5 ms·
> Signal uses standard cellular mobile numbers as identifiers Exactly and what's to say I want some random guy on the internet being able to call my phone. Ke
by dngray 7y ago
> Signal uses standard cellular mobile numbers as identifiers
Exactly and what's to say I want some random guy on the internet being able to call my phone.
Keep in mind tptacek quite literally pastes replies gushing about Signal/Wire in any thread related to PGP or instant messaging. They even paste it in threads which mention PGP but talk about other issues such as file encryption, signing etc, ie the uses not covered by an instant messaging platform. I have come to just skimming over anything they say because of it. Come on, put a bit of effort into your reply.
> Wire uses metadata but only requires an e-mail account.
It also doesn't offer federation. At this point I think Matrix is the best hope if you're okay with minimal metadata. It is also making huge strides of progress if you keep up to date with their development, so that's exciting. https://matrix.org/blog/posts https://matrix.org/blog/posts
> There is Cwtch (https://cwtch.im/ https://cwtch.im/) that extends Ricochet to support multi-party messaging. I did not dig deep into it, but it may use the same algorithms. Additionally, it uses a language with a GC.
I have high hopes for Cwtch. It seems to be a common thing people don't want to address: metadata. That said you can have a fairly meta-dataless experience with Matrix if you run a server and don't federate.
Ideally I'd like to see this get solved https://github.com/vector-im/riot-web/issues/2320#issuecomment-485227466 https://github.com/vector-im/riot-web/issues/2320#issuecomme...
- pvg 7y agoquite literally pastes replies Can you find a concrete example of that?
- dngray 7y ago> Can you find a concrete example of that? I should have been more clear on that. Their own replies, look at their post history. It's usually something like "Use Signal/Wire blah blah they are so good and will solve all the worlds problems". Someone then always points out that Signal requires you to share your phone number. Who wants to do that publicly? Then people usually say the desktop client is pretty bad experience and you need Signal on your phone anyway to be able to use it. Even if you use a disposable SIM, the issue comes up with the number going back into the carrier distribution pool to be issued to new customers. Phone numbers are a terrible way to identify people. Unlike email, where you can have spam filters, phone numbers have virtually no user controls for stopping unsolicited communications. Hell even IRC has that it's called /ignore. Often then the next thing that gets mentioned is Signal does not like people making third party clients, so that means no nice TUI client or something that is native for your platform. I dunno about you, but I go out of my way to avoid Electron. I am thankful that at least with Matrix, there are other clients being developed, and tools like Pantalaimon that will allow for easy encryption everywhere. https://github.com/matrix-org/pantalaimon https://github.com/matrix-org/pantalaimon I have blind friends and they say Electron applications are terrible. By that I mean non-functional with their screen readers, so that's a 0/10 for accessibility. And then someone else always points out Wire has metadata and isn't even federated like Matrix so you're back to square one.
- pvg 7y agoIt's usually something like "Use Signal/Wire blah blah they are so good and will solve all the worlds problems". But it's not that or something like it. Nor is it "literally pastes replies". You can take issue with both the opinions and the way they're presented. You can't mis-represent them, though, and that's what you're doing.
- mikekchar 7y agoTo be completely fair tptacek is a recognised security expert. Yes, he likes Signal. Apparently like you, I disagree (their refusal to implement non-personally identifying information as an identity is enough for me). However, I'm not a recognised security expert (and just between you and me, I'm not actually a security expert... or even more than mildly competent... maybe not even that... ;-) ). He's got his opinions and he states them pretty clearly. I don't think that's a crime. I've discussed his opinions with him in threads before and I can't see anywhere where he's obviously wrong. When I've asked him directly about the identifiers, he's declined to answer -- which makes me think that he probably agrees but thinks that the other issues are more important than that. I could be wrong, but that's my impression.
- johnisgood 7y agoPhone number as a requirement and an identifier is pretty serious in the context of security and pro-privacy. In my opinion it disqualifies any IM software if security and privacy is desired. Yes, there are other things to consider, but this issue alone is a deal-breaker, at least to me.
- pvg 7y agohe's declined to answer -- which makes me think You don't have to, it's easy to pull the plentiful relevant hadith: https://hn.algolia.com/?query=author:tptacek%20signal%20phone%20number&sort=byDate&dateRange=all&type=comment&storyText=false&prefix&page=0 https://hn.algolia.com/?query=author:tptacek%20signal%20phon...
- mikekchar 7y agoCool. Thank you. It seems that my assumption was correct :-)
- pvg 7y agoAbout the phone numbers? Not really how I read it. But that's just me - my impression from reading endless secure messenger HN threads is that both 'phone numbers' and 'federation' are ideological sideshows that have very little to do with the actual security and privacy properties of secure messengers.