5 ms·
I was worried about sharing broadly and leaking info from 1 contact to another, but it seems like the Signal team did all the right things here. When you creat
by fitblipper 4y ago
I was worried about sharing broadly and leaking info from 1 contact to another, but it seems like the Signal team did all the right things here.
When you create a story you can make it a group story or not.
If you do not make it a group story, reactions and replies to stories get sent to you over your 1:1 chats and not shared across other recipients of the story.
If you make it a group story, and share it with multiple groups each group receives their own copy of the story and replies and reactions can only be viewed by others in the same group.
After having been burned SO OFTEN by other social platforms embarrassingly notifying others when I did something I thought was a passive post, or leaking information from 1 of my subgroups with another I was very worried that would happen here, but great job signal team!
The only awkward part that I've noticed so far is if I have a contact in 2 groups that I create 2 group stories with, they now have 2 identical stories show up on their story board. It makes sense and I think the UI clearly indicates for which group replies and reactions to each story it would go to which is probably the safest (best?) solution, but I could see that getting a little annoying if I share multiple groups with a frequent story poster.
- stavros 4y agoIt seems to me that, under the hood, stories are implemented as simple messages. To publish a story to 200 friends, you just send 200 photo messages to them. Group stories are a group message (and hence separate per group), which is a very good abstraction.
- cfhhgtyg 4y agoIn groups you do the same: send a photo message to every group member
- kibwen 4y agoI'm still of the opinion that encrypted private group chats are an impossible UX problem (1:1 chat is fine). But if I were to trust anyone to find a way to do it properly, it would be Signal.
- OkayPhysicist 4y agoWhat makes it impossible? Naively I would think that if you have a secure 1:1 communication protocol, then you can send N*(1:1) secure messages to a group of N people. To solve the "fake group message" problem where an adversarial member of the group sends different messages to different members of the group, or delays the message to some members, the protocol could simply allow for a 2nd level "vouch" message to be sent, such that Alice sends the message to Bob, Alice sends the message to Charlie, Charlie messages Bob a receipt with the receive time and a hash of the chat log, and Bob messages Charlie a receipt with the receive time and a hash of the chat log. If the hashes don't match, or the receive time is unacceptably different, then you highlight the message as suspect. Sure, it takes N^2+N messages, but that's not exactly a massive overhead for text. Multimedia takes N times as much bandwidth as the 1-server, server-many model for the sender, but otherwise isn't terrible.
- waynesonfire 4y agohavn't thought about it too much, but seems like merkle tree may be able to tackle this problem.
- deleted 4y ago[deleted]
- ChadNauseam 4y agoAh, but what if I send different vouch messages to different users? There is actually a way to do it, if you assume PKI (which signal provides) and that all messages will be delivered in some bounded time. It’s called the dolev-strong protocol and it guarantees that all honest members of the group will agree with each other. Unfortunately, it requires one round per group member and delivering all messages within a bounded time isn’t easy.
- OkayPhysicist 4y agoSince you'd be receiving vouches from all group members, you'd get some data about who trusts who's message. To the user, you'd probably highlight the message with the "something's fucky" notifier (red background? a caution symbol?) and then have the further "of X vouches you've recieved, these Y disputed the message's (content/existence)" type deal. Which lets you know that Alice and Bob are in contention, which is probably good enough for most situations. "One of these three (or more if you have multiple groups of bad faith actors) sets of users are operating in bad faith" should be plenty of information for a user to make an informed decision. Even if that decision is "wow, how did I end up in a group containing multiple groups of bad actors, I should be elsewhere".