3 ms·
Signal has done a lot of nice work on building a UI that conveys what nerds/paranoid people want to know for private messaging (e.g. "Your safety numbers with s
by keithwinstein 4y ago
Signal has done a lot of nice work on building a UI that conveys what nerds/paranoid people want to know for private messaging (e.g. "Your safety numbers with so-and-so have changed") while still providing a usable app. But for the most part, the threat model of "private messaging" is one that software can defend against pretty well; everybody understands that when Signal provides "privacy," they don't mean in the face of an adversarial receiver who wants to share the message with the whole world.
For a service like "messages that the receiver can read offline but the sender can later delete [or that auto-delete after 24 hours]," I'm curious to see how they handle the UI when the threat model is harder to defend against cryptographically, because it depends on software that isn't acting as a user-agent. Are they worried about people running rogue clients that save every message (or about screenshots?)? If so, how do you do a good job communicating to the nerdy/paranoid user that deletion is not guaranteed? Or does everybody already understand that auto-deletion is best-effort and shouldn't be treated as on par with the strength of assurance that Signal provides for privacy?
- klabb3 4y ago> Or does everybody already understand that auto-deletion is best-effort and shouldn't be treated as on par with the strength of assurance that Signal provides for privacy? No, but this is what we should teach. Even "best effort" is misleading. Auto-deletion should be considered a UX feature that only affects your own experience, not those you talk to. That said, in a high trust relation you can assume that auto-deletion is best effort, same as with your own devices. It should be seen as "this is a hint that helps your peer to delete messages, so that they don't stick around for everyone's sake".