Requiring all three auditor signatures keeps independence meaningful; the seven-day freshness window also makes the remaining split-view risk concrete.
That requires access to the actual phone and the unlock code in the case of WhatsApp (you need to identify to add a WhatsApp web client).
For telegram it's a bit easier yes, but the user can set up an additional password. I have done so of course. Note that telegram is not E2EE so they can give your stuff to the police at any time unlike WhatsApp and signal.
For signal I don't know as I don't really use it but i understand it works the same way as WhatsApp, scan a QR code and authenticate to the phone.
Also, with all 3 systems it's clearly visible when you look at the linked systems.
It is possible to intercept text messages and phone calls in such a way that the recipient never even knows a text message or phone call was sent to them in the first place. SMS is an extremely insecure channel for handling authentication codes.
Yes I know but when you want to link a WhatsApp Web client to a phone with WhatsApp, SMS is not used. You need to scan a QR with the phone in question and sign in to the phone.
SMS is used to register WhatsApp to a new phone, but that signs the original phone out. Also, you need the pin code that WhatsApp forces you to set. If you don't have it you have to wait a week if you got a recycled number. Also the original account holder is notified you tried it.
So this method cannot be used by the police to snoop unnoticed. I believe signal works the same as WhatsApp here, it also forces you to set a pin now.
For telegram this can be used yes but you can set an optional extra password. And also like I said telegram is not E2EE anyway so it's open to warrants.
I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.
Decreases what info Signal needs to collect and retain about a user. When using an SMS verification as a proof, Signal needs to log the phone number, because if they didn't, one spammer could use one phone number to create 10^99 accounts.
When using payment as proof, they can verify that payment occurred, validate the account and then immediately forget about the transaction. One spammer would still have to pay 10^99 times to create that many accounts.
If your concern is "muh phone number", then you can pay and not have to give the phone number to sign up.
It's already the case today (and has been for years) that you don't need to give strangers your phone number to chat on Signal. My username is soatok.45; try to get my phone number if you can.
If you want absolutely no info to be collected, ever, and there to be zero cost on the end user too, be prepared to welcome your new spam overlords. Because the people who will benefit the most from a zero cost signup that only requires a username are spammers.
Signal's mission is to provide maximized privacy in a form the non-technical public can use.
A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?
Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.
True they can make their choices but it also means I won't support them in any way. Or recommend them.
I'd use something that's truly decentralised but signal is just another walled garden like WhatsApp. Just one that promises to behave better. But what's a promise worth these days?
A decentralised network would mean a guarantee that they can't do anything bad. I'll take that over promises and good intentions any day.
I don't care about the masses. If signing up for a matrix account is too annoying for them they don't really care about privacy anyway. After all it's the same they have to do for any online shop. Just create a username and password. Somehow it's not a problem for the masses if they wanna order a phone charger but for matrix it's suddenly 'too complicated'?
People like you who equate signal and WhatsApp are also responsible for not making any progress due to ideological stubbornness itâs something that I absolutely despise from a part of HN crowd here.
Great, I'm happy to be a nail in the coffin of the signal advocacy.
Remember how everyone jumped on Google when they promised to do no evil? Now they're one of the most abundant mass surveillance companies in the world and we can't move away because they're too big to fail. The same with WhatsApp. People jumped on it because it was good, then nobody left when meta bought it because all their friends were on it.
Signal is one sale away from being evil too. They might not sell it but we've been conned so many times by big tech that I will only take technical guarantees, not promises that can be broken. We have to avoid getting locked in again.
And really, lots of progress is made in real open communications. Matrix is getting more mature by the day. NATO uses it, the French government and several others. And the good thing is, you can always run your own server and connect to the hive. Nobody can tell you what to do, nobody can tell you to surveil your users like the EU is planning to do.
We need something truly open. Not a WhatsApp light.
One possible solution is to only be able to contact someone if you have received an invitation code from them out of band. E.g. "scan this QR code to add me on signal". Such an invitation code should default to single-use but users should be allowed to generate standing invitations so that businesses and the like can print and post one in their store or whatever. Start getting spam from one of your standing invitations? Just revoke it and make a new one. Presumably the Signal folks can come up with more alternative solutions than the half baked one I came up with after thinking about it for a minute, they're clever cookies.
Welcome back to âkey signing partiesâ. PGP never got enough adoption. At least Signal is simple enough that the (ahem) leaders of the US can (mostly) manage to use it.
Leaders of the US use an Israeli backdoored version of Signal (TM-Signal) TeleMessage by Smarsh was used by DOD, CPB, and others for records retention reasons... also hacked to smithereens.
People seem to get on with Discord invite links just fine. You don't have to do the "confirm that all these emoji are the same on both your devices" dance to stop spam.
Requiring all three auditor signatures keeps independence meaningful; the seven-day freshness window also makes the remaining split-view risk concrete.
You're absolutely right! Let's delve deeper...
Bit of a positive piece amid a negative headline this week: https://cybernews.com/privacy/police-telegram-whatsapp-signa...
That requires access to the actual phone and the unlock code in the case of WhatsApp (you need to identify to add a WhatsApp web client).
For telegram it's a bit easier yes, but the user can set up an additional password. I have done so of course. Note that telegram is not E2EE so they can give your stuff to the police at any time unlike WhatsApp and signal.
For signal I don't know as I don't really use it but i understand it works the same way as WhatsApp, scan a QR code and authenticate to the phone.
Also, with all 3 systems it's clearly visible when you look at the linked systems.
It is possible to intercept text messages and phone calls in such a way that the recipient never even knows a text message or phone call was sent to them in the first place. SMS is an extremely insecure channel for handling authentication codes.
https://youtu.be/wVyu7NB7W6Y
Yes I know but when you want to link a WhatsApp Web client to a phone with WhatsApp, SMS is not used. You need to scan a QR with the phone in question and sign in to the phone.
SMS is used to register WhatsApp to a new phone, but that signs the original phone out. Also, you need the pin code that WhatsApp forces you to set. If you don't have it you have to wait a week if you got a recycled number. Also the original account holder is notified you tried it.
So this method cannot be used by the police to snoop unnoticed. I believe signal works the same as WhatsApp here, it also forces you to set a pin now.
For telegram this can be used yes but you can set an optional extra password. And also like I said telegram is not E2EE anyway so it's open to warrants.
I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.
They will allow registering without phone number as a paid option soon.
> registering without phone number as a paid option soon
Replacing the need to register with a phone number with a requirement to pay is a better option how, exactly ?
Decreases what info Signal needs to collect and retain about a user. When using an SMS verification as a proof, Signal needs to log the phone number, because if they didn't, one spammer could use one phone number to create 10^99 accounts.
When using payment as proof, they can verify that payment occurred, validate the account and then immediately forget about the transaction. One spammer would still have to pay 10^99 times to create that many accounts.
Payment leaves a huge identification trail because of all the know your customer stuff these days.
If they accept monero or something then ok but I doubt they will.
They could make it so all that is known by banks is that you purchased the service. Like how Nym does it or how you can buy Mullvad credits on Amazon.
https://nym.com/zk-nyms
Ideally they accept Monero and do unlinkable payments but I doubt they will accept Monero. Hopefully they accept some crypto.
If your concern is "muh phone number", then you can pay and not have to give the phone number to sign up.
It's already the case today (and has been for years) that you don't need to give strangers your phone number to chat on Signal. My username is soatok.45; try to get my phone number if you can.
If you want absolutely no info to be collected, ever, and there to be zero cost on the end user too, be prepared to welcome your new spam overlords. Because the people who will benefit the most from a zero cost signup that only requires a username are spammers.
two weeks
Signal's mission is to provide maximized privacy in a form the non-technical public can use.
A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?
Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.
True they can make their choices but it also means I won't support them in any way. Or recommend them.
I'd use something that's truly decentralised but signal is just another walled garden like WhatsApp. Just one that promises to behave better. But what's a promise worth these days?
A decentralised network would mean a guarantee that they can't do anything bad. I'll take that over promises and good intentions any day.
I don't care about the masses. If signing up for a matrix account is too annoying for them they don't really care about privacy anyway. After all it's the same they have to do for any online shop. Just create a username and password. Somehow it's not a problem for the masses if they wanna order a phone charger but for matrix it's suddenly 'too complicated'?
People like you who equate signal and WhatsApp are also responsible for not making any progress due to ideological stubbornness itâs something that I absolutely despise from a part of HN crowd here.
Great, I'm happy to be a nail in the coffin of the signal advocacy.
Remember how everyone jumped on Google when they promised to do no evil? Now they're one of the most abundant mass surveillance companies in the world and we can't move away because they're too big to fail. The same with WhatsApp. People jumped on it because it was good, then nobody left when meta bought it because all their friends were on it.
Signal is one sale away from being evil too. They might not sell it but we've been conned so many times by big tech that I will only take technical guarantees, not promises that can be broken. We have to avoid getting locked in again.
And really, lots of progress is made in real open communications. Matrix is getting more mature by the day. NATO uses it, the French government and several others. And the good thing is, you can always run your own server and connect to the hive. Nobody can tell you what to do, nobody can tell you to surveil your users like the EU is planning to do.
We need something truly open. Not a WhatsApp light.
> signal is just another walled garden like WhatsApp
For me the difference is in the ownership. Who owns each. Which is BigCorp? Thatâs why I trust one more than the other.
Ownership can change. That's the problem. It happened to WhatsApp itself! Meta bought a network with the userbase that was already too big to leave.
> What is a more private, usable solution for filtering them out than using a phone number?
Since when is giving out your phone number a "more private" option ?
You don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people.
If it's not, let us know a solution (to Signal's actual problem as stated in the GP) that is more private.
One possible solution is to only be able to contact someone if you have received an invitation code from them out of band. E.g. "scan this QR code to add me on signal". Such an invitation code should default to single-use but users should be allowed to generate standing invitations so that businesses and the like can print and post one in their store or whatever. Start getting spam from one of your standing invitations? Just revoke it and make a new one. Presumably the Signal folks can come up with more alternative solutions than the half baked one I came up with after thinking about it for a minute, they're clever cookies.
Welcome back to âkey signing partiesâ. PGP never got enough adoption. At least Signal is simple enough that the (ahem) leaders of the US can (mostly) manage to use it.
Leaders of the US use an Israeli backdoored version of Signal (TM-Signal) TeleMessage by Smarsh was used by DOD, CPB, and others for records retention reasons... also hacked to smithereens.
Requiring manual key verification is a bad design that doesn't scale or benefit most people.
People seem to get on with Discord invite links just fine. You don't have to do the "confirm that all these emoji are the same on both your devices" dance to stop spam.