8 ms·
I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed
by ludocode 6y ago
I'm extremely disappointed about how this Signal PIN rollout has been handled. Signal refused to let me view my received messages until I created a PIN. I filed a bug report about it [1]. I don't know if I was just caught in an A/B test or what because it hasn't happened to all of my Signal-using friends but it happened to me.
I don't understand why it isn't just optional. They claim they want to protect my Signal data stored in the cloud. I don't want my data stored in the cloud. I want them to store nothing. I don't care about their Intel SGX whatever because I don't want to have to trust their servers in the first place.
Cloud storage is a complete non-starter for me. I started my company to get away from cloud storage [2]. The fact that they are forcing this on their users is making me seriously consider dumping Signal. I just don't know if there are any sane alternatives.
[1]: https://github.com/signalapp/Signal-Android/issues/9632 https://github.com/signalapp/Signal-Android/issues/9632
[2]: https://homefort.app/ https://homefort.app/
- saurik 6y ago> I don't care about their Intel SGX whatever because I don't want to have to trust their servers in the first place. Yeah: particularly given how Intel SGX gets broken every year :/... prime+probe, foreshadow, load value injection, plundervolt... Moxie's fetish for Intel SGX is extremely concerning.
- RL_Quine 6y agoSGX has simply just been shown to be incompatible with secure software and is impossible to justify. Signal can happily operate without the need for this sort of thing to begin with, but they keep insisting on weak solutions for no reason.
- ccktlmazeltov 6y agoThese weak solutions are actually enough to keep the government requests at bay, for the moment. Why go into crazy crypto theory if that's good enough right? That's what Apple and Google are doing as well.
- saurik 6y agoAs far as I understand, Apple is using dedicated secure enclave chips in their iCloud keychain service; the attacks against SGX are usually (admittedly, not always) side channel attacks due to being able to use the CPU for arbitrary insecure execution and then use that to extract information from the container. It is also my understanding that Apple controlled the keys for their hardware, and could watch themselves destroy the key: as far as they know, they can't access the data themselves and nor can anyone else... Intel SGX is subject to upgrade keys from Intel and their remote attestation can be forced by Intel: if a government wants the data they should bring the computer to Intel and start a similar battle to the one the FBI had with Apple on their older phones (where Apple already had a back door but didn't want to be forced to use it by signing a firmware to access the phone).
- RL_Quine 6y agoI’d really like to have a more sane version of Signal as a fork, which allows the maintaining of compatibility, but given how hostile they’ve been towards this sort of thing I suspect it would be unmaintainable.
- jtl999 6y agoThey don't block third party clients ala WhatsApp, but going on GitHub and arguing with people isn't a good thing either :/
- marssaxman 6y agoI think I liked Signal better when it was just encrypting text and sending it over SMS. I noticed recently that someone has been maintaining such a fork, under the name "Silence", but haven't had a chance to try it yet.
- cvwright 6y agoI used Silence as my primary SMS app for several years while I was on Android. Overall I had no complaints. Beware though, they seem to have been booted out of the Play Store at some point, so you might need to install through F-Droid.
- Jarwain 6y agoFrom what I understand, they are fine with forks of Signal as long as these forks have distinct branding and don't depend on OWS services to operate, I'd imagine because they don't want the operational burden of ensuring the compatibility of third party clients nor confused users going to OWS for support instead of the third party devs. Which, imo, is a pretty reasonable decision.
- themihai 6y agoDoes homefort sync over the lan or it requires a 3rd party/ proxy broker? It says "The mobile app connects to your home computer" which concerns me a bit as it sounds like a VNC headline.
- ludocode 6y agoThe idea is to use try to use NAT traversal (i.e. STUN or UPnP) to get a direct connection, and otherwise relay (i.e. TURN) with end-to-end encryption. I'm hoping IPv6 will eventually allow direct connections everywhere so nothing needs to be relayed. I haven't built that stuff yet though so the current version requires that your home computer has a public IP address and that you open a port in your router. Obviously it's only usable by technical people right now, but I do eventually want this to be something my mom can install and use on her own.
- lann 6y agoCheck out zerotier; I've been looking at similar p2p techniques and ZT does a good job of packaging them all up with a relaying fallback.
- novok 6y agoIsn't the point of something like this PIN that the only thing stored on the cloud is an encrypted blob that they don't have the keys to? That way it doesn't matter if SGX or similar breaks or not, since the encryption is only happening on your devices. The PIN is the key.
- saurik 6y agoThe PIN is a very short key, so the only real protection is that Intel SGX (which notably gets broken every year, and so this doesn't actually work) is preventing people from getting access to the encrypted data to brute force the key; the enclave then enforces some limit on the number of attempts (and maybe some rate limit on the speed of attempts).
- RL_Quine 6y agoThe client allows them to be alphanumeric, but the default is 4 numbers. The irritating behaviour of repeatedly asking for it to be entered at awkward times means people will just set it to 1337 and call it a day.
- Skunkleton 6y agoI used my debit card PIN, so I should be fine right?
- deleted 6y ago[deleted]
- jacobush 6y agoBank level encryption. Yep, fine.
- mos_basik 6y agoI haven't even opened Signal since hearing about this update, so I don't know how irritating the prompts are, but I did see this in the blog: >Because Signal doesn’t have access to your keys – or your data – your PIN isn’t recoverable if you forget it, so our apps help you remember your PIN with periodic reminders. Don’t worry, these reminders get less frequent over time. Having read that, I doubt I'll get too irritated at the reminders and eventually they'll go away. You have a point that anyone who hasn't read the update blog will have no similar hope and might use something easy. I guess I'd hope the Signal user base is more security conscious than that. For instance, I know my PIN is going to be alphanumeric and immediately stored my password database.
- Arnt 6y agoIt's not optional because its purpose is incompatible with that. They want to add signal identifiers that aren't phone numbers. If such identifiers are to communicate with you, you need to store what's necessary.
- pas 6y ago> It's not optional because its purpose is incompatible with that. I don't blame signal for forcing strong PINs, I don't know what's their purpose, but non phone number identifiers don't require cloud storage. The contact list (with the associated public keys) does. What? How? You just need a key (password). If you are able to log into that "identified" then you are online with that and others can message you on that, and the network will route messages to your client. There's nothing to store up to this point. And if people want backups they can optionally enable that. Or the network could support multiple clients signed in for the same "identified" and allow those authenticated and authorized clients to sync/backup among themselves.
- quambene 6y agoI was quite disappointed as well. I guess the only way to go is to use a strong password, which is NOT "memorizable" and hope that the reminder banner won't show up too often. Very sad ...
- dessant 6y agoI think they've messed up badly with this update. I have several friends who want to get rid of Signal because they could not access their messages until they've set up a PIN. Imagine needing to configure and remember a PIN on the spot when you need to urgently read your messages.
- arsome 6y agoInteresting, mine keeps nagging me at the bottom of the screen every day, but hasn't forced it on me at all yet.
- sliken 6y agoI've lobbied for signal, and gotten friends and family to join. Most are annoyed by the PINs and some have left. Their handling of PINs seems quite contrary to their goal of pretty good security for the largest possible number of people. It's VERY frustrating to have your device asking for pins every time you use it. I'm trying to protect from attackers on the internet, not someone who is going to assault me. After all if they assault me for my phone they can assault me for my pin. Single devs need to read https://xkcd.com/538/ https://xkcd.com/538/
- Skunkleton 6y agoThat's not what the PINs are for.
- andrepd 6y ago>I guarantee you, the vast majority of Signal users are only using it because they have some weird privacy-obsessed friend (i.e. us) that has roped them into using it. They don't care enough about Signal to memorize a PIN and get constantly tested on whether they remember it. They want it to just work. This cannot be stressed enough
- coronadisaster 6y ago> I don't understand why it isn't just optional. they probably got served with a secret order from the gov.
- moxie 6y agoRight now if you re-install Signal on your device, you lose all your messages. That's already a very bad user experience, but imagine how much worse it would be if you lost your entire address book in that moment as well. Right now that's not a problem because your social graph is in the address book on your phone, and isn't managed by Signal. This is one of the primary reasons that Signal uses phone numbers for addressing: it leverages an existing user-owned and user-managed social graph. However, what we've repeatedly heard from users is that they don't want addressing to be based exclusively on phone numbers for a variety of reasons. If we're not using that social graph, then where does the Signal-specific social graph live? For every other app in the world, the answer is that it lives in a server-side plaintext database. Snapchat, WhatsApp, Telegram, Matrix, Wire, FB Messenger, Skype, etc etc... they're all just storing your entire social graph in a plaintext database (along with a bunch of other stuff, like your groups, profiles, etc). Given the way that technology has developed (devices are fundamentally designed for a world of clients and servers), it's probably not possible for us to build something that makes no use of servers. Instead, we've focused on building something that doesn't store or transmit any sever-side plaintext. For instance, when you set your Signal profile name and avatar, that lives "in the cloud" so that other Signal users can retrieve and display it. But it's encrypted (https://signal.org/blog/signal-profiles-beta/ https://signal.org/blog/signal-profiles-beta/), so only your contacts can see it (not us). With Signal Private Groups (https://signal.org/blog/signal-private-group-system/ https://signal.org/blog/signal-private-group-system/), again we have to store data "in the cloud," so that there's a canonical data source for group management, but again all of the contents are encrypted so that only group members can see it (not us). In this case, we're using Secure Value Recovery to ensure that a future addressing scheme that's not based on phone numbers is available across app reinstalls, phone switches, phone loss, etc. We could have just done what every other consumer messaging app in the world has done (store it in plaintext on the server), but we built this instead. It is the most user-friendly option that we could conceive of while still being privacy preserving, and took a lot of engineering work. We're going to keep looking at all the feedback we've gotten, though, to try to make it the best experience we can.
- mnm1 6y agoThe point is not to force this idiocy on people. Losing my messages and contacts when setting up a new device is actually a great feature. I regularly delete them and signal even has a feature to do so automatically. And forcing people to create a pin in the ui is just lousy ux. Until I read this article, I had no idea what that meant and just wanted it to go away. Now I want it to go away even more. Edit: it's especially stupid if you can't use a pw manager with it. I haven't tried it because I don't want to set one. Once I'm forced, I'm going to ditch signal. Fuck that.
- deleted 6y ago[deleted]
- petre 6y agoOne alternative is Wire. I use both. My partner uninstalled Signal when it failed to work from within the UAE and could not contact me. If she wouldn't have done it then, she would now with this PIN nonsense. At least we can text via Wire.