Conversation

it's funny how a major secure messenger(signal) seemingly ties your account to a phone number?

everyone will repeat that sms 2fa is bad because someone with your password and the ability to sim swap you can access your account, but it's fine to use it as the only factor by default (or with a pin, bypassable by waiting a week). yes people will get key change notifications but honestly no one cares about those

they would be better off tying it to an email and having reset links. (apart from using phone numbers as an expensive resource for antispam reasons, which is the only "real" reason to still require one. but they could do what discord can, in specific discords, do and require it to be linked but not really use it :) )

2
0
0

@5225225 The other reason is contact discovery. It's unlikely Signal would have ever taken off it didn't make this decision early on.

1
0
0

@be true, signal's old(kinda) name (textsecure) being more clear about "sms, but encrypted" explains the design choice, but i still think the choice makes not a ton of sense now

as an option, sure, but i(and quite a few others, i assume) turn off discovery via phone number, it is its own application unrelated to sms

(that and if your threat model includes the government, and theirs does, holding phone numbers isn't the best of ideas, considering how identifying they are? not an issue to most, but likewise the need for e2ee is honestly also not an issue for most. not entirely sure if they can look up a phone number from a username, but i assume so, considering it shows up in the data export)

0
0
0
@5225225 I know a lot of people who love signal but tbh I've always seen it as the least bad option (in some circumstances). It still sucks a lot

I think the phone requirement is the most egregious thing but there's a lot of other wtf designs too. I got a new phone recently, which is how I found out you can only use your signal account on one of them (yes, even though you can log in on as many computers as you want). The copying of messages from one phone to the other was going to take hours, and it was late, so I cancelled it. The next morning I found out that apparently that was my only chance to copy those messages, and now they're stuck in limbo on my old phone

people will be like "it's impossible to build a e2ee app because e2ee is fundamentally at odds with user friendliness" and then you look at the e2ee apps and they have so many paper cuts that are way worse than anything that's induced by the encryption
2
0
0

@n3tcat @5225225 For the whole e2ee, Signal definitely has some downsides from that (like not being able to see older messages when you join a group chat), but also there’s just generally the fact that Signal chooses security over convenience pretty much whenever it can, which makes it annoying as a general-purpose chat app, especially because there’s no good medium between apps that actively harvest your data and apps that sacrifice a decent bit of convenience for security

1
0
0
@aens @5225225 I think coming from matrix I'm like "wow e2ee in signal is so much better". this is probably not the case for people coming from e.g. discord. But I still really think that signal has a bunch of completely unnecessary sharp edges that has nothing to do with e2ee
1
0
0

@n3tcat @5225225 Agreed. For example, compare the number of clicks required to copy your username in Signal to what it is on basically anything else. I still think I’d prefer having a low-security, but not actively spying, chat app that I use for 90% of things, and then something E2EE for the small amount of stuff where I actually care if it’s private

1
0
0

@aens @n3tcat the issue with that is you both need to know it needs to be private, and be willing to put up with the worse UX and application switching

that combined with "okay, there's an application used exclusively for Serious Shit, therefore you can infer that anyone using it is interesting"

for those reasons i think having the general purpose application be "always e2ee, but with select weakenings on a per-group basis where you can clearly describe why it's weaker and who might want/not want that" is the ideal strategy

like - there's no reason why you can't send chat history(say, last 100 messages or last week, or "all messages in this channel") to new members. that exposes those messages to people who wouldn't have seen them otherwise, but that's still better than "literally anyone with access to the server can see the messages"

(that and e2ee everything is nice as a server host to make you a less interesting target, if you don't have message plaintext.)

0
0
0

@n3tcat @5225225 out of all of the phone number messengers out there signal’s implementation does feel the least bad because at least it doesn’t block landline and “voip” numbers atm

0
0
0