7 ms·
I've been using Signal PINs for a long time to lock the app to my SIM card and unfortunately they are a real pain. This sounds exactly the same. First off the
by mapgrep 6y ago
I've been using Signal PINs for a long time to lock the app to my SIM card and unfortunately they are a real pain. This sounds exactly the same.
First off the app is incessant about asking you to enter your PIN to prove you know it; this prompt is supposed to get less frequent and I suppose it does but is still way too frequent. Some of us are competent at storing secrets in a password manager and this is like a punishment for us because it can easily take several minutes to go retrieve the strong password, copy it, paste it in.
It actually reduced the security for me; I started out with maybe a 16 or 20 digit PIN and cut it to a smaller number of digits that I could memorize. (I still haven't memorized them!)
There were also issues with Signal's implementation of the feature. I chose quite a long PIN (>20 digits) at first for security only to find out later from them that it was above the silently imposed limit. Later when I went to verify the PIN it would not work because whatever silent truncation was done when establishing the PIN was not re-performed on verification so it did not recognize the PIN.
- thanksforfish 6y agoI've found that tapping next to the registration lock PIN prompt will dismiss it on Android. A "dismiss" button and a "don't ask me again, I won't lose this" checkmark would make much more sense to me.
- tialaramex 6y ago> "don't ask me again, I won't lose this" This option should be labelled according to the reality rather than people's wishful thinking "Don't ask me again, when I lose this I am OK with losing the account and messages" There's probably a pithier way to express that we could get into the common lexicon as I foresee it being useful in many places. Maybe we can just label it "Yolo!" ?
- fwn 6y agoOr we could label it: "I use a password manager like every other tech-serious user." ... that would encapsulate the basic reality that no one can actually remember all their ~500 secure passphrases.
- fao_ 6y agoI mean, for a start the messages are stored locally, it doesn't protect the messages server-side, because they are never stored on the server. All the pin does is keep the server-side data, i.e. your address book and conversation information, safe. Secondly, outside of encryption, it should not be Signal's job to enforce whether a logged-in user of a phone can see that user's content. It is the operating system's job to enforce user-level security, and users of Signal are unlikely to keep their phones without a pin, fingerprint, or other level of authentication. The fact that you cannot turn off the option to lose all your messages when you lose a pin that you have been forced to set is horrific for those of us that rely on conversation history as a memory aid, and is precisely the reason why I have refused to set a pin.
- msh 6y agoWell most mobiles don't offer multi user and phones are often loaned temporarily to other people. For example for kids to play on.
- fao_ 6y agoAndroid 9 and 10 has multi-user. And if you take into account the "lending phones to kids" scenario it gets worse because that just means that when your 4yro kid gets your phone they can irrecoverably delete all your messages, simply by playing around with it.
- ccktlmazeltov 6y agohow hard is it to enter 4 digits right
- thanksforfish 6y agoI would recommend something much longer than 4 digits.