7 comments

  • purpleidea 8 minutes ago
    Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.
  • ggm 12 minutes ago
    For those who missed it, unrelated to this specific ZKP thing the release cycle also now permits Android tablets without a SIM to be first-class adjunct devices without using wierd tricks or alternate clients. It may permit them to be the initiation/sign-on device, which would invoke the ZKP, but the point for me as an existing phone number denominated user, the point is I can be on my tablet with true signal now. Nothing against molly, wanted it in the base.
    • opengrass 7 minutes ago
      You can already do that without being a trusted device.
  • ynniv 26 minutes ago
    you can't wave your hands, say "zero knowledge", and be private. this is too little information to be useful
  • opengrass 19 minutes ago
    Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.
    • mmooss 9 minutes ago
      What about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.
  • rkagerer 25 minutes ago
    Lots of discussion at that link, but what's the bottom line? Can you register without a phone number yet?
  • user3939382 18 minutes ago
    I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".
    • 420official 3 minutes ago
      Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?

      I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?

    • bawolff 10 minutes ago
      Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there.

      I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.

  • atiq-ca 1 hour ago
    Signal still uses proprietary blob and uses google/apple service for notifications. Use molly.im instead which has solved these problems.
    • Cider9986 39 minutes ago
      Molly is a security-hardened Signal client only on Android for people unfamiliar. They went through a period of not updating (there were no security updates during that time afaict), but now releases should happen faster on top of Signal.

      In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.

      I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..

      Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead.

      • rkagerer 29 minutes ago
        If you're using WebSocket, how do Google and Apple see metadata? Can someone explain why it's so difficult to make a decent chat app divorced from their ecosystems?
    • john01dav 28 minutes ago
      The native Signal android app delivers notifications just fine without Google play services on my degoogled android.
    • opan 24 minutes ago
      I was using Silence from F-Droid for a while back in the day because of these issues, but the lack of interop and needing to make everyone move again soured me on the whole thing. I would rather just get people on XMPP or Matrix and not use some sketchy phone-first app at all. For SMS I use Fossify Messages, which I think was a fork of QKSMS. I don't use SMS as primary or sensitive comms, only as needed. Same as email, basically, but less useful.
      • nosioptar 10 minutes ago
        I really liked silence. I stopped using it when f-droid said the source code was no longer available. Fossify messages is the best replacement I've found.

        (I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)

    • ranger_danger 1 hour ago
      I tried it and it was fine while it worked, but eventually I had to go back to regular Signal because Molly's updates did not follow Signal's closely enough, and at some point the server code changed enough to where I was unable to use it for an unacceptable amount of time (after checking, it took them weeks to update). Something to keep in mind if you're not using a custom server.
      • blfr 37 minutes ago
        Maybe it's because I use Molly as a secondary device (my tablet) but I never had an issue where it didn't work for weeks.
    • throwaway35435 30 minutes ago
      [dead]