Hacker Newsnew | past | comments | ask | show | jobs | submit | chews's commentslogin


I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.

They will allow registering without phone number as a paid option soon.

> registering without phone number as a paid option soon

Replacing the need to register with a phone number with a requirement to pay is a better option how, exactly ?


Decreases what info Signal needs to collect and retain about a user. When using an SMS verification as a proof, Signal needs to log the phone number, because if they didn't, one spammer could use one phone number to create 10^99 accounts.

When using payment as proof, they can verify that payment occurred, validate the account and then immediately forget about the transaction. One spammer would still have to pay 10^99 times to create that many accounts.


Payment leaves a huge identification trail because of all the know your customer stuff these days.

If they accept monero or something then ok but I doubt they will.


They could make it so all that is known by banks is that you purchased the service. Like how Nym does it or how you can buy Mullvad credits on Amazon.

https://nym.com/zk-nyms

Ideally they accept Monero and do unlinkable payments but I doubt they will accept Monero. Hopefully they accept some crypto.


> you can buy Mullvad credits on Amazon

That is not the same thing.

You buy a Mullvad scratch card on Amazon and you redeem the token string.

Mullvad also offer the option to put your card number into the Mullvad website, and I'm sure many privacy conscious people would be very reluctant to do that.

Card payments these days leave far too big a trail. The bank knows, the intermediary (e.g. Stripe) knows, and the merchant (e.g. Mullvad) has to keep records for accounting/tax requirements.


It’d be pretty disappointing if they started including cryptocurrency features in their stack and didn’t accept it.

They added that BS and then didn't do anything with it.

Molly is going to add a Monero integration while also having various other advantages.

They don't accept crypto donations directly or accept them for their backups so I assume they wont for registration.


Also when they start dealing with payments there might be regulatory requirements like record keeping for a certain period.

I find convincing that phone numbers or payment is the best way to avoid spams at their scale.

If your concern is "muh phone number", then you can pay and not have to give the phone number to sign up.

It's already the case today (and has been for years) that you don't need to give strangers your phone number to chat on Signal. My username is soatok.45; try to get my phone number if you can.

If you want absolutely no info to be collected, ever, and there to be zero cost on the end user too, be prepared to welcome your new spam overlords. Because the people who will benefit the most from a zero cost signup that only requires a username are spammers.


I'm a bit surprised by this dismissal. Of course some info must be collected, or there must be some cost to enter (probably both I mean phone number is also a cost, but one most people already sunk). But we can still debate the best way, right?

For example:

* Are you absolutely positive signal will never have a bug that let attackers reveal contact phone numbers? I really trust in their secure coding skills, but this class of vulnerabilities (like 2fa leaj) happened to even the biggest players.

* One of the reasons signal collects phone numbers (and asks for a contacts permission) is to check which contracts are already on signal. For some people or in some governments even having a signal account is an opsec problem (to be fair, they have a secure privacy-preserving protocol for this - as you know - and it's possible to avoid this footgun if necessary)


two weeks

[flagged]


> Lol how is that any better at all?

They are [1] implementing unlinkable payments so all that is known by credit card is that you purchased Signal and Signal doesn't know which credit card goes with which account.

>Signal is an obvious honeypot.

Claims without evidence can be dismissed without evidence. You might say they don't do enough to protect metadata privacy but it was never made to be an anonymous messenger, it was made to be a private messenger. You can easily check the end-to-end encryption in the code (reproducible builds on all platforms except iOS BTW!). This person audited Signal recently [2].

>They make no money and have no plans to.

They make money from donations and paid backups and they might make money from paid accounts.

[1] https://github.com/signalapp/Signal-Android/commit/7da3357b5...

[2] https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...


And apparently, just like Telegram, just like WhatsApp, they readily merge the username with your number if numbers are already saved.

Signal's mission is to provide maximized privacy in a form the non-technical public can use.

A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?

Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.


> in a form the non-technical public can use.

That happens when public uses it, en masse, in the first place. And as it is today the "public" has no reason/incentive in switching to it and that naturally keeps the "non-technical public" away from it.

So who is this serving eventually? A very few, mostly "technical public", in complete contrast to what you have said.

I suspect Signal's goal is something entirely else. For them it's just two things:

1. Some sort of shallow ideology (started with the founder and the flame kept alive by the later leaders who often come across ideological groupies; the last bit is a bit strong but whatever)

2. Executing based on that for the sake of executing that because they can

What their intention is not: Signal ever becoming IM app of choice anywhere and possibly they might have their reasons for this. One of those reasons could be affordability as you have said it.

Note: in case this wasn't clear, the moment you attach a "phone number" you make it inherently unsafe for most, like 99.353959353%, of "general non-technical public" to use Signal and remain really unidentifiable. Once they are identified - in most countries (and now even in places like USA it seems) only thing needed after that is being "picked up" and rest will be just sung even without a device. I mean it's so absurd to even not think about it is that it's ridiculous. So no, it is DEFINITELY not "non-technical public can use".


True they can make their choices but it also means I won't support them in any way. Or recommend them.

I'd use something that's truly decentralised but signal is just another walled garden like WhatsApp. Just one that promises to behave better. But what's a promise worth these days?

A decentralised network would mean a guarantee that they can't do anything bad. I'll take that over promises and good intentions any day.

I don't care about the masses. If signing up for a matrix account is too annoying for them they don't really care about privacy anyway. After all it's the same they have to do for any online shop. Just create a username and password. Somehow it's not a problem for the masses if they wanna order a phone charger but for matrix it's suddenly 'too complicated'?


People like you who equate signal and WhatsApp are also responsible for not making any progress due to ideological stubbornness it’s something that I absolutely despise from a part of HN crowd here.

Great, I'm happy to be a nail in the coffin of the signal advocacy.

Remember how everyone jumped on Google when they promised to do no evil? Now they're one of the most abundant mass surveillance companies in the world and we can't move away because they're too big to fail. The same with WhatsApp. People jumped on it because it was good, then nobody left when meta bought it because all their friends were on it.

Signal is one sale away from being evil too. They might not sell it but we've been conned so many times by big tech that I will only take technical guarantees, not promises that can be broken. We have to avoid getting locked in again.

And really, lots of progress is made in real open communications. Matrix is getting more mature by the day. NATO uses it, the French government and several others. And the good thing is, you can always run your own server and connect to the hive. Nobody can tell you what to do, nobody can tell you to surveil your users like the EU is planning to do.

We need something truly open. Not a WhatsApp light.


Signal is a small organization and nothing like Google. Signal is a non-profit and their code is open source.

Their code is open source but you can't really do anything with that. You can't run your own server on the network, and they've previously stated they don't want third party implementations of clients.

Again, I don't trust promises anymore. Eventually they're going to need more money and that money will come with strings attached. If some org like Matrix would get bought people would just decouple themselves from their network. With Signal we can't do that because they are the only operator.


> Their code is open source but you can't really do anything with that. You can't run your own server on the network, and they've previously stated they don't want third party implementations of clients.

There are third-party forks and clients. Parts of the US government use one.

https://news.ycombinator.com/item?id=49678919

Also, you can audit the code.


> signal is just another walled garden like WhatsApp

For me the difference is in the ownership. Who owns each. Which is BigCorp? That’s why I trust one more than the other.


Ownership can change. That's the problem. It happened to WhatsApp itself! Meta bought a network with the userbase that was already too big to leave.

> What is a more private, usable solution for filtering them out than using a phone number?

Since when is giving out your phone number a "more private" option ?


You don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people.

> You don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people.

You are deliberately missing the point.

Signal are gatekeeping these new advanced security features behind a phone number wall (soon to become paywall if some posts here are to be believed).


If it's not, let us know a solution (to Signal's actual problem as stated in the GP) that is more private.

One possible solution is to only be able to contact someone if you have received an invitation code from them out of band. E.g. "scan this QR code to add me on signal". Such an invitation code should default to single-use but users should be allowed to generate standing invitations so that businesses and the like can print and post one in their store or whatever. Start getting spam from one of your standing invitations? Just revoke it and make a new one. Presumably the Signal folks can come up with more alternative solutions than the half baked one I came up with after thinking about it for a minute, they're clever cookies.

Welcome back to “key signing parties”. PGP never got enough adoption. At least Signal is simple enough that the (ahem) leaders of the US can (mostly) manage to use it.

Unfortunately, in an end to end encrypted messaging system, an identity is denoted by some sort of long number. That is an inescapable fact. Trusting a third party to correctly map, say, a phone number to a cryptographic identity number eventually results in the sort of attacks we have been seeing with phone oriented encrypted messengers recently like WhatsApp and Signal. The PGP people were doing the right thing when they were doing education in the form of key signing parties. That is something the user needs to know.

Anonymous messengers have no real choice and have to use some sort of number for identity. See Briar, Session or Tox for examples.

My comments on Signalgate 1.0:

https://articles.59.ca/doku.php?id=em:sg


> attacks we have been seeing with phone oriented encrypted messengers recently like WhatsApp and Signal

Could you give an example of an actual attack of this kind on Signal? The 'Signalgate' event was someone mistakenly inviting the wrong person to a chat.


Leaders of the US use an Israeli backdoored version of Signal (TM-Signal) TeleMessage by Smarsh was used by DOD, CPB, and others for records retention reasons... also hacked to smithereens.

Requiring manual key verification is a bad design that doesn't scale or benefit most people.

People seem to get on with Discord invite links just fine. You don't have to do the "confirm that all these emoji are the same on both your devices" dance to stop spam.

> People seem to get on with Discord invite links just fine.

Discord is used by a narrow group of technically literate people. Signal is for everyone. Your grandparents probably don't use Discord, but if they can text then they can use Signal.


Imagine setting up a chat for an organization you're working with - will you be willing to process 20 out-of-band QR codes? 50?

On a smaller scale, it's clear that Signal believes a functioning address book is necessary for end user adoption. For example, by default Signal notifies you of people in your phone contacts who are on or who later join Signal.

> Presumably the Signal folks can come up with more alternative solutions

I have yet to see a solution better than the one they chose, for their requirements. Notice that there are none in this discussion.


Ditto for Trail of Bits, worked with them recently and they do some really impressive quality work, and have some very sharp guys working for them.

now is time to start the ai to spam/reverse the - google.com/goto for url resolution, it can't be that hard to reverse engineer how the hash works. It was doable for twitter and YouTube, it will be doable here too...

you should kick the tires on an unfiltered (abliterated model) it's the closest thing to having a real conversation with the devil. There is good reason for the concern's outlined above and undoubtedly Anthropic / OpenAI have internal unfiltered models with no safety... they got freaked out based on how they work and are virtue signaling alarm... all while selling out to defense contractors.

Yeah I really struggle to balance wanting information to be free and not wanting the information on how to make deadly weapons too easy to obtain.

At least with books or the internet you had to go through some effort


This is what made a generation of Kennedy's...

Add a dash of nimby and xenophobia and this is about right... you've got the likes of OpenAi and Anthropic destroying printed work from Austrailia and New Zealand to acquire latent data, Meta executives downloading commercial porn on their home computers and driving SSD's into work, all of them are building datascenters in metropolitan areas with generous tax breaks for their non-profitable ventures. The fact that 60% of model usage is now Chinese is what's prompting these folks to whine for protectionary measures. Meanwhile they will have no problem clearcutting massive swaths of meaningful work for people in their pursuit of AGI.

It's wild to me that PoW systems are how we sort the bot problem... the bummer is that all this "work" is just wasted cycles, at least in crypto there is a token you can sell.

> at least in crypto there is a token you can sell

That would defeat the purpose. The goal is to make scraping costly, not profitable.


Scraping would be costly in this world: scrapers would have to spend tokens in order to get the webpage.

But, in this world, the website owner would receive tokens that they can then use to do whatever they want, including paying for servers and bandwidth. This is the sense in which the cycles aren’t wasted: the website owner now has cash to spend.

Effectively, both scrapers and ordinary users would be paying for the privilege of getting website bytes.

This also solves the problem of having to wait for your phone to solve the challenge while you’re browsing: you can buy or mine some tokens ahead of time and pay them as soon as challenged. So can the scrapers, but because they’re accessing enormous numbers of pages it’s hopefully prohibitively expensive for them.


I am convinced. Is there any project implementing or proposing this?

I guess it could in principle be profitable for the website, not the client?

unfortunately at that point it would be indistinguishable from running cryptojacking on your website

No. The client is doing the work.

The client is doing the work in both cases

Yup was thinking the same: make honest people pay $0.00001 when they visit the site (in electricity/compute), have the challenge made so that only the website wins a tiny something. Bleed the bots dry.

> This makes Anubis challenges use a memory-hard proof of work function (argon2id) instead of just a CPU hard one. It also means that the "hey Claude vibeslop me a CUDA Anubis solver" route is on its way to being fundamentally dead.

Nice.


Sure, then just replace it with something that is useful to society but not immediately profitable to a scraper, like science research

I want to do this eventually, but it's hard to split things into the micro-tasks that would be required to make this work on Anubis. One of the ideas I'm throwing around is a world where Anubis helps fuzz old games to find timesaves in tool-assisted speedruns. It's harder than you think.

The tools that exist for fuzzing speedruns (TASers call it "botting") are fairly primitive, excluding a few game-specific ones. Because of that, there really aren't that many TASes where a distributed randomised search could make improvements which don't get immediately overshadowed within a day of human attention. Improving botting tools and increasing their adoption would be more effective IMO. (Incidentally, TASVideos.org recently banned one of the people pioneering bot development.)

Meanwhile BOINC is well-established as the platform for distributed computation. If you can figure out how to squeeze its work units into Wasm challenges, I'm sure a lot of researchers would thank you.


BOINC isn't really built for "small tasks", afaik. Once you get small enough, the work the server is doing to manage the tasks gets to be around the same cost as the server just doing the tasks itself.

Yeah, I'm using PoW-based "DDOS defense mechanism" for a current project and had this thought too. I briefly looked into what it would take to exploit PoW to do something economically valuable like folding@home, and it looked a bit tricky. At first glance, these sort of projects seem a bit unsuitable for real-time PoW because they were designed to be run on desktops and so tend to do things in large batches. There probably are other use-cases that could be more suitable though.

Might be worth chucking that thought into Astra, especially if someone springs the $$$ money for it?


This would be rad.

> the bummer is that all this "work" is just wasted cycles

There's probably an overlap with people who think anubis is a good idea and those who think we should be doing more to battle climate change.

The two views are not compatible though.


It's wild how many people happily jump on this DRM train now that they are hoping to gain from it.

Well, there was CoinHive which did this exact thing 6-7 years ago, but that system got abused a bit much

PoW was originally anti-spam technology.

Both CarPlay and Android Auto are second screens to your phone... they're just "Airplay" streaming a simpler interface.

being done by No Such Agency.

it's fair to say they do and have for ages... it's not that hard to assume a well trusted TLS cert is under their control.

What does having a "well trusted TLS cert" enable for them in this case, exactly?

Having a magical cert doesn't mean you can just intercept everything.


On the contrary, it lets you MITM encrypted communications by swapping the website's original certificate for the "well trusted TLS cert"

No, it doesn't. HSTS and other methods prevent this from happening.

HSTS doesn't protect you from this at all. It only requires HTTPS, which a spoofed-but-trusted cert passes just fine.

No mainstream browser (or any browser?) is doing cert pinning.

What "other methods" are there that are deployed and actually in use?


Transparency logs. It's mandatory for a cert to be in CT logs for browsers to trust it. Those are public, if this was happening, someone would have noticed already.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: