4 ms·
I like the idea. But I’m pretty happy with Signal. Signal does require a phone number I think, but otherwise seems very similar. Grounding identity in a phone
by oofbey 6mo ago
I like the idea. But I’m pretty happy with Signal. Signal does require a phone number I think, but otherwise seems very similar.
Grounding identity in a phone number is very reasonable for almost all normal usage. It makes recovery simple. It does block the ultra paranoid use cases though. Oh well.
- Nyr 6mo agoSession is not similar to Signal. Session aims to provide anonymity, Signal aims to provide privacy.
- bsaul 6mo agosignal is really crappy. It fails at the most basic feature which is : deliver the message on time.
- bjord 6mo agodoes it? have you been trying to use signal while disconnected from the internet?
- oofbey 6mo agoI had a friend who complained about this too. I never understood it. She had a really cheap old android phone. Maybe that’s the issue?
- bjord 6mo agoI primarily use a nearly-bottom end android phone that's a few years old and just recently switched to an even older, even lower end android phone that is six years old. Neither has that issue. Obviously, I'm not really claiming that it's not possible people are experiencing this issue, but it can't possibly be widespread. I feel like most likely people are using android skins that aggressively kill apps in the background.
- dalmo3 6mo agoI have that exact issue on a couple of not exactly low end Samsung phones. Holding them side by side with signal open. Delivery times vary wildly. Whereas WhatsApp just works (though I hate it for other reasons)
- bjord 6mo agoI can see why that would be incredibly frustrating. Have you reported it to them, either via github or email?
- bsaul 6mo agonope, iphone here, and quite recent. But it's not just me, all the people i communicate with on this app have the same kind of problems. With a group of friends we even had a totally weird ordering of messages, making the conversation quite absurd. There's something deeply wrong with the way signal delivers messages...
- Imustaskforhelp 6mo ago> otherwise seems very similar. It's worth mentioning that Session had started out as a fork of signal.
- 0xy 6mo agoSignal's code quality is not conducive to security. They had an extremely bad state management bug that resulted in photos being sent to random contacts in your list (potentially life ruining implications if you're sending private photos). For this reason, it's hard to trust them. The encryption quality is irrelevant if the slop coded client is blasting random photos to random contacts.
- alance 6mo agoSource?
- 0xy 6mo agoIt would've taken you less time to Google, but sure: https://www.bleepingcomputer.com/news/security/signal-fixes-bug-that-sent-random-images-to-wrong-contacts/ https://www.bleepingcomputer.com/news/security/signal-fixes-... Send a GIF to Contact A, Contact B receives random private images? Absolutely inexcusable slop code project. This class of state management bugs should not be possible with a well-architected client, period. Signal's E2E encryption is more like End 2 Random End.
- alance 6mo agoOr why not include the source of your claim up front? From GitHub comments: https://github.com/signalapp/Signal-Android/issues/10247 https://github.com/signalapp/Signal-Android/issues/10247 Greyson: > Hi there, sorry, this issue was fixed in 5.17 (which hit 100% production on 7/21) They had a difficult to reproduce problem reported in late December 2020, and got the fix rolled out seven months later. Not sure your criticism "absolutely inexcusable slop code" is well considered.
- 0xy 6mo agoSo 7 months of their users getting rinsed by an extremely serious issue exposing your private photos to random contacts. Seems like slop code to me. Those kinds of state management bugs should not be possible. It indicates code divorced from best practice state management. Knowing that bug COULD exist, means that you cannot be sure that messages you send in Signal will make it to the recipient you intend given the poor quality. This means the E2E encryption is fundamentally broken, by the way. Because the client is lying to you about the true state of who it's about to send to. The recipient text has fundamentally zero relationship to the true recipient of the message given that bug. Having the UI and message sending code reference two different versions of state is incredible incompetence.
- balamatom 6mo ago>Grounding identity in a phone number is very reasonable for almost all normal usage In many jurisdictions, telecoms form an abusive oligopoly, and you need to provide a state-issued identity document to get a phone number. That is not at all reasonable for normal usage - unlike well-known non-abusive authentication methods, such as a keypair; or its even simpler cousin, the username/password.
- oofbey 6mo agoI guess it depends on what you consider normal. Most of the humans I know find it vastly easier to produce a state issued id to an authority than to generate a public/private key pair.
- balamatom 6mo agoWhat's easier: to obtain state ID, or to sign up to a website with your preferred username and password?
- oofbey 6mo agoObtaining your first id is obviously difficult. But so is obtaining your first computer. If you’re on good terms with your government, obtaining the id is easier. That’s really the key. Sure if you focus on hostile states this stuff all makes sense. If you’re insistent on hiding from authorities then many things become much more difficult, by design.
- thefounder 6mo ago>> Grounding identity in a phone number is very reasonable for almost all normal usage. Yeah if you compare that with Facebook messenger and other such services but if you want secure communication it's not reasonable.