back

by colesantiago·5y ago·view on hn ↗
Although a welcome addition to Signal, personally would like to see the 'phone number sign up' 'disappear' from the app and instead add email signup.

Thats all.

5 comments
This is one of the biggest things that stops me from using Signal. I don't have a phone number really any more (I'm a digital nomad, and pick up regional sims)

I'm not really interested in the disappearing message either if I wanted that I could just use Slack Free edition :troll:.

In all seriousness though, my messages are part of my memory. They're shared experience with my partner and a record of decisions.

I understand they're useful for some people, but they're an anti-feature for me.

> In all seriousness though, my messages are part of my memory. They're shared experience with my partner and a record of decisions.

Thanks for saying this, I moved to Telegram[1] before I had a chance to learn about/suffer from Whatsapp take on backups, but it would have been devastating to lose years of messages with people over a bricked phone.

[1] I know Telegram has a bad rep due to their home cooked crypto and maybe other stuff, but I like the app, I vaguely trust the author, and it works fine for me.

> [1] I know Telegram has a bad rep due to their home cooked crypto and maybe other stuff, but I like the app, I vaguely trust the author, and it works fine for me.

Is that because you assume the NSA aren't reading all your messages or you don't mind if they are? Because the whole problem with dodgy crypto is that it still seems to "work fine for me" even when it isn't.

In my case it is to a large degree because I don't care.

Disappearing messages are to prevent my kids reading the messages between me and their mother ;-)

If NSA actually read my messages that would be kind of funny.

If they have such a hack I'm sure they won't spend it on me or any other Joe Sixpack.

Maybe ФСБ reads it but I have a hard time believing that too.

My threat model consists of (not in any particular order):

- my kids,

- random internet strangers,

- Facebook (who'll sell you to whoever pays),

- Google or a Google-like entity with runaway "AI" and arrogant customer support[1] (who can lock out from my accounts for no reason)

Besides, despite all the talk about E2E-encryption being so important, Signal (which I cheer for) IIRC has had a nasty XSS-exploit in their desktop allowing remote control of the pc, their phone client has been sending pictures to others than the recipient and probably a couple more.

Ad I and others have pointed out repeatedly:

There is more to security than encryption. It doesn't matter if it is E2E-encrypted if it is delivered to the wrong contact. And it doesn't matter if it is E2E-encrypted if whoever knows the secret can send you a specially crafted message and take control over your machine.

[1]: I originally wrote employees but I don't think the average Google employee is more arrogant than others, they just come across that way because of policies created far above them.

Secure systems are all alike; every insecure system is insecure in its own way. A messenger that has E2E encryption might not be secure, but a messenger that doesn't have E2E encryption is definitely insecure.

Not caring about your messages being read, or being willing to trust the operator of the service, is fine, but in that case I struggle to see why you'd pick Telegram, given that their whole selling point was about privacy and encryption when their encryption didn't actually work.

> A messenger that has E2E encryption might not be secure, but a messenger that doesn't have E2E encryption is definitely insecure.

It is secure for my purposes.

Throwing away threat models and the meaning of secure and encrypted just to be able to define something that competes for attention as "not secure" and "not encrypted" (from other threads) isn't very high level, it is basic framing.

edit:

> Not caring about your messages being read, or being willing to trust the operator of the service, is fine, but in that case I struggle to see why you'd pick Telegram, given that their whole selling point was about privacy and encryption when their encryption didn't actually work.

Remember, when Telegram came around WhatsApp was un-encrypted. Not point-to-point encrypted, just encoded. You didn't need to know or crack a key, you just needed toknow the protocol.

Also, the main selling point of Telegram as I remember it wasn't security, it was dumb IMO, it was "we will be free (no cost) forever while WhatsApp is going to charge you money".

Finally it isn't that I don't care if my messages are read, K just cannot care if my messages are read by NSA or FSB. If they go after me nothing will stop them.

> Throwing away threat models and the meaning of secure and encrypted just to be able to define something that competes for attention as "not secure" and "not encrypted" (from other threads) isn't very high level, it is basic framing.

It's basic, but it's valid. I was responding to all your "It doesn't matter if it is E2E-encrypted if xyz" points, which are faulty logic; if whether it's E2E-encrypted matters in your threat model, then whether it's E2E-encrypted still matters in your threat model even if other aspects of the system are secure.

> Remember, when Telegram came around WhatsApp was un-encrypted. Not point-to-point encrypted, just encoded. You didn't need to know or crack a key, you just needed toknow the protocol.

Citation? I don't remember it happening that way at all; Telegram marketed themselves by attacking WhatsApp on a couple of minor vulnerabilities in side features like video handling (which was legitimate in some ways, but extremely hypocritical given the bigger weaknesses in Telegram's own implementation). If message text was readable that would have been a much bigger deal.

> when their encryption didn't actually work.

what are referring to here? I vaguely know about delivery bugs and protocol patches

The initial release used a homegrown crypto protocol with serious weaknesses, and the developer at least initially doubled down and tried to defend it.
For that same reasoning I support telegram more than signal. I simply do not see signal ever get to a widespread adoption, I do not see signal trying to get to a widespread adoption either; signal is not a messaging app it is a secure comunication app and for this they make a lot of tradeoffs.

An example is E2EE, it is a nice property but today it has significant UX implications that makes it bad default in my opinion for a popular personal messagin app; in other places it is essential, just not there.

Moreover the main threat model is not NSA hacking my device or the app's servers, it is app developer selling my data and governments making "lawful" requests to service providers. In both these metrics signal ranks better as far as I understand, but it is more of an individual choice.

If we are worried about the NSA the best thing to do is to move out of SMS/phone calls as fast as possible on mediums that do not allow passive monitoring and are likely to resist government pressure.

> For that same reasoning I support telegram more than signal. I simply do not see signal ever get to a widespread adoption, I do not see signal trying to get to a widespread adoption either; signal is not a messaging app it is a secure comunication app and for this they make a lot of tradeoffs.

But Telegram's whole selling point is privacy and security. If security is not your priority (which is totally reasonable!) there are plenty of other messaging apps that are much more established than Telegram, and much more honest about not being particularly privacy-oriented.

> An example is E2EE, it is a nice property but today it has significant UX implications that makes it bad default in my opinion for a popular personal messagin app

Doesn't seem to have been a problem for e.g. WhatsApp.

> Moreover the main threat model is not NSA hacking my device or the app's servers, it is app developer selling my data and governments making "lawful" requests to service providers. In both these metrics signal ranks better as far as I understand, but it is more of an individual choice.

> If we are worried about the NSA the best thing to do is to move out of SMS/phone calls as fast as possible on mediums that do not allow passive monitoring and are likely to resist government pressure.

Both these points seem like complete non sequiturs. If you want to avoid the app developer selling your data or providing it to governments, you need E2EE, there is no other way. Passive monitoring hasn't been a thing for about a decade, any non-joke messenger is at least using TLS, and it's not like people were using SMS/phone calls until Telegram came along with the revolutionary new idea of an internet messaging app.

There are a lot of regional variations on this and the only regions I am vaguely familiar with are a couple countries in europe and the US/Canada, that said:

> there are plenty of other messaging apps that are much more established than Telegram.

Not where I live, the only comparable app is whatsapp and after that various social media platforms probably.

> [E2EE] Doesn't seem to have been a problem for e.g. WhatsApp.

It is, porting backups between phones (last time I tried) requires both phones to be active.

> and it's not like people were using SMS/phone calls until Telegram came along with the revolutionary new idea of an internet messaging app.

They were using whatsapp, which in my opinion is worse than telegram and uses E2EE as a PR shield. I personally do not trust facebook to deliver a trustworthy app (they would have to be OSS with reproducible builds at least) I do not care that my messages are encrypted on their servers, they can steal them from my phone storage directly. It is a matter of lack of trust towards facebook.

My main chat platforms are IRC, Telegram and Discord. None of them are E2E encrypted and don't sell themselves as such.

I keep that in mind when discussing things.

If I want to start doing something shady, I can pick up something else than Signal, since I don't want my phone number ending up on random people's phones.

> My main chat platforms are IRC, Telegram and Discord. None of them are E2E encrypted and don't sell themselves as such.

Telegram's initial marketing heavily emphasised privacy. If I search for Telegram then the very first search result blurb starts "Telegram messages are heavily encrypted". Maybe they don't explicitly claim to be E2E, but they absolutely are selling themselves as an encrypted, privacy-friendly messenger.

> If I want to start doing something shady, I can pick up something else than Signal, since I don't want my phone number ending up on random people's phones.

Completely agreed, I dislike the Signal hype as much as anyone. But I trust Telegram even less.

The heavily encrypted refers to server side storage.

https://telegram.org/privacy#3-3-1-cloud-chats

> All data is stored heavily encrypted and the encryption keys in each case are stored in several other data centers in different jurisdictions. This way local engineers or physical intruders cannot get access to user data.

Wow, that's not at all clear from their marketing. That kind of misleading statement is definitely not what I'd want to see from a privacy/security-focused product - and yet Telegram's whole marketing is about privacy/security.
Honestly you might want to look into Google Fi (Even though google is evil and just being under their umbrella makes me consider leaving) since their plans automatically work in most countries [1].

I want to find a better cell plan with a company I am not ethically opposed to but Fi is so good that it makes it really really hard to beat.

[1]: https://fi.google.com/about/international-rates/

Google Fi has actually been reasonably useful despite the fact that I can't get it to work because I'm not in the US. They have a web messaging interface that I can collect 2FA from.

I avoid phone based 2FA where possible, but the few that I have are sent there.

But it's not really for non-US, and they've really started cracking down on people that use it exclusively internationally.

Which is a real shame. It's absolutely the service I want/need as digital nomad.

If you don't mind me asking, how do you handle 2FA and companies that require a phone number(eg. my bank)?

Do you have to constantly cycle through numbers, do you have a VOIP number?

> If you don't mind me asking, how do you handle 2FA and companies that require a phone number(eg. my bank)?

I'm note vertis, but I wont give out my cell phone number, so: Companies that require 2FA via phone just don't get my business and about all banks in germany offer chipTAN. The chipTAN devices are all made by shady companies and are less than open but I still trust them more than any smartphone or the mobile network.

Yeah, for the most part I use either time based tokens or my Yubikey. Where that's not possible and I can't avoid dealing with the provider as you mentioned it's Google Fi since they have a web gateway I can retrieve them on.
Yes.

Or, at the very least, support people who have a phone that is not Android or iOS by allowing them to register from a desktop application. Does not seem misaligned with Signal's aim for privacy.

One of the things I've noticed is that Signal doesn't seem to care about privacy at all. They care a lot about security though, which is a different thing, and tell you that's privacy.
See Best WhatsApp alternatives that respect your privacy[1]. Signal has:

Pros

    Free
    Very good encryption
    Almost no metadata kept
    Protocol independently audited
    Seamless to use on Android
    Disappearing messages
    E2EE text, voice, and video group chat
Cons

    Requires a valid phone number to register
    Hosted on Amazon Web Services (AWS)

[1] https://protonmail.com/blog/whatsapp-alternatives/
You can also add another big cons: the only supported way to run Signal is to own a device that runs code that you can't control on the main CPU (an iPhone; or an Android device, which also means running proprietary drivers in user space in practice). I know, I'm repeating myself.

You can manage to use Signal with most features without the need to run proprietary blobs by registering your phone number using signal-cli or axolotl (and maybe alternatives, but I haven't tried). They can run on a regular desktop or on a GNU/Linux phone, and then pairing Signal-Desktop with it. This is not straightforward, and forget convenience on the phone for now (I haven't managed to make groups work on UIs based on signal-cli though they theoretically should, Axolotl does not fully support new groups and by that I mean it's missing essential features like accepting an invitation).

Then, the blobs you are running are "only" in your phone's modem, unless you also managed to use some service providing SMS from the internet.

This is totally unsupported because it depends on alternative Signal clients that are not allowed on the Signal's network. For some reason Signal-cli and Axolotl don't seem to have been asked to stop from the Signal team, but it happened to a Signal fork, Free-Signal, which only goal was to de-blob Signal. And they are in their own right to do so, I'm not questioning this.

This is painful, really. Signal is so close to be great. Matrix / Element works well enough. It has rough edges but I (re)-discovered that Signal has some too and I'm not speaking about this whole situation.

Google Play Services or microg is also required.
This hasn't been true for quite a long time. Signal works perfectly fine on a google-free phone.

Edit to clarify: Signal sets up a background connection instead, which still results in real-time notifications (the same way that Wire works on a phone without Google Play services)

Your comment was dead, I vouched for it. I think you are correct. It was correct a while ago anyway.

A year ago or two, I wanted to build Signal for Android without the proprietary library that talks with google play services. It was possible by modifying the source code a bit, because the code checks for the presence of the handles the absence of the Google play Services and enables some sort of fallback.

I would not know if it is still the case today, I don't currently own an Android device.

That is called XMPP.
Or at least allow me to change my number without losing all my history.
I'd like tablet/Android without SIM.
Signal is a secure comunication app not a messaging app. All they do is optimized towards providing security, confidentiality, and/or privacy with a decent UX, but they make it very clear that the UX is on a lower level of priority. So since message transfers are a confidentiality risk they do not provide it.

Signal is an analogue of the tor browser, most people get diminishing returns after an adblocker/incognito mode.

They did desktop sidecar. why not do a sidecar for SIMless tablets?

they did iPad. presuambly the secure region coding for iDevices is better?