Live data from Hacker News

Improving first impressions on Signal

signal.org

91–100 of 100 posts

Re: Improving first impressions on Signal

#91
post #7

Earlier quoted context omitted.

Yes, I do this. I really wish they and everyone else would stop using phone number as an ID and use an alphanumeric ID. Really, I don't want to give out a phone number to everyone.

Exactly. How hard can it be? It would make it way more secure for almost no effort. I would use Signal if it did not require a phone number or an e-mail address (whichever it requires).

I'm okay with it requiring an e-mail address, that's easier to be universally accessible, as long as your e-mail provider is sane and doesn't require SMS confirmation to login.

Phone numbers, for most people, only work within a certain part of the world and aren't easily accessible worldwide.

Re: Improving first impressions on Signal

#92
post #52

Earlier quoted context omitted.

I've not had this problem with iMessage really. Are you SURE its not possible to block out bad actors on messaging?

Apple keeps detailed metadata records of who sends messages to whom on iMessage, when, and how often. Signal does not. Apple backs up iMessage plaintext contents to Apple, via non-e2e iCloud Backup, bypassing iMessage's end to end encryption. Signal does not.

My point is whatever approach apple is taking, I'm not getting a lot of spam on iMessage, and the one time I did it was pretty easy to mark as spam if I remember.

Re: Improving first impressions on Signal

#93

Just got a new phone and migrating Signal was a total disaster. The first thing I did was login to the new phone which is apparently the wrong thing to do because you lose all your old messages and there's no option to import after you login. You have to logout but there is no logout . Gotta uninstall and reinstall, or clear app data. Next I tried the account migration feature which requires using both phones simulta…

Yeah, this is the #1 issue that holds me back from recommending Signal to everyone in my network. It seems like there are just too many ways to end up in an unrecoverable state. Phone died, lost, or stolen? Can't migrate. Phone number changed? Can't restore backup. And so on. Sure would be nice if there was at least a standalone viewer app which would let you view backups even if you can't restore them.

It's almost like keeping the messages secure is more important than persistence for the creators, and main stakeholders.

Re: Improving first impressions on Signal

#94
post #6

Earlier quoted context omitted.

I've fought spam in other contexts and found that to be true. A change stopped spam until spammers learned what the change was, which made them adapt. The adaption might not be perfect, but it would happen, so prolonging the blocked period was essential. If one can do something that's effective and that the spammers don't understand for months, that's great. If they can spam for days and then blocked for a longer per…

Do you think an eventually open style spam filter could work? One where the implemntation is released say 2 years after it was first written (including modifications)

I don't see what "work" means in that case.

The delayed release is supposed to achieve something, which it can succeed at, or not. I don't see what that is. The delayed release may also have an impact on the the software's and database's function as a spam filter. I don't have a good intuition for that impact either. Sorry.

Re: Improving first impressions on Signal

#95
post #2

Signal's message requests is a major selling point for me. I recently created a Signal account after having a bad experience in which someone used my phone number to harass me with SMS/calls (every time, from a different VOIP number). It's frustrating that, even in this era, there is no good way to filter out malicious actors from SMS/call. P.S. You can sign up with Signal via a VOIP number to avoid sharing your real…

I've not had this problem with iMessage really. Are you SURE its not possible to block out bad actors on messaging?

iMesssage allows you to filter out bad actors -- but raw SMS (green text message) does not. I was getting a few SMS messages a day, each from a different phone number, likely with a service like TextNow.com

Re: Improving first impressions on Signal

#96
post #93

Earlier quoted context omitted.

Yeah, this is the #1 issue that holds me back from recommending Signal to everyone in my network. It seems like there are just too many ways to end up in an unrecoverable state. Phone died, lost, or stolen? Can't migrate. Phone number changed? Can't restore backup. And so on. Sure would be nice if there was at least a standalone viewer app which would let you view backups even if you can't restore them.

It's almost like keeping the messages secure is more important than persistence for the creators, and main stakeholders.

It's exactly like that. Which isn't necessarily a bad thing. But handling use cases like reading your own safely encrypted past messages after your phone number changes seems pretty reasonable to me.

Re: Improving first impressions on Signal

#97

Earlier quoted context omitted.

It's complicated and can be expensive. Also people that has you real phone number cannot contact you on Signal, so you have to have two accounts, one with your real number to chat with your contacts and another one with the fake one to share with strangers that you don't trust, and as far as I know the Signal app doesn't support two account (yes on Android there are ways to have two instances of the app, on iOS you c…

On Telegram if anyone else has your phone number in their contacts then they’d know it’s you even if you initiated the communication via username. Or that’s how it was. I am not sure if this has changed/been fixed.

Only by default, you can opt out this behaviour. But I don't see a problem with it, if someone already has my number he doesn't get much more information (beside the fact that I may want to have a "secret" Telegram account. But in that case you can register it with another phone number).

Re: Improving first impressions on Signal

#98
post #91

Earlier quoted context omitted.

Exactly. How hard can it be? It would make it way more secure for almost no effort. I would use Signal if it did not require a phone number or an e-mail address (whichever it requires).

I'm okay with it requiring an e-mail address, that's easier to be universally accessible, as long as your e-mail provider is sane and doesn't require SMS confirmation to login. Phone numbers, for most people, only work within a certain part of the world and aren't easily accessible worldwide.

The reason I am not okay with it is that it is usually tied to your person in one way or another. Have you tried getting an e-mail while using Tor? Next to impossible. Plus, it is unnecessary really. You can use nicknames or say, a generated UUID of some sort, with perhaps a QR code for easy copying.

Re: Improving first impressions on Signal

#99
post #91

Earlier quoted context omitted.

I'm okay with it requiring an e-mail address, that's easier to be universally accessible, as long as your e-mail provider is sane and doesn't require SMS confirmation to login. Phone numbers, for most people, only work within a certain part of the world and aren't easily accessible worldwide.

The reason I am not okay with it is that it is usually tied to your person in one way or another. Have you tried getting an e-mail while using Tor? Next to impossible. Plus, it is unnecessary really. You can use nicknames or say, a generated UUID of some sort, with perhaps a QR code for easy copying.

crating a new yandex email account works nicely via tor for me

Re: Improving first impressions on Signal

#100
post #99

Earlier quoted context omitted.

The reason I am not okay with it is that it is usually tied to your person in one way or another. Have you tried getting an e-mail while using Tor? Next to impossible. Plus, it is unnecessary really. You can use nicknames or say, a generated UUID of some sort, with perhaps a QR code for easy copying.

crating a new yandex email account works nicely via tor for me

I will check. I would say that it works... for now. :P It is not something we should rely on, I think.
Post reply on HN