5 ms·
The argument I hear in favour of this practice by messaging apps is that, this design helps your friends find you easily by your number. But I agree with you,
by malikNF 4y ago
The argument I hear in favour of this practice by messaging apps is that, this design helps your friends find you easily by your number.
But I agree with you, asking for the phone number and telling me this app is secure is ridiculous. Let me register with something less intrusive, if I want to go the phone number way, then let me use that. Give me an option.
- palata 4y agoNot ridiculous at all, depends on your threat model. It's perfect for me.
- malikNF 4y agoSo why do we need e2e encrypted messaging? Why do we worry about the "secure" part of messaging? One of the main reasons for me is, it's hard to trust a centralized authority. Can you trust your information stored at your messaging app's servers stay secure forever? Can you trust that company to never get compromised? So yeh, they go through all the hassle of making things "secure" but attach everything to something(phone number) most of us can't get without revealing our actual details. So yeh, its ridiculous to go through all this hassle to make things private and secure, but force people to use something that de-anonymizes everything about them.
- palata 4y agoI don't want them to have access to my messages and make a profile out of me, even less of billions of people. That's why I also care about metadata: social graph is valuable for profiling. I don't write anything that would be interesting to the NSA, I'm not a target for them, so I don't care if they see I use Signal. BTW, say you have an anonymous Telegram username, I'm pretty sure it's trivial to find your name from the content of your messages. Or just from the metadata.
- 8organicbits 4y agoIs there another technique for effortlessly bootstrapping a contact list? Finding someone requires some kind of lookup/search. Using PII makes a lot of sense because that's how people identify each other. Anything out-of-band is quite complex. If I told my mom to install some app and we'd connect to each other using some random IDs, we'd probably still be using SMS.
- andai 4y agoA Signal support claims "The Signal service does not have any knowledge of your contacts." Can someone explain how this is possible? How does my phone know when to notify me that a friend has joined signal? Edit: apparently it's "private contact discovery", I need to give this a proper read later. https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/
- palata 4y agoYes, their blog posts are really good. Read about the sealed sender, too! And then realise that even with sealed sender, if you send from your home IP, then you are identifiable. So you should send from a reasonably anonymous IP (w.r.t. your threat model)
- andai 4y ago>If I told my mom to install some app and we'd connect to each other using some random IDs, we'd probably still be using SMS This is surprising to me, since it was my mother's generation that got me into Skype (where you have to manually add the other person by their username), almost twenty years ago. (Even worse, not long before that you had to manually punch the other person's "ID" into the device every time you wanted to talk to them!)
- brandonr49 4y agoI will never get over the fact that the Nintendo Switch operated on random character strings to find friends rather than usernames or something more straightforward for normal users. But the fact that they managed it does mean it's not so large a barrier.
- uoaei 4y agoRepeat after me: Security and privacy are not the same thing. Among many other differences: security is a binary (can an attacker gain access to information) but privacy is a spectrum (what kinds of information do I want to leak).
- dane-pgp 4y ago> security is a binary (can an attacker gain access to information) Only if you're looking through a very narrow lens. There are a range of potential attackers out there with different motivations and resources available to them. The question you have to ask (for each attacker) is whether the value of the thing you are trying to secure is worth more to them than the cost it would take them to break your security. In aggregate, that looks a lot like a spectrum of security, with different people being secure against more or fewer different attackers.
- uoaei 4y ago"The thing" you are trying to secure is either secure or it is not. That is what I meant by "binary".
- dane-pgp 4y ago"The thing" you are trying to keep private is either private or it is not, too. Maybe you're saying that some information is more sensitive than others, which is true, but some security failures are worse than others (e.g. denial of service vs. remote code execution, or ability to forge messages vs. ability to decrypt messages).