: Signal Private Group System

signal.org

91–100 of 153 posts

Re: Technology Preview: Signal Private Group System

#91
post #2

Again, in the theme of "features every group messaging system had already, but Signal didn't, because they hadn't figured out a way to implement it without turning Signal's central servers into a database of who's talking to who about what". Signal didn't even have user profiles until recently, for the same reason. Here, they've slightly expanded the state of the art in MAC-based anonymous credentials to accomplish t…

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

I converted several non-technical people to Signal, and a few were devastated to learn that getting a new phone meant that they lost their message history. They refuse to use it ever again.

The other sticking point is the phone number requirement. A (female) friend shared her “Signal” contact info with a professional acquaintance who doesn’t understand boundaries. After ignoring him on Signal, that led to unwanted SMS messages and even phone calls. For such a privacy-focused app, I don’t know why they are not more interested in protecting phone numbers.

Re: Technology Preview: Signal Private Group System

#92
post #66

Earlier quoted context omitted.

Unencrypted data/keys should never be in the backup, only data encrypted to some passphrase. It's perfectly fine (and necessary) to require a passphrase to recover backed up logs on the new device.

Signal has had the ability to export chat backups for a long time. I'm not sure why people would complain other than the export is local and you have to manage migration to new device by copying files instead of it being saved on a server and uploaded to your new device after you lose an old one. Also, identity is persistent since you're using a phone number and signal attaches the name you list to that phone number…

That was only added to the Android version. Not possible on iOS.

Re: Technology Preview: Signal Private Group System

#93

I noticed this from the paper: > Note that a user who has acquired a group’s GroupMasterKey and then leaves the group (or is deleted) retains the ability to collude with a malicious server to encrypt and decrypt group entries. We deem this risk acceptable for now due to the complexities in rapid and reliable rekey of the GroupMasterKey. Does this mean that the server and a deleted user can always collude to get the d…

Yes, this means the server and a deleted user could collude to re-add them, or anybody of the deleted user's choosing to the group, or to remove selected people from the group (the server doesn't need collusion to remove random people from a group) No, the members of the group would be able to see that the deleted user is back, or whatever else has happened to the list. Signal's server isn't responsible for deciding…

Got it. I was thinking that for bigger groups, it might be hard for members to keep track of who got deleted when and by whom, so it might be easier for a deleted user to slip back in without attracting notice.

Your point that the deleted user and the server can collude to add a rando to the group seems like a bigger deal, since it would be harder to catch.

To make the same point more critically, if the members need to constantly recheck the mapping of group name to membership list (to stop server cheating), then the scheme might not be buying much.

Re: Technology Preview: Signal Private Group System

#94
post #22

Earlier quoted context omitted.

Why would group Signal messages (a drop-in replacement for group texts) be compared to Slack?

I recently was selecting a messaging platform for my family, and we evaluated both Signal and Slack, and went with Slack. My wife did the same with her family, and went with Signal. From this, I gather they overlap in some features enough to compete for some use cases.

Why not Keybase over Slack?

Not saying Keybase is better; no dog in that fight, just curious if you had considered it.

Re: Technology Preview: Signal Private Group System

#95
post #53
post #5

Earlier quoted context omitted.

I love Signal, and upsell it whenever I can. Signal has its ideosyncratic parts, some of which are being worked on, others not so much. Some of the more visible ones are IMO: Signal forces users to use phone numbers; some people don't like this because they want to use multiple ephemeral usernames so they can be 'Joe' to friends, 'kleptoclown' to their github group, 'dungeonmaster42' to their DND group, 'joesolutione…

If you are a client for Signal, rubberhose cryptoanalysis is a much bigger issue. Here is a story what has happened to Doubi (SSr developer.) He was a very well aware of anonymity risks, and he evaded police for years on end. China literally tried to do geolocate him by turning off the internet in entire cities, but to no result — he caught on to that, and started randomising his release timing, and avoiding releasin…

Pardon my ignorance but I'm unable to find much about this story... and the links you posted are hard to piece together with this narrative.

Not even doubting it, just wondering if there's more of a source that's laid out (work/timeline/etc)? It's supremely interesting and should probably be more well known if it's not already.

Re: Technology Preview: Signal Private Group System

#96
post #78

Earlier quoted context omitted.

Why would a group communication tool be compared with another group communication tool? What's the part you're missing there? I have some friends I talk to in Signal groups. I have others I talk to in Slack. In both cases, the goal is the same: communicate privately with a known group of friends.

In the case of Slack though these are "private" communications only in the same way that say, email to colleagues at work is "private". Lots of people certainly could snoop this, and more probably would be able to if they really wanted to. You would not be told about that, it'd just happen and everybody involved would convince themselves that it's fine. Is it fine though? Signal's rationale is that if we actually sec…

Yes, thanks, I understand the technical difference. What I'm saying is that from a user perspective, many people don't care, or don't care very much. Otherwise they wouldn't be using SMS, telephones, or email.

If Signal wants to be broadly successful, they have to be as good from the perspective of the broad base of users.

Re: Technology Preview: Signal Private Group System

#97
post #80
post #78

Earlier quoted context omitted.

Why would a group communication tool be compared with another group communication tool? What's the part you're missing there? I have some friends I talk to in Signal groups. I have others I talk to in Slack. In both cases, the goal is the same: communicate privately with a known group of friends.

Please recall that earlier in the thread, the following was posted: "[Signal is] really an engine for revealing people's true preferences for messaging, which, for many people, tend to be that they want all the ergonomics of Slack a lot more than they want cryptographically sound secure messaging." This comparison to Slack makes no sense - Signal replaces texts and makes them end-to-end encrypted. It's a straight upg…

The comparison doesn't make sense to you, because you value privacy highly. It makes plenty of sense to people who don't.

People do literally compare them when deciding what group messaging app to use: https://news.ycombinator.com/item?id=21746863

For people like that, end-to-end cryptographic security is at best a nice-to-have. And I'd guess that's circa 90% of people.

Signal's true value comes when lots of people are using it. I never bother with secure email, because almost nobody I know has it set up. But I use Signal for the great bulk of my texting, because most of my friends are on it. If Signal wants that to be more and more true, they have to compete with the other tools people use for group communication.

Re: Technology Preview: Signal Private Group System

#98
post #77

Earlier quoted context omitted.

Yes, you are an exception. Just look at how popular books of letters are: https://www.goodreads.com/list/show/100260.Best_Books_of_Let... Or look at how popular "Letters of Note" is: https://twitter.com/lettersofnote Conversation is connection.

I'm going to keep digging this hole for myself because I think there is some amount of treasure to be found. I'm also interested to see how far out of touch I am. There are tiers of conversation. Letters between famously literate people or during times of war have a value proposition on an entirely different scale to group chat messages. It's about the value that the individual assigns to the content of the conversat…

> There are tiers of conversation. Letters between famously literate people or during times of war have a value proposition on an entirely different scale to group chat messages.

Only in retrospect. At the time, it's impossible to know. We happen to have (some of) Picasso's childhood artwork. What might it be like if we had da Vinci's and Bosch's and that of the Lascaux Caves artists?

Or look at the way Pepys' diary serves as an important source to historians for the details of daily life at that time. Or how Pompeii's graffiti gives us valuable historical insight: https://www.theatlantic.com/technology/archive/2016/03/adrie...

Destroying information now is expressing 100% confidence that nobody will have use for it later.

> It feels as if the point that I'm trying to make is that mindful archiving is a better solution than to just 'keep all the things' - for me, primarily, it's the far improved wheat / chaff ratio.

Depends on the cost of storage and retrieval, really. That was certainly true for, say, paper letters. But as the cost of storage and retrieval goes steadily down, manual archive selection becomes less and less worth it. Hoarding is only a problem IRL because it becomes expensive and unsafe. But my digital archives grow much more slowly than Moore's Law, so the cost to me of keeping all my email, photos, etc, is effectively zero. When I replace my backup drives every few years I spend about the same amount of money, and I keep having more and more space left over.

Re: Technology Preview: Signal Private Group System

#99

Earlier quoted context omitted.

Honestly, the one and only feature I'm missing in Signal that would let me use it and recommend it to everyone without reservations (rather than exclusively for ephemeral-only communication) is the ability to keep identity and full message history when moving to a new device. Today, on iOS, you can't move your Signal history to a new device, and on Android you can only do so by manually making an encrypted backup fil…

I converted several non-technical people to Signal, and a few were devastated to learn that getting a new phone meant that they lost their message history. They refuse to use it ever again. The other sticking point is the phone number requirement. A (female) friend shared her “Signal” contact info with a professional acquaintance who doesn’t understand boundaries. After ignoring him on Signal, that led to unwanted SM…

I just had the experience with a friend whom I got to use Signal who was shocked that she lost her message history when switching phones. Our conversation about it was kind of awkward because I was thinking something like "mud puddle test" (https://blog.cryptographyengineering.com/2012/04/05/icloud-w...) and she was thinking something like "missing basic feature".

Re: Technology Preview: Signal Private Group System

#100
post #77

Earlier quoted context omitted.

I think I'm an exception in this instance, but I don't understand what value there is in message history. How often do you find yourself reminiscing by going back through a messaging log? If there are photos that should be kept then there are other ways to back them up. Is there valuable context in the conversation that was had around the delivery of the photo? Are messages backed up and restorable for other messagin…

Yes, you are an exception. Just look at how popular books of letters are: https://www.goodreads.com/list/show/100260.Best_Books_of_Let... Or look at how popular "Letters of Note" is: https://twitter.com/lettersofnote Conversation is connection.

He's not the only exception.

I have all my Signal messages set to auto delete after 7 days (or less). And I'm pretty happy with how that works. If I thought people at a bar were recording every conversation they had or could overhear forever, I'd talk less freely (and go to different bars).

Not everybody wants ephemeral chat. But I suspect more people _think_ that's what they've got - but in reality do not have...

Post reply on HN