5 ms·
> What is a more private, usable solution for filtering them out than using a phone number? Since when is giving out your phone number a "more private" option
by traceroute66 5d ago
> What is a more private, usable solution for filtering them out than using a phone number?
Since when is giving out your phone number a "more private" option ?
- tialaramex 5d agoYou don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people.
- traceroute66 4d ago> You don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people. You are deliberately missing the point. Signal are gatekeeping these new advanced security features behind a phone number wall (soon to become paywall if some posts here are to be believed).
- mmooss 5d agoIf it's not, let us know a solution (to Signal's actual problem as stated in the GP) that is more private.
- snackbroken 5d agoOne possible solution is to only be able to contact someone if you have received an invitation code from them out of band. E.g. "scan this QR code to add me on signal". Such an invitation code should default to single-use but users should be allowed to generate standing invitations so that businesses and the like can print and post one in their store or whatever. Start getting spam from one of your standing invitations? Just revoke it and make a new one. Presumably the Signal folks can come up with more alternative solutions than the half baked one I came up with after thinking about it for a minute, they're clever cookies.
- fn-mote 5d agoWelcome back to “key signing parties”. PGP never got enough adoption. At least Signal is simple enough that the (ahem) leaders of the US can (mostly) manage to use it.
- chews 4d agoLeaders of the US use an Israeli backdoored version of Signal (TM-Signal) TeleMessage by Smarsh was used by DOD, CPB, and others for records retention reasons... also hacked to smithereens.
- upofadown 4d agoUnfortunately, in an end to end encrypted messaging system, an identity is denoted by some sort of long number. That is an inescapable fact. Trusting a third party to correctly map, say, a phone number to a cryptographic identity number eventually results in the sort of attacks we have been seeing with phone oriented encrypted messengers recently like WhatsApp and Signal. The PGP people were doing the right thing when they were doing education in the form of key signing parties. That is something the user needs to know. Anonymous messengers have no real choice and have to use some sort of number for identity. See Briar, Session or Tox for examples. My comments on Signalgate 1.0: https://articles.59.ca/doku.php?id=em:sg https://articles.59.ca/doku.php?id=em:sg
- mmooss 4d ago> attacks we have been seeing with phone oriented encrypted messengers recently like WhatsApp and Signal Could you give an example of an actual attack of this kind on Signal? The 'Signalgate' event was someone mistakenly inviting the wrong person to a chat.
- some_furry 5d agoRequiring manual key verification is a bad design that doesn't scale or benefit most people.
- 5d ago