6 ms·
Ironically, Signal actually ranks a -1 for privacy in this use. Presumably you're already using Signal and getting mainstream contacts to start using it too. Y
by aaravchen 8mo ago
Ironically, Signal actually ranks a -1 for privacy in this use.
Presumably you're already using Signal and getting mainstream contacts to start using it too. You probably have a basic profile that at least includes your real name, and might also have your picture. Maybe you're even one of the 7 people in the world that use the Stories feature in it. Well good news, now all of that is also unconditionally available to anyone in any group you ever join, including any future changes you ever make to that info, unrevocably forever into the future.
Signal has a fun dark pattern where it unrevocably grants permissions for anyone you allow to contact you to see everything in your profile for the rest of time. It has only a single trust level with contacts effectively: full trust.
This is unacceptable in any tool you use for online community, unless you exclusively use it for online community and can decline to provide any info in this full-trust level. Unfortunately Signal also makes very sure you can't have a second account, by tying your account to a phone number, and only allowing one Signal instance per mobile device.
Is Signal good? Yes, but only exclusively for communication with people you already trust.
EDIT: typos
- mastermage 8mo ago[flagged]
- ozlikethewizard 8mo agoYou can have multiple instances of signal on a mobile device, and you can use VoiP or eSIMs to register. Signal with an online persona revealing no identifying information, registered to a cash purchased eSIM on an ungoogled android is as good as your getting. Why do you think so many jurisdictions are trying to ban both GrapheneOS and Signal.
- dns_snek 8mo agoYou can do all of that but you shouldn't have to when using a privacy-focused messenger, and most people won't so they'll be exposed and suffer the consequences if they use Signal expecting a certain level of privacy (and pseudo-anonymity). It's a terrible anti-feature and the only reason they're not being punished for it is because there aren't many alternatives to pick from.
- OJFord 8mo agoThat's privacy for someone who cares deeply and will get it somehow no matter what, not default zero-effort privacy for the ignorant. (Which WhatsApp does pretty well for example.)
- oarsinsync 8mo ago> default zero-effort privacy for the ignorant. (Which WhatsApp does pretty well for example.) Can you elaborate on what default zero-effort privacy for the ignorant WhatsApp offers, that Signal does not?
- OJFord 8mo agoI don't know, I'm not familiar with Signal. But features such as described above with worse privacy than the basic chatting functionality detract from it, it's not just that it would be a bonus if it were better, because that's exactly how effort comes in, having to know about it, and the typical layman user just blindly uses it. Take Telegram for example, where only explicitly 'secret' chats are e2ee, you have to go out of your way, it's not the easy path.
- ekianjo 8mo agoOf course it's revealing information. If I know that two users that are identified by their phone numbers are talking to each other every day, this is a clear connection you can exploit. Metadata is only useless if you have no imagination.
- kenniskrag 8mo agoIn europe you need identification to buy a sim or esim. https://www.reddit.com/r/europe/comments/9ziqfi/european_countries_requiring_registration_of/ https://www.reddit.com/r/europe/comments/9ziqfi/european_cou...
- andrepd 8mo agoDidn't know that the UK, the Netherlands, or Portugal aren't part of Europe... Also, you can buy phone numbers with monero for 0.08$ https://smspool.net https://smspool.net.
- lvass 8mo agoAnd what happens when the next guy buys that same number and registers on Signal? Phone numbers are recurring costs. And to keep a truly private one you must keep paying without ever disclosing personal info and that is really hard. Signal is a privacy nightmare for long term use.
- vel0city 8mo agoThere is a week long registration lock protected by a PIN. Your contact list is protected by that PIN as well. They cannot access your chats. All your contacts will get a notification that the contact has changed when they go to talk to your phone number or get a message from your number. https://support.signal.org/hc/en-us/articles/360007059792-Signal-PIN https://support.signal.org/hc/en-us/articles/360007059792-Si...
- lvass 8mo agoThis is good and means no one can impersonate you using your phone number, but doesn't solve the recurring costs issue, you still need to buy a new number when someone registers yours, and every financial transaction puts you at more privacy risk. And is terrible UX, imagine having to add your contacts new numbers every other week.
- 8mo ago
- aaravchen 8mo agoYou could have a second actuve eSIM if you have a phone that supports more than one (no phones support more than 2 active simultaneously). Though technically the phone number only needs to be accessible for the initial account setup so I guess you could have a burner phone you switch out eSIMs on. Each Signal application only supports a single account though. So you can have one, and if you have a work profile you're not otherwise using you could have a second account in that instance.With the new Private Spaces you could potentially have a third as well. So you _may_ be able to have up to 3 simultaneous Signal accounts on the same device. I'm using my work profile and Private Space for things I can't share a Signal install with though. And I dont want to buy and maintain an extra phone number from a telco just to have another Signal profile.
- derkades 8mo agoThe part about stories is not true. When sending a story you can choose who to send it to. To make it easier you can even put people in groups
- fsflover 8mo ago> Ironically, Signal actually ranks a -1 for privacy in this use And it ranks near Discord in terms of removing the single point of failure.
- pyb 8mo agoHow could Signal be considered privacy-conscious ? The first thing they do is ask for your phone number.
- neobrain 8mo agoSignal has profiles nowadays that can be used to connect with people without sharing phone numbers. The latter are only used for signup and discarded immediately after.
- reactordev 8mo agoI doubt they are discarded when push notifications exist
- Krizzu 8mo agopush notifications are not related to phone number, but rather to a randomly generated token in app.
- pmontra 8mo agoI don't know how Signal works and I never used it, but could I signup with a phone number and keep using it with another number, on the same phone?
- alias_neo 8mo agoYes. The phone number is just for activation, once activated, you can swap the SIM and carry on. Or have the SIM that receives the activation text in another phone, or be virtual, or whatever.
- pseudalopex 8mo agoAnother comment contradicted this.[1] [1] https://news.ycombinator.com/item?id=46959019 https://news.ycombinator.com/item?id=46959019
- direwolf20 8mo ago
- gsaslis 8mo agoI didn't think I'd ever be part of any group of 7 people in the world, but today is that day, I guess. And I know one more of those people already! 5 more to go.
- raxxorraxor 8mo agoI dislike Signal as I need to identify myself through info that is protected. Like a phone number for example. Not a privacy app in my opinion. Sure, might be good for some use cases... but overall there are better solutions.
- lukan 8mo ago"but overall there are better solutions." Can you please name some?
- Gud 8mo agoWhy the downvotes? A messaging app that requires a personally identifiable token is inherently not good for privacy…
- cykros 8mo agoKeep an eye on Whitenoise. It's basically taken the technology behind Signal and placed it atop Nostr, so rather than signing up with a phone number, you do it with an npub (pubkey). Still in very early days so the features aren't all there yet, and battery use could be better, but they've got the basics of it working already.
- aaravchen 8mo agoSimpleX is another option. These don't have discoverability for lay people users just joining though, which is actually a huge network effect positive for Signal in the family and friends use cases. However it avoids the issues with the public group chat privacy. It ends up coming down to client and protocol features for those. SimpleX has a more extreme privacy threat model than Whitenoise so user contacts tend to be throw away (for good or bad), which generally doesn't work for public communities. The real kicker is that almost nothing has the community automation tools and administration of Discord which is the really hard lift.
- a3w 8mo agoCompletely not my experience: I have lots of Signal contacts I cannot phone, since the phone number is never shared by default. Not even the signal contact is shareable. It is way too privacy focused to work easily. i.e. I cannot even match two people I have in contacts unless one of them sends me their hidden username. Then they can talk to one another. And people in my contacts don't use their full name. In groups, they often share the first name, making it confusing as hell. And many use an arbitrary nickname, most often the abbreviated first name I think but sometimes truly random stuff, and might even change that yearly with no mapping in my history to tell me who they were.