7 ms·
So far the biggest weakness of Signal is identification via a phone number. It's not only hackers who can spoof the numbers, but an authoritarian governments to
by viktorcode 1y ago
So far the biggest weakness of Signal is identification via a phone number. It's not only hackers who can spoof the numbers, but an authoritarian governments too may take ownership of a number at any moment.
Addressing future threats is good, but priorities should be different.
- exo762 1y agoYou can set a password in Signal, preventing movement of your account in case of SIM hijacking. Feature is called "Registration lock".
- array_key_first 1y agoIts a difficult problem because you, ideally, want to curb spam. Requiring phone numbers is a somewhat easy and somewhat reliable way to do that.
- jadbox 1y agoSort of. There are now immense warehouses filled with racks of used cell phones to generate spam. Limiting by phone number helps, but it's FAR from being an adequate cure.
- meowface 1y agoIf no one knows your user ID besides you and the people you share it with, why would spam be a big issue? If it's a random string, I don't know how anyone could get it, unless you share it publicly or with someone untrustworthy who shares it publicly. And even if it's a username users choose, as long as there's no directory it still shouldn't be a big problem. That is - even if someone makes 1000 bot Signal accounts, what can they really do with that if they don't have a good way of enumerating other Signal users?
- godelski 1y ago> if they don't have a good way of enumerating other Signal users? You can always brute force. Btw, if you don't accept message requests from spammers they have no indication of if you have an account or not. Try sending a message to a friend who you haven't added on signal. You can just see you sent the message but not if it was received or rejected or anything. Not until they click accept
- meowface 1y agoIf it's a sufficiently long random string, that shouldn't be possible, right? Admittedly not an amazing user experience to have to share a random string to your friends, but many Signal-like apps do this. Great point that requiring a friend request beforehand kind of eliminates the issue too. I assume the Signal developers do have a good reason for thinking requiring phone numbers reduces abuse, but I'm having trouble understanding it.
- godelski 1y ago> Admittedly not an amazing user experience to have to share a random string to your friends And struggle to get adoption. If it's too long, it's hard to share but difficult to brute force even with massive parallelism. But you can always brute force, it is just about how effective brute force is. Entropy is a double edged sword. It's also harder to then do contact discovery to find who's already in the network. Which is the basic principle of any social network (yes, I'm calling old school landline phones a social network too). It's a tradeoff, right? And it's worth noting that usernames exist now and this is serving as a bridge. You can provide links and QR codes too. I think this is a fair system and allows my grandma to use signal while still providing a path forward to another paradigm. This brings me to one of my critiques of signal. I wish they would recognize we all have multiple identities. My real name obviously isn't godelski. But I might want to link my contact here on HN but not reveal to those people that my actual name is "Joe Schmoe". We don't need unlimited identities but having 2 or 3 could really do a lot for privacy. Let me have a little more granularity over my privacy settings. Let me have some people contact me via godelski.## and some by joeschmoe.##. The former sees my name as "godelski" and the latter as "joe". And to be clear, the phone number issue is privacy related, not security.
- bravoetch 1y agoWhitelisting solves spam. Phone numbers should be obsolete by now.
- ajsnigrutin 1y agoYou don't need phonenumbers to deal with spam, just set the "allow messages only from contacts/friends" and a way to add new contacts when needed (via username, email, or even a phone number). It used to work without issues with protocols like MSN messenger, aim, icq etc.
- johnisgood 1y agoMany other secure IM software managed to work without phone numbers and they are also metadata resistant. Signal should start doing things that way. In many countries your SIM card is tied to you, which is a huge deal-breaker.
- 0rzech 1y agoYup, in Poland, a mobile phone number (pre-paid or not, it doesn't matter) is tied to a PESEL number [1] at the time of purchase. The official justification, as usual, was combating crime, but the end result is a tighter grip on citizens' privacy by the government while spammers and others continue their business as usual. [1] https://en.wikipedia.org/wiki/PESEL https://en.wikipedia.org/wiki/PESEL
- zelphirkalt 1y agoSame or similar in Germany. Almost impossible to get a SIM card without showing up somewhere with your id. Or I don't know how to.
- WhyNotHugo 1y agoJust step into a random supermarket in a neighbouring countr and buy a SIM in cash at the register. It's crazy how heterogeneous rules are inside the EU.
- godelski 1y ago> identification via a phone number. Identification of what? That you have a signal account?[0] I'll admit that that's not ideal but I'm unconvinced this is a big issue. > an authoritarian governments too may take ownership of a number at any moment. Suppose they did hijack the account. This would not give them the message history. You know that, right? It also kicks out the original owner, warning them they've been pwned. Don't get me wrong, Signal has issues and we should be critical and hold them to high standards. BUT *they are only E2EE and low metadata Messenger that my grandma can use.* That's a big fucking deal. If we want secure communication to be common place we need to make sure it's usable. Sure, there's more secure and more private services, but none that my grandma could use. I very much think signal should shift focus to privacy as they've got the security side pretty well handled (as this blog illustrates). But also these comments at the top of any signal thread feel a bit out of touch. Maybe I'm reading too much into it but there's a lot of people who confidently act like this compromises security or places harm on a user. The existence of a registered signal account means very little, especially as you note numbers can be spoofed. You need more than a number to hijack an account and hijacking only reveals messages moving forward while telling the compromised user they're compromised. So can we focus on bigger issues? Can we critique while still recommending? I have no problem saying I have issues with signal and wish they did more while acknowledging that it is strongly my preferred means of contact and I try to convince others to talk to me that way. These things are not at odds. I've gone so far as donating to them several times because I use the service so much [0] https://signal.org/bigbrother/ https://signal.org/bigbrother/
- WolfeReader 1y agoImagine being someone who would downvote this without a comment. Is it: "I disagree but am not literate enough to state why" Or is it: "This person is right, but I don't want people to know it (insert motive here), so I will try to make their comment invisible" Either way they're cowards, and you are correct. Signal is the best intersection of genuine security and ease-of-use I've seen.
- godelski 1y agoMy points are positive now but the variance has been huge. I'm surprised how often a comment like mine swings or gets entirely downvoted without a reply. I do not know if it is zealots, bots, or people just feel like the issue is "so obvious" that it needs no addressing. But I'm not sure how that's different than the first item. It is also crazy to see how on HN of all places there's still a lot of confusion between the difference of privacy and security. People are saying phone numbers are a security issue. That's flat out wrong. It is a privacy issue.
- password4321 1y agoIn case anyone is not aware: https://news.ycombinator.com/item?id=39444500 https://news.ycombinator.com/item?id=39444500 Keep your phone number private with Signal usernames (2024-02-20, 1422 points, 890 comments)
- aspect0545 1y agoThis is different though. PP is saying that you require a phone number to sign up, and phone numbers are being used to match your account to your user name.
- password4321 1y agoAgreed as far as governments tracking Signal sign-ups. For a long time though user names were not even supported between Signal users.
- Citizen8396 1y ago"As a new default, your phone number will no longer be visible to everyone in Signal." https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames https://support.signal.org/hc/en-us/articles/6712070553754-P... "Signal does not send your phone number to anyone unless you have enabled that others can see it and then you send them a message or make a call to them." https://support.signal.org/hc/en-us/articles/360007061452-Does-Signal-send-my-number-to-my-contacts https://support.signal.org/hc/en-us/articles/360007061452-Do...
- beeflet 1y agoThis doesn't address the security problem
- godelski 1y ago> the security problem You're confusing privacy with security. Phone numbers are a privacy problem and NOT a security problem. Think of it this way. There's a vault that's locked with secrets inside, but the door is transparent. This does not prevent privacy. But the vault provides security. Signal is not a transparent door, but is opaque. You can't see inside the vault. But the phone number reveals that you have access to the vault. This is very different than a security problem. Anyone connecting the two can see that you have a vault (security)[0], but they cannot see inside (privacy) or even when you access it (privacy). There is no security issue with phone numbers. [0] or can see that at some point in time you had a vault or someone that previously had that number had a vault
- XorNot 1y agoThey can take ownership of the number but not the keys on the device, which would show up as safety codes changing. This problem is honestly minor compared to teaching users to have opsec practices suitable against such a threat.
- jcul 1y agoMost people take no notice of this stuff IMO. I see it regularly in WhatsApp groups when someone gets a new phone (presumably, or they are being impersonated!).
- XorNot 1y agoRight but thats my point: if you adversary is a nation-state, assuming any technical measure can casually protect users against targeted action is foolhardy.
- zelphirkalt 1y agoAlso annoying: You cannot use the same Signal account from 2 different phones (with different SIM).
- alltheseas 1y agoCheck molly, FOSS Implementation of signal protocol https://molly.im/ https://molly.im/
- Velocifyer 1y agoThat's a fork of signal.
- karlzt 1y agoIt's pathetic, isn't it?