13 ms·
Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still
by uncomputation 4y ago
Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.
- deleted 4y ago[deleted]
- A4ET8a8uTh0 4y agoI will admit that this requirement always confused me. What is there to benefit from by requiring it?
- moontear 4y agoLess spam. A phone number is a much better deterrent against opening a hundred accounts than let’s say an email address.
- rakoo 4y agoIt's the easiest anti-spam measure, because it makes it expensive enough that spammers won't have a million accounts. Fake account detection is effectively put on the back of mobile carriers
- dogecoinbase 4y agoThey trade your privacy for not having to figure out some technical issues. Also, when they rolled out their cryptocurrency payment system (after keeping the server-side source code secret for more than a year, during which Moxie, who is a paid advisor to that same cryptocurrency, denied they were working on a payment system), they got KYC for free.
- MobiusHorizons 4y agoI believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.
- charcircuit 4y agoWhy not just store a contact list of usernames on the phone though?
- dcow 4y agoWhat would this list contain? You don't have a signal username. If you did you'd have to claim it somehow (degenerates to email or phone verification). It's not that simple. Using phone numbers allows signal to plug into the existing state of the world and leverage it to upgrade the security of messaging for everyone who uses it. The one compromise is that it treats phone number as a short identifier (importantly, not cryptographic, it uses real crypto for that). If you don't use phone numbers, your product would look more like Keybase. You have to somehow facilitate key exchange between people in a way that's actually usable. Otherwise all your security benefits go out the window because nobody uses your product. Signal understands this nuance perfectly which is why they're a successful product.
- k1t 4y agoIf I don't use Signal, then I'm not going to keep a list of my friends' Signal usernames on my phone. If I subsequently sign-up for Signal, then I have no way to discover which of them use Signal - short of contacting them via some other method and asking for their Signal username, if any. By making the Signal username the same as the user's phone number, I actually DO have a list of Signal 'usernames' on my phone already. As soon as I sign-up, I can send my list of friends' phone numbers to Signal and they can tell me which of those people have Signal accounts.
- autoexec 4y ago> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers permanently.
- CodesInChaos 4y agoMaking it more expensive to create spam accounts, I'd guess.
- fooqux 4y agoBesides fighting spam accounts, finding and connecting with others is easier. No more needing to ask somebody what their account name / friend code / ICQ number / whatever UID a system uses to add them to your contacts. It's not a good user experience to type in someone's sometimes insane username. Meanwhile, someone in my contacts that installs Signal automatically sees my name pop up and can start chatting. Far easier, and helps drive adoption.
- Macha 4y agoExcept the reality is that I'm asking for a phone number to add people (well on whatsapp here in europe), and most screen names people chose can be communicated verbally while phone numbers often have people resorting to handing the phone displaying the number around.
- cmeacham98 4y agoThere's no need to make it a requirement for this. Matrix has similar functionality, but doesn't require that you add your phone, just makes it an option.
- konschubert 4y agoWithout it, you wouldn’t be able to see which of your contacts are on signal. And then nobody would use Signal. It’s very unfashionable today, but they decided to not let perfect be the enemy of good.
- panick21_ 4y agoWhile that is nice, I see no reason to require that. Some people just don't care about that feature.
- dcow 4y agoWhat is this future UX you're imagining? How does the future solve the contacts book/short identifiers problem?
- fezfight 4y agoJust like this website. Usernames. Easy peasy.
- dcow 4y agoAnd how do you claim a username?
- deleted 4y ago[deleted]
- aaaaaaaaaaab 4y agoBy knowing the password?
- dcow 4y agoWhere do you put the passwords DB?
- panick21_ 4y ago
- adrr 4y agoUsing the phone number as the identity. You need to verify ownership of the phone number to prove your identity. I guess they could use email as an alternative.
- mbrubeck 4y agoIt means that Signal doesn't need you to create or upload a list of your contacts; it uses the existing contact list from your phone. This also lets you use Signal to replace the default text messaging app on Android, automatically upgrading conversations to be encrypted when possible. This in turn means that just using Signal to communicate with someone becomes a normal, everyday activity, and less of a sign of suspicious activity (from the point of view of law enforcement, etc.).
- fezfight 4y agoI think the problem is that it's a requirement, not a feature you can choose to use. I'd be more inclined to use Signal if I choose to use only a user/pass. Just need a block function.
- dcow 4y agoHow would other people contact you?
- getcrunk 4y agoWith your username?
- dcow 4y agoHow do you text a username?
- Volundr 4y agoBy opening signal, putting in the username and sending a text. Signal only uses MMS as a fallback when communicating with someone not on signal. When both parties are on signal SMS/MMS is not used. Presumably they are OK with not being able to communicate with people not on signal.
- sofixa 4y agoWhy do you need to text? Sending messages without the arcane UX and unreliability of old school SMS or the tries at improving it(RCS) is simply better.
- xorcist 4y agoBeside the technical reasons, tech companies are valued from their access to contact information, and Signal has had huge investments made. This despite the obvious fact that it is highly unlikely that Signal would benefit directly from that data in any way. But much Signal's design is taken from the companies that came before, which did.
- dijonman2 4y agoIt also pushes fraud detection up the pipeline to mobile operators.
- dcow 4y agoI wouldn't even call it bad. In may ways it's good, actually. It's good because it allows signal to build a product that is relevant and usable. Phone numbers only connect people and are a bridge to allow all the perfect crypto to do the legwork. The knee jerk "phone bad" reaction is understandable, sure. But I don't think it's warranted for Signal. Signal would look like Keybase without phone numbers. Keybase (or their key exchange UX, at least) is great. But it's not the same product.
- baby 4y agoPeople use telegram more and more which is based on usernames...
- deleted 4y ago[deleted]
- lrvick 4y agoI refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consider they have centralized control of client binaries, and metadata protection anchored on centralized SGX they can trivially access. This negligent design makes them vulnerable to coercion or even court orders if any judge realizes they actually -can- decrypt messages and dump metadata. Matrix supports Signal crypto but in a federated network with no PII requirements like Signal. Also no lock-in or central control of apps.
- Thorentis 4y ago> abortion seekers Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.
- HideousKojima 4y agoI wonder how the people putting "abortion seekers" on such lists would feel if I included "self-defense rights advocates" for people 3d printing guns or smuggling them in from abroad on similar lists.
- lrvick 4y agoI would have no problem seeing that included on such lists either. I have friends who hunt and I myself enjoy shooting on a range once in a while. I also know single parents that live alone in sketchy areas that are well trained and level headed enough to trust with firearms for home self defense. There are almost always reasonable uses of many services and tools we tend to have knee-jerk-ban reactions to as a society.
- Volundr 4y agoI'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so. I haven't done a deep dive, but as far as I can tell in most cases it's legal to 3d print too, though admittedly that's something that there are some semi-serious efforts to change. In other words I'd suspect the classification of "self defense advocate" to be a self serving branding effort since there are legal ways to accomplish the same, but I wouldn't doubt the need of this person for a secure messaging platform.
- cookiengineer 4y ago> don’t store any messages on their side Google Play services are still required for the official builds because of the (unverifiable to be really) encrypted backups. > everything is client-side Signal's FOSS fork developers would disagree. They got outright legal problems after they wanted to implement an open source alternative. Most APIs in regards to contact management are server-side. There's Molly as a younger fork but I'm waiting for Signal to write them also a cease and desist letter. Honestly this is why I think that Signal should be treated the same like WhatsApp. Supposedly end to end encrypted, but only until you suddenly have the FBI with printed out chats in front of your door. As long as Signal uses proprietary services and contains proprietary blobs in their (default aka Play store-provided) app we have to treat it as an unsecure messaging system. Especially given the RCEs that it had in the past, where it was as simple as injecting an HTML with a script tag to install malware on your system.
- exyi 4y agowe still don't know of anyone with their messages printed out. Signal probably doesn't have all the contacts hoarded on their server, while WA certainly does. For me, there is a big difference in "might be buggy" vs "certainly is privacy hostile" I still prefer Matrix, but Signal is clearly the next best thing for chats. And it also has quite a number of non-HN users :)
- MayeulC 4y ago> Google Play services are still required for the official builds because of the (unverifiable to be really) encrypted backups. ??? I use the official build with encrypted backups without Google services, and have been doing so for at least 3 years. I've been forward-carying my backup since 2016, too.
- deleted 4y ago[deleted]