9 ms·
How can I use this without a phone or phone number at all? If I am concerned about privacy, why would I give them that access and information when it's not nece
by usea 5y ago
How can I use this without a phone or phone number at all? If I am concerned about privacy, why would I give them that access and information when it's not necessary for the service? Surely they are only trying to gather information on their users. Whether it's being sold, breached, or used for ad targeting, I am not interested. It comes across as a scam.
I cannot take seriously any claims made by the company or its employees / owners. None of it can be used as evidence of their goodwill or what they do with my data. They have an interest in deceiving me.
- colordrops 5y agoThis is for proctecting your data from other end users. Signal still needs your number to provide to three letter agencies.
- sa1 5y agoOn the contrary, they started out with phone numbers so that they could avoid storing user data on their servers. The whole plan to finally have usernames comes down to their use of Intel SGX.
- colordrops 5y agoWhat does being tied to a phone number have to do with avoiding storing data on their servers or SGX?
- sa1 5y agoWith a phone number, the contact graph can be on the phone. With usernames, the contact graph has to be stored on their servers. They were forced to store (encrypted) information on servers anyway, since client-side contact matching didn't end up scaling, which is why stuff like this and usernames are now being developed. Their new security strategy now relies on decryption being done by client-attested code on SGX enclaves, so that the server still doesn't have access to the plain-text contact graph. All of this took a huge amount of time to come up with, and you can see the progress if you read their blogs or forums.
- colordrops 5y ago> With usernames, the contact graph has to be stored on their servers. Are you suggesting that there isn't a contact graph on their servers? How exactly do they route from one user to another? It's certainly not P2P. If you are suggesting that we should trust them just because it could work without them storing who I've contacted, you are mistaken. The whole point of private messaging is to obviate the need for trust. The code should be auditable/open source, and everything on the server should be either transparent, or assumed to be compromised. They certainly do send your contact graph to their servers, and whether they say they discard it or not is irrelevant. In the context of privacy, you must assume your data is persisted once it is behind a curtain you have no visibility into.
- sa1 5y agoThey only started sending your contact graph after adopting SGX. Before that the matching used to happen client side through a bloom filter. They can theoretically rebuild a contact graph by finding everyone you’re talking to, but that’s a small subset of the contact graph created by contact matching. The code is open source and SGX literally means that the client attests that the code on the server matches what it’s expecting. Signal might be the most audited stuff out there.
- colordrops 5y agoI trust bloom filters more than SGX. I assume they stopped using bloom filters because of performance or reliability reasons? Also, aren't most mobile processors not Intel? How would SGX be used?
- sa1 5y agoHere you go: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/
- colordrops 5y ago
- shishy 5y agoI don't think it's so nefarious... phone numbers were just the easiest way for them to create a portable social graph without requiring users to re-discover if anything changed. Plus, it looks like this move is going to push them in a direction where phone numbers won't be required (as they've indicated previously is in the works).
- colordrops 5y agoOk, but now that it's not tied to phone numbers anymore why do you still need one to sign up? And why has this been "in the works" for years? It's certainly not that hard to implement. Many less capable and mature messengers work without a phone number.
- Vinnl 5y agoIt is still tied to phone numbers; you can now just change which one. It's hard to implement it in a privacy-preserving way. Many other messengers of similar scale implement it by storing your social graph unencrypted on their servers.
- palata 5y agoI am pretty sure it's harder than you think, while keeping Signal's UX and privacy level: https://signal.org/blog/secure-value-recovery https://signal.org/blog/secure-value-recovery
- colordrops 5y agoWhat does this have to do with being tied to a phone number?
- its_bbq 5y agoSignal is about as reputable as you can get for e2e encrypted chat
- iratewizard 5y agoSignal is high up, but matrix is higher in my book.
- palata 5y agoGenuinely interested: can you elaborate on what metadata the matrix servers have access to? Say, don't they know who I am writing to, when and which groups I belong to? Signal does not, and that's guaranteed by the client code (i.e. no need to trust anything on the server for that).
- mort96 5y agoA cryptocurrency scam isn't super reputable IMO.
- tapoxi 5y agoThey're working on usernames, but what's the privacy concern around using your phone number? Is it to be pseudononymous? My use case for Signal is friends and family, and it was easy to get everyone onboard because we all have each other's phone numbers already and didn't need to build a new list of contacts. It's a drop-in Android-compatible replacement for iMessage.
- sgarman 5y agoPersonally I don't have a privacy issue with it per se but I have two phones, one is data only sim and I can't use signal on that device with their current model. I guess because the device is a "phone" whatever that means. If they do away with this reliance on phone numbers hopefully we could get something more flexible that allows me to use it on "phones" without phone numbers.
- tenuousemphasis 5y agoDid you try this? It should let you use Signal on two phones https://signal.org/blog/ios-device-transfer/ https://signal.org/blog/ios-device-transfer/
- rhn_mk1 5y ago> the privacy concern around using your phone number You have to give up your anonymity to get one in many places.
- 5y ago
- wyager 5y agoCheck out Wired; it's a signal clone, but they don't require phone numbers (just emails) and it seems to be built a lot better in many ways (e.g. allowing multiple accounts on one device).
- palata 5y agoHow does it compare in terms of privacy? I mean Signal's private contact discovery, private groups, private profiles, sealed sender, etc?
- deleted 5y ago[deleted]
- stjohnswarts 5y agoYou can't. Every engineering choice is a compromise. I don't know why everyone assumes that these choices are always malevolent. I guess you can just not use it? Lots of us use it everyday without issues. If you want something that suits all your needs there are PLENTY of libraries out there for you to throw together your own adhoc distributed encrypted messenger. I have done it a couple of times myself just for fun.
- deleted 5y ago[deleted]
- goatsi 5y agoUsing phone numbers as identifiers for encrypted messages is the core feature of Signal. It was marketed from day one as a drop in SMS replacement. Initially it even used SMS as the transport for encrypted messages. It was literally called "TextSecure". This is why I have always found the attacks on it using phone numbers to be amusing.