11 ms·
Disappearing messages for Signal
- subliminalpanda 10y agoSignal keeps getting better with each release, great job at everyone from Whisper Systems.
- MereKatMoves 10y agoI love using Signal and will continue to make modest donations, but I would really appreciate an improvement in audio call quality. I still use Silent Circle for calls because it is so tiring to talk when the bitrate is low.
- subliminalpanda 10y agoAgreed. WhatsApp calls are near flawless when connections are good, I'm sure WS can reach audio quality parity. I often get disconnected on Signal after 20 minutes or so on a voice call, but I suspect that's due to the other end being behind a VPN with awful latency.
- MereKatMoves 10y agoDid FB/WA clarify that they use the OW audio encryption algos, or did they just put the OW 'trophy' on the wall without the actual implementation? WhatsApp is, I agree, very good quality for what it is, but I would never trust it or FB with anything but social/personal calls. Social Media platforms are for other people to hand over their lives to. Let them subsidize my detachment from their usage, and I thank them for it. I'm sure there will come a day where you can't use WA without a FB account, at which point it is dead to me and my social contacts will be the first to know about it via WA.
- subliminalpanda 10y agoLooking at WhatsApps security whitepaper: "WhatsApp calls are also end-to-end encrypted When a WhatsApp user initiates a call: 1 The initiator builds an encrypted session with the recipient (as outlined in Section Initiating Session Setup), if one does not already exist 2 The initiator generates a random 32-byte SRTp master secret 3 The initiator transmits an encrypted message to the recipient that signals an incoming call, and contains the SRTp master secret 4 If the responder answers the call, a SRTp encrypted call ensues" From wikipedia: "Signal voice calls are encrypted with SRTP and the ZRTP key-agreement protocol, which was developed by Phil Zimmermann.[1][57]" So from where I'm reading they seem to be doing more or less the same thing when it comes to encrypting voice calls. https://www.whatsapp.com/security/WhatsApp-Security-Whitepaper.pdf https://www.whatsapp.com/security/WhatsApp-Security-Whitepap... https://en.wikipedia.org/wiki/Signal_(software) https://en.wikipedia.org/wiki/Signal_(software)
- MereKatMoves 10y agoForgive me for being a layman in these matters Are you saying "maybe/maybe not"? If they seem to be doing something that is "more or less" the same then my radar is triggered for them not actually declaring they are delivering totally encrypted (ie no backdoor tomfoolery) voice calls.
- uph 10y agoOver the past year, we've been progressively rolling out Signal Protocol support for all WhatsApp communication across all WhatsApp clients. This includes chats, group chats, attachments, voice notes, and voice calls across Android, iPhone, Windows Phone, Nokia S40, Nokia S60, Blackberry, and BB10. https://www.whispersystems.org/blog/whatsapp-complete/ https://www.whispersystems.org/blog/whatsapp-complete/
- Johnny_Brahms 10y agoSRTP and ZRTP is only for negotiating what to use. You can still use different codecs. I'd guess Wire, WA and SC use opus (since it is by far the best), while signal is still using speex. ZRTP makes negotiation possible, so a roll-out of opus should be possible without breaking older clients.
- kkl 10y agoMy Signal phone audio issues went away after I upgraded hardware. Not a great solution (obviously) but something worth noting.
- MereKatMoves 10y agothat's interesting. I'm running a 2 year old Xperia Z3 and it never occurred to me that my CPU might be the issue, but SC seems to handle audio quality just fine edit - what did you upgrade to/from?
- kkl 10y agoLG G2 to a Nexus 5X.
- StavrosK 10y ago> I still use Silent Circle for calls because it is so tiring to talk when the bitrate is low. To be fair, that's a high bar. Our (SC) phone guys are masters at optimizing audio quality. I would be extremely surprised if any other app (encrypted or not) had significantly better audio quality than Silent Phone.
- walterbell 10y agoWire's audio quality is quite good, even on cellular and/or VPN. Haven't compared with Silent Circle.
- StavrosK 10y agoOh, I'll give that a go, thanks! I should try Signal again too, hopefully audio quality has improved from the Redphone days.
- secfirstmd 10y agoYeh it definitely has come on a lot since then
- quantumfoam 10y agoI have to agree. Privacy is a right. It's not often you run into a free alternative that offer sync capabilities across all platforms and devices. You also have a way to restrict or remove access from unknown fingerprints. The only downside I see about Wire is that the option to "submit crash reports and usage data" is enabled by default but that's just an Advanced options visit away from disabling. Give Wire a try and give their white papers covering how they approach [1] privacy and [2] security a read. [1] https://wire.com/resource/Wire%20Privacy%20Whitepaper/download/ https://wire.com/resource/Wire%20Privacy%20Whitepaper/downlo... [2] https://wire.com/resource/Wire%20Security%20Whitepaper/download/ https://wire.com/resource/Wire%20Security%20Whitepaper/downl...
- MereKatMoves 10y agoHaving used all the encrypted call possibilities there are , you are, in my opinion, absolutely spot on. SC has exceptional clarity. WA isn't bad. Can you talk more about "our guys" in respect to the fact that the CIA and NSA use the Blackphone? Should I, as a casual business person, be wondering that the handsets you supply to them are in some way compromised? I know that both the NSA and the CIA are interested in my phone conversations, which is why I ironically bought a Blackphone (for when I assume they are listening) and others which make their life harder (but I do accept that I do this more for the kicks of making them work for their intel) tl:dr - is SC actually secure given that the company has been short on cash for a while and that the CIA and NSA equip their agents with the same phones. I don't mind talking because I have nothing to hide, but backdoor code is usually the case if you are selling 10k phone units to US LE.
- taejo 10y agoI've never noticed a quality issue... because I've never had a call connect at all (to be fair, it's been a while since I accidentally clicked the "call" button and checked, since I've long given up on trying to use it deliberately).
- Johnny_Brahms 10y agoI'd guess both SC and WhatsApp use opus, whereas Signal at the moment is using speex. There is an issue open at github, but it does not seem to be a priority. I haven't read very much about it, but there seems to be concerns about opus leaking data about the call. I don't know how, but from android5.0 there is an opus encoder included that supports CBR mode.
- jpt4 10y agoWith all due respect, Open Whisper Systems might ought first consider fixing Signal's multiplicate message problem, especially silent (to the sender) group chat spamming.
- moosingin3space 10y agoAs a Signal user, I've experienced this issue as well. I work around it by deleting the message, then re-sending it, but that's clunky.
- avhon1 10y agoI don't think that's the problem that jpt4 is talking about. I believe he is talking about how sometimes a group message will be received 20 times or more, and yet the sender will still see "message not sent" for some recipients.
- moosingin3space 10y agoThat is the issue I'm referring to.
- avhon1 10y agoHow does re-sending the message help? Everybody in the group has already received the message a dozen times or more.
- LeonidasXIV 10y agoIt doesn't but the sender does not know that everybody has the message a dozen times so he resends it.
- soared 10y ago>multiplicate I'd never heard this word so I looked it up. Google didn't have a definition but merriam-webster was the first result. They showed me an extra concise definition and then this message... >Wait, there’s more! This word doesn't usually appear in our free dictionary, but we’ve shared just a bit of the information that appears in our premium Unabridged Dictionary. There’s more definition detail there. Start your FREE Trial Now! Umm.. Fuck you Merriam-Webster?
- mtgx 10y agoGreat. One of the most requested features is finally here. I think all that's left now is video calling (on the desktop, too).
- subliminalpanda 10y agoI would like to be able to re-register a new number without having to de-activate the account thereby not losing all of my chats.
- geomark 10y agoIs there a way to export chart history and then import it to the new account?
- subliminalpanda 10y ago> Is there a way to export chart history and then import it to the new account? Another feature that I would like to see (Chat backup and restore). If it's there, I can't find it.
- faktorialas 10y agoThis comment says it's unavailable on iOS and Chrome, but there on Android: https://news.ycombinator.com/item?id=12689695 https://news.ycombinator.com/item?id=12689695 I can back up that Chrome point, unless it has been added in a recent update. On Android, it can do encrypted and plaintext backups - never tested, but I assume they include messages. What else.
- thomasville 10y agoIs there a way from preventing certain contacts from knowing I'm on Signal? Like, it is embarrassing that Jason from college knows I'm on Signal. I know you guys will disagree and say it is not embarrassing, but it seems that a privacy-focused app would respect this notion. Obviously being a member of certain apps (grindr) can be seen as negative. I think I should be able to Whitelist my contacts.
- cbsmith 10y agoSIgnal is basically getting the full feature set of TigerText.
- mordant 10y agoI don't understand why it still doesn't support landscape mode on iPhone.
- uph 10y agoIt's on the roadmap https://github.com/WhisperSystems/Signal-iOS/issues/937 https://github.com/WhisperSystems/Signal-iOS/issues/937 The iOS version didn't have a dev for a while after Frederic Jacobs went to Apple, but Michael Kirk recently took over so things are happening again.
- libeclipse 10y agoI'm not sure that this is a benefit. It gives users a false sense of security. Screenshots or pictures can always be taken on the other end. Didn't signal used to be explicitly against this feature.
- oconnore 10y agoIf their sense is that -- after configuring 1 week self destruct, the people they're talking to likely won't be keeping months and months of chat logs on their phone anymore -- it's a very true sense of security.
- kuschku 10y ago[deleted]
- uph 10y agoWhat good is a seatbelt if the person sitting next to you can stab you? The blog post makes a point of this not being secure if the person you're messaging is malicious and that's not what it's for. I think these two comments make good points: I just had an interesting conversation with a friend who was recommending that I use Telegram/Wickr, and I told him that Signal was where it's at. Then he asked me if it had self-destructing messages, and I said "Why bother? That can be easily circumvented". His reply was that in some countries phones had been confiscated, and even though one person had enabled local encryption, the user with the confiscated phone had not enabled it; thereby implicating everyone who had communicated with that person (even though the messages were delivered secure over the network). So while self-destructing messages are in many ways a flawed guarantee of privacy, they can perform a very useful function in cases where the users are not malicious, but rather are security ignorant (i.e. most people with a phone). https://whispersystems.discoursehosting.net/t/automatically-disappearing-messages/473/18 https://whispersystems.discoursehosting.net/t/automatically-... I've always been thinking that the critique of such a feature is based on a false underlying premise. Yes, it's true that the recipient can make a screenshot of the message. But the recipient in the absolute majority of cases is not a "threat" in a classical sense, not someone with bad intentions or someone who is not supposed to know the contents of that message. After all, the sender trusts the recipient, as he is the one sending the message to the recipient in the first place. The usual scenario is a recipient who is not that security-aware and doesn't think about those things that much if at all. Personally, I'd say most of my contact are that way. The sender might send this recipient a message containing something especially critical, say, a user name and a corresponding password, and doesn't want to see that information in the wrong hands if e. g. later on, the recipient loses their phone, the phone gets stolen, etc. Also note that this kind of recipient is unlikely to use a general passphrase for Signal as this lessens convenience. So what's essentially happening here is a security-minded sender taking security measures for or in place of a thrustworthy, albeit forgetful, non-security-minded, etc recipient. https://whispersystems.discoursehosting.net/t/automatically-disappearing-messages/473/10 https://whispersystems.discoursehosting.net/t/automatically-...
- Canada 10y agoI've been receiving a bunch of "Bad encrypted message..." lately. Wonder what's up with that.
- MichaelGG 10y agoTons of those, plus repeats, and "random" delays. Sometimes it takes a few minutes for messages to go through (single check). Last week was really bad. I don't know how multiple messages can happen; shouldn't they have a unique ID?
- uph 10y agoLast week was due to server issues https://whispersystems.discoursehosting.net/t/intermittent-message-send-failures/537/7 https://whispersystems.discoursehosting.net/t/intermittent-m...
- Canada 10y agoI saw the mailing list post, then got the bad messages a day later. Probably the same issue, still curious about the technical details though.
- Canada 10y agoYeah. My understanding is the message key used to decrypt first copy should be immediately deleted after decrypting it, so how can the second copy be decrypted successfully? Seems to fly in the face of forward secrecy unless it's purely a client side bug. Bad encrypted message, if I recall correctly, means either the MAC check failed or the protobuf payload inside didn't deserialize correctly. I don't know.. I'm not setup to debug it on my regular phone with a production signal apk installed.
- newscracker 10y ago> and "random" delays. Sometimes it takes a few minutes for messages to go through (single check). This was the main reason I almost stopped using Signal several months ago and started trying out Wire (which is also slower when compared to Telegram). I find it disappointing that the problem still exists. I can't convince others in my circle to use it if basic message delivery is flakey and slow.
- sigmar 10y agoI had an idea a few days ago where you authenticate your identity (i.e. numeric fingerprint) on-demand by sending a pic of yourself where the QR code is overlayed as blacked-out pixels before being transmitted. Then the recipient can look at the photo to see it hasn't been manipulated, and use the app to verify the QR codes match. I'm sure there are issues with this, but it seems like a nice feature for when secure out-of-band communication is not possible.
- drudru11 10y agoHow do they make money?
- hoers 10y agohttps://en.wikipedia.org/wiki/Open_Whisper_Systems#Funding https://en.wikipedia.org/wiki/Open_Whisper_Systems#Funding
- subliminalpanda 10y agoFrom wikipedia: "The group is funded by a combination of donations and grants, and all of its products are published as free and open-source software." https://en.wikipedia.org/wiki/Open_Whisper_Systems https://en.wikipedia.org/wiki/Open_Whisper_Systems
- drudru11 10y agoWhy isn't this on their site? ... this is just thinking out loud, not directed at you.
- deleted 10y ago[deleted]
- baby 10y agoIf you want to implement the signal protocol for your own company (see WhatsApp, Messenger, Allo, ...) you will probably have to buy a license ($$$), and ask for their help ($$). * https://whispersystems.org/blog/whatsapp-complete/ https://whispersystems.org/blog/whatsapp-complete/ * https://whispersystems.org/blog/allo/ https://whispersystems.org/blog/allo/ * https://whispersystems.org/blog/facebook-messenger/ https://whispersystems.org/blog/facebook-messenger/
- cyphar 10y agoCool feature, though it'd be nice if Signal fixed the message delay and message dropping problem. But Signal uses the proprietary GCM service (because "it's impossible to do message sending correctly, so let's force people to use proprietary software") so they probably can't fix it...
- uph 10y agoNo one is forcing you to use proprietary software. See this comment from moxie https://news.ycombinator.com/item?id=10665520 https://news.ycombinator.com/item?id=10665520 Using GCM is only a problem for people running a custom Android ROM without Google Play Services. Using GCM doesn't make Signal less private. Google doesn't see any data via gcm, it's just a tickle. If you want push messages, you gotta use a push network. https://twitter.com/whispersystems/status/695399112833761283 https://twitter.com/whispersystems/status/695399112833761283 Feel free to help out with code https://github.com/LibreSignal/LibreSignal/issues/43 https://github.com/LibreSignal/LibreSignal/issues/43 or money https://www.bountysource.com/issues/35722527-create-proper-pull-request-to-add-libresignal-s-websocket-support-to-ows-signal https://www.bountysource.com/issues/35722527-create-proper-p... if using Signal without GCM is important to you. If the only thing that the remaining people here want out of LibreSignal is a websocket-only solution and gmscore isn't an option for whatever reason, I would consider a clean, well written, and well tested PR for websocket-only support in Signal. I expect it to have high battery consumption and an unreliable user experience, but would be fine with it if it comes with a warning and only runs in the absence of play services. However, I also realize that still won't help people that are trying to build a Google-free experience on Google's platform https://github.com/WhisperSystems/Signal-Android/issues/127 https://github.com/WhisperSystems/Signal-Android/issues/127 , since we still don't have the things we need https://github.com/WhisperSystems/Signal-Android/issues/127#issuecomment-21763521 https://github.com/WhisperSystems/Signal-Android/issues/127#... to be comfortable distributing software outside of Play. https://github.com/LibreSignal/LibreSignal/issues/37#issuecomment-226646872 https://github.com/LibreSignal/LibreSignal/issues/37#issueco... Considering how a small minority complain about this everytime Signal is mentioned you'd think they'd do something about it, but take a look at that Bountysource link and you'll see 8 backers. Guess complaining is easier.
- lqdc13 10y agoI love Signal and this seems to be a stab at Wickr since from what I've heard that is the reason people prefer it to Signal sometimes. Having said that, it has a couple of problems: 1. Images are downsampled without warning. There should be some sort of warning or mini info box for the times when the images are downsampled and there should be information about the changes in resolution. 2. If one uses it as the main messaging app, one has to search through history sometimes. But there is no chat search feature. I am forced to scroll all the way up and copy the message data to an editor. Even really basic case insensitive search would be great.
- drew-y 10y agoIt'd also be nice if the iOS or Chrome client had a chat history backup feature like they have on android. This is one of my biggest complaint with messaging apps in general. I'd like to be able to preserve and archive my chat history with people close to me.
- 1024core 10y agoWhat if the person you're chatting with does not want it archived? (I'm not questioning, but wondering what a protocol would be)
- cvwright 10y agoThis issue is one of those that make it very difficult to build a single "secure chat" app that does everything for everyone. Personally, I want an automatic, encrypted network backup of all my messages so I don't lose them if my device is lost or destroyed. But I know lots of folks around here are excited about the automatic delete thing too. It's going to be very hard to make something that all of us can be happy with.
- jeeekthrowaway 10y agoYou can't trust the client. It's the same fundamental flaw with DRM. If that person does not want it archived, you can make it difficult but not impossible.
- secfirstmd 10y agoHow to donate to Signal! http://support.whispersystems.org/hc/en-us/articles/212940158-How-can-I-donate- http://support.whispersystems.org/hc/en-us/articles/21294015...
- AckSyn 10y agoNow if they would drop the ridiculous requirement of having a phone number and go with usernames and not require access to my contact list like most other services, you could actually be safer and not rely on _their word_ alone.
- mahyarm 10y agoThe app is open source and you could do something like a proxy or similar if you really want to be sure of what get sent from your client. The server is also open source too. As moxie said, it's about raising the defaults of the world, not about making it secure for the crypto nerd.
- throwaway7767 10y ago> As moxie said, it's about raising the defaults of the world, not about making it secure for the crypto nerd. The thing is, the attacks in the "crypto-nerd paranoia" category tend to become everyday attacks over time. Pre-Snowden, most people would put a lot of the things the NSA is doing into the "crypto-nerd paranoia" bucket. Now we know they were wrong to do so. Signal routes all conversation metadata through one infrastructure, which becomes a very tempting target. By also requiring phone numbers as identity, they make it very easy to tie that metadata to real people and perform graph analysis on it.
- mifreewil 10y agoWith the approach that Signal has taken, it doesn't require you to register a username. The app just registers you with the server as a Signal user using your already unique ID - your phone number. While not the most secure and privacy-protecting method, it allows anyone to just install it and start using it as a secure alternative to plaintext SMS.
- lqdc13 10y agoRegarding SMS - it's not always an alternative to SMS since it uses data. I know data is more popular than SMS in many countries, but when you hit your monthly limit, you want to disable all data. Regarding the simplicity of using a phone number and how it would be very easy for all users - Wickr provides basically the same service, is more popular, but uses usernames instead of phone numbers. The fact that something is open source isn't always a clear win. OpenSSL, for example, is open source and yet they seem to have many bugs. For the record, I use Signal almost exclusively for communication. I just wish it was more protective of users' privacy without having to put in a ton of effort.
- Zhenya 10y agoEverytime there is an update, I become more emboldened to continue to push my friends from whatsapp to Signal. I just wish we had way to see what's going on in their server.
- uph 10y agohttps://www.whispersystems.org/bigbrother/ https://www.whispersystems.org/bigbrother/ https://github.com/WhisperSystems/TextSecure-Server https://github.com/WhisperSystems/TextSecure-Server
- mi100hael 10y agoThe fact that their phone server isn't free makes me somewhat more concerned as time goes on. I used to think it was just because they were busy, then I thought maybe they just wanted more time to refine things, but now it's been nearly two years since they released the current re-vamped Signal 2.0 for iOS and over a year since releasing Signal for Android. At this point I'm running out of justifications for them for why their phone server is still proprietary & closed source.
- Zhenya 10y agoI keep thinking about this concept of a "glass server". They can run it, but allow developers to somehow see running processes, and write (rate-limited) queries to test things. I haven't solidified this concept in my head but it seems like a step towards federation without the problems of federation.
- mi100hael 10y agoHmm that's an interesting idea. I'm assuming their phone server is Java, same as their text server, so the builds should theoretically be identically reproducible for both. It seems like it should be possible to include a field in each response with some sort of signature so users can verify which build is serving requests. It'd have to be in every response so that they can't just reverse-proxy /status to the valid build and serve other requests from a modified build, and it'd have to be somehow dependent on some changing external factor or input so they can't just hard-code the valid build's signature.
- deleted 10y ago[deleted]
- wtbob 10y ago> They're relatively compact. Users compare 12 groups of 5 digits with each other, which is half the size of our previous hexadecimal format. 60 digits have 199 bits of security, so I suppose that's mostly okay, right? Does the birthday paradox apply here, reducing it to 98 bits?
- StavrosK 10y agoNo, since you presumably want to match a specific user's key, not just find two users with the same key.
- lenish 10y agoIt is a similar problem, however: https://en.wikipedia.org/wiki/Birthday_problem#Same_birthday_as_you https://en.wikipedia.org/wiki/Birthday_problem#Same_birthday...
- lorenzhs 10y agoThat's still not the problem considered here. You're not asking "does anyone have the key I'm seeing here", you're asking "does this person next to me have the key I'm seeing here". No birthday paradoxes of any kind involved.
- lenish 10y agoForgive me, as I haven't used signal, but I don't see how whether they are sitting next to you or not changes the problem. If I can generate a key that hashes to the same value as your key, I can convince anyone I am you. If I can generate a second collision for a third party's key, I can convince you you are talking to that third party, as well. Generating hash collisions is, as I understand it, pretty well modelled with the birthday paradox (and variations like the one I linked). Physical proximity seems entirely unrelated.
- lorenzhs 10y ago
- newman314 10y agoI'm not sure I like the UX for the disappearing messages. Having a little hourglass after every message breaks the flow up. I'd rather see the message bubbles be black instead of blue. It's also not intuitive to tap on a recipient's name to enable disappearing messages. Lastly, maybe messaging should default to 1 week disappearing messages...
- lettergram 10y agoI was thinking that too. I actually want my messages to just be deleted every month, but w.e. I'll take it.
- countingteeth 10y ago> Hexadecimal isn't compatible with all alphabets, so it left a lot of people out. Not ... really. Latin characters are available in every locale. Virtually anyone literate enough to use signal is going to distinguish the latin letters A through F. You reading this, I'm assuming you're not literate in Greek, but can you distinguish the letters α, β, γ, and δ, even if you cannot name them? Don't bring up CJK; virtually no one in this day and age is functionally literate in any CJK language that can't read the Latin alphabet. Let's take the hypothetical person literate in another script who is completely unfamiliar with the letters ABCDEF. They don't use our arabic numerals either. If you need to localize arabic numerals, why on earth couldn't you localize hexadecimal, too? Obviously, hexadecimal is not friendly to the layperson as a means of representing numeric quantities. But neither is comparing two 60 decimal digit numbers as a means of authentication. I don't think it's inherently easier for a layperson to match 60 decimal digits versus 50 hexadecimal digits.
- antocv 10y agoSignal is not anonymous. Antox from the tox.im people is a better more secure and anonymous messaging application. Ring.cx is also better.
- lorenzhs 10y agoSignal does not claim to be anonymous, nor does it try to be. Your recommendation misses the point.
- miguelrochefort 10y agoWho exactly uses Signal? Why do you think it's secure?
- uph 10y agoEdward Snowden, Bruce Schneier, Matt Green and a few more. I think it's secure because it's been audited, because I trust the experts who say that it is secure, because of http://support.whispersystems.org/hc/en-us/articles/212477768-Is-it-private-Can-I-trust-it- http://support.whispersystems.org/hc/en-us/articles/21247776... and because of https://whispersystems.org/bigbrother/ https://whispersystems.org/bigbrother/