4 ms·
For most users, I think maintaining exclusive ownership of a phone number is much easier than securing their email account or a traditional username+password cr
by oil25 7y ago
For most users, I think maintaining exclusive ownership of a phone number is much easier than securing their email account or a traditional username+password credential, so posit it's a natural fit for a secure mobile messenger.
- dbrgn 7y agoMaybe for a secure messenger, but for a private one? It bugs me that I need to share my phone number with people that I want to contact on Signal, especially since Signal claims to focus on privacy. A private messenger should be usable anonymously, shouldn't it?
- deleted 7y ago[deleted]
- oil25 7y ago> A private messenger should be usable anonymously, shouldn't it? It would make a good feature, but anonymity is not a requirement for privacy. I want my connection to the bank's website to be private, but there's no need for it to be anonymous. Signal offers a lot of advantage over traditional SMS with familiar usability. It doesn't perfectly solve everyone's threat model for privacy and anonymity, and doesn't have to.
- jen_h 7y agoIt's not a natural fit for a secure mobile messenger if you want to stay anonymous. For some of us, security == anonymity. Tying your identity to a phone number that can only be obtained by handing a telecom your government identity documents fails. And I don't know if anyone else has mentioned this, but uploading entire contact lists should also not be considered a natural feature of a secure mobile messenger.
- oil25 7y ago> For some of us, security == anonymity. I don't follow. How is security equal to anonymity? If anything, security is what enables privacy, which could enable anonymity. There are plenty of circumstances where you need security, but not anonymity - for example a message to your partner. Of course if you do need anonymity, there's a lot more involved than simply installing a "secure app" or anything of that sort. > Tying your identity to a phone number that can only be obtained by handing a telecom your government identity documents fails. I don't know about that in the US. I was able to open a pre-paid T-Mobile account to use with my LineageOS Android device without identity verification. Perhaps it is different elsewhere now? > And I don't know if anyone else has mentioned this, but uploading entire contact lists should also not be considered a natural feature of a secure mobile messenger. That sounds troubling, is it what Signal does? Would like to read more about that - is there a Github issue for reference?
- jen_h 7y agoI’ve got this crazy feeling that you’re not asking these questions in good faith, especially if you don’t understand how anonymity is important for people using secure messengers or need a Github issue to inform you about a feature long-discussed in the app.
- oil25 7y agoIt was asked in good faith and I did explain my reasoning for why anonymity and security are different concepts. Have you got a citation for the claim that Signal "uploads entire contact lists" or was this just FUD?
- jen_h 7y agohttps://en.wikipedia.org/wiki/Signal_(software)#Contact_discovery https://en.wikipedia.org/wiki/Signal_(software)#Contact_disc... https://support.signal.org/hc/en-us/articles/360007319011-Edit-or-Update-Contacts https://support.signal.org/hc/en-us/articles/360007319011-Ed... https://signal.org/blog/contact-discovery/ https://signal.org/blog/contact-discovery/ But if you don't believe anonymity is an important component for security, you probably think hashes uploaded and deleted are perfectly secure, too, so we're probably not going to come to any agreement here. Personally, I do wish they'd decouple from phone numbers and allow users an option not to transmit hashes for their entire contact list. I don't think these are unreasonable features for a messenger that's supposed to be designed for privacy and activism.