Hacker Newsnew | past | comments | ask | show | jobs | submit | opengrass's commentslogin

You can already do that without being a trusted device.

For the longest time, you couldn't. It wasn't until this release I realised that had changed. If it changed before, it wasn't well communicated to me as an Android signal user. I was on beeper and then molly precisely because there was so little traction on changing this. You could install signal fine, but you couldn't QR code or secret phrase mesh it with your android handset. Oddly, iPad meshed fine with iPhone or Android, and OSX desktop likewise. Just Android tablet which didn't.

Do you think this changed in over 18 months? I think it changed in under 18 months.


I think this is pretty recent, I'd never heard of it before. I even got a new phone a month ago and didn't notice this being an option.

Definitely under 18 months.

If I’m not fully mistaken, I checked for the combination of iPhone as main device/Android tablet as iPad-like second device sometime in the past six months, at most since the beginning of the year, and it wasn’t possible (unlike phone + iPad as tablet, which seemed quite strange to me).

In any case, it’s a recently released change.


Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.

Ah OK, I wondered where is the "catch".

You cannot keep all 3 of "no gatekeeping" - "anyone can message anyone" - "low spam".


It says something about Play Billing being used specifically to mitigate spam?

I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.



Wouldn't that be related to data storage? Which they offer now? Or is that different?

Ah, I thought you meant using google play to do the payments to prevent spam unrelated to the cost. I know they are costing something.

Ugh wtf so I need a Google account on Android? That's not going to happen.

For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet.

Just allow monero payments or something. Alongside Google play for the sheep that want to use that.


> Just allow monero payments or something.

This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.


> If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.

How do they perform address book matching without an phone number? It just being accessible by SGX does not really count as not storing it.

Problem with phone numbers is they are to short to store as a hash, since you can brute force the sha256 of an phone number in a trivial amount of time on a single consumer device


Wouldn't a payment of about $0.05 do the trick? My understanding of most kinds of spam is that it relies on being able to deploy hundreds of thousands of bot accounts just to get a few hits.

This is for registering an account that can then send many many messages.

Are you being hyperbolic, or do you really consider Google the worst with regards to privacy.

The most ubiquitous, absolutely. Their data collection is unparalleled. They're on almost every website, app, they have fingers into payment and browsers and mobile OSes.

In terms of what they do with big data there's more evil parties like Palantir but data abuse starts with collecting it, and I would object to it even if Google promised to only use it for good. For me my privacy is already violated when my data is collected, not just when it's abused. And I do consider Google's use of that data abusive, just not in the worst ways.


The idea that Google isn't the worst in respects to privacy is not an idea I've seen. Is there a company you propose as being worse? I think Meta is the next contender but they don't have nearly the same influence, so its still Google. Not for a lack of trying though. Mark would love to have the data and infrastructure dependence that Google holds over the internet.

Google is a bad as a phone number since it also has strong ties to your real identity

Yes. Google is even worse imho.

Google is objectively the worst

Hopefully they eventually make a way to pay without it.

You wouldn't believe the spam if they did that

Why? Just raise the prices if they get more spam on non-google payments.

I've literally registered a Signal account on one of the free SMS sites floating around. Why would spammers choose the payment route over phone numbers? They would just choose the one that's cheaper.


Can you actually make a Google account without a phone number these days?

googles obligation to hand out all account linked info notwithstanding, one may still create google accounts without associating a phone number, by doing so on old android versions. signal does however explicitly force credit card info here, thus providing direct individual traceability ..

Plus they are mandating you give your details to Google. So much for privacy

What about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.

Nobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal.

They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.


I always thought they didn't want monero because they were pushing their own crypto thingy. Which indeed nobody uses.

They avoid Monero because Signal and the EFF are actually the feds and this is all theater.

Claims without evidence can be dismissed without evidence.

Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX.

If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?

They are the largest messenger that has E2EE backups by default.


If I was the NSA, I would be using the fact that signal uses AWS for their backend combined with the cudgel that .us.gov has with the AWS govcloud contract to mandate that all traffic to and from signal's backend also gets routed to NSA traffic analysis servers, which could then be correlated with other sources like ISP data to get a pretty complete record of all Signal message metadata.

To be clear, I use signal pretty heavily, but that's because my threat model doesn't really include competent .us.gov actors. I don't think that they'd either prove they're doing this or go through the trouble of parallel construction over anything in my messages or who I'm talking to.


Nobody is arguing the e2ee isn't valid, its useful as a metadata collection platform, which is all they care about. Former NSA and CIA Director Michael Hayden famously stated: “We kill people based on metadata." and then he tried to hold back a smile and said "but not with this metadata". It's usefulness as a metadata collection platform becomes much less useful if people don't trust it, so of course it's secure.

If you can convince as many of your enemies (the american people who politically organize against them) to use the same platform, your job becomes easier than having to ETL from 20 different privacy platforms..

To be honest, I use signal, I have nothing to hide but it is useful in that nobody can spoof me (easily). I even talk to my 60 year old mother on signal. It has it's uses. But the EFF is definitely a federal psyop to get people using tools and techniques they control.

Just look at the people who created TOR, they're all feds. All these projects are funded by feds. These tools are advertised in CIA recruitment campaigns, they are literal weapons to circumvent nation state firewalls and deliver psychological weapons, overthrow governments or allow covert recruitment of foreign traitors.


I'll see your conspiracy theory and raise you one: What if the feds fund tech privacy projects specifically so that people like you won't trust them, and instead embrace privacy nihilism?

This is a known strategy of the Kremlin, by the way. They fund opposition groups which protest them, and then leak the fact of that funding so that people who are genuinely upset at the Kremlin get confused about who is captured opposition and who is legitimate.

It can be a signal in some cases, but funding sources are not a reliable way to make a conclusion about a group's motivations.


They funded it from the start via Radio Free Asia (CIA) and the Open Technology Fund.

Signal is for protecting opposition groups that help in regime change operations.

Why would people embrace privacy nihilism? The Signal shills also agitate against gpg/PGP, so we know it is secure and you should use that instead.


>Signal is for protecting opposition groups that help in regime change operations

SMS registration flow is trivially blocked in places where regimes are controlling telecom infra. And Twilio is unreliable in dozens of places for non-political reasons. Signal is very first-world centric from this point of view.


True, if they're not even going to allow that for payment then they might as well remove it from the app altogether. Because what's the point if they don't even believe in it themselves.

I've literally never seen anybody mention it, much less use it since it was announced.

AI slop


hmmm, thanks.


RTMFers will inherit the earth.


Lenovo, ASUS and Acer only. Dell takes orders without Windows.


Lenovo also takes orders without Windows. Only for "configurable" skews through the website though.


*SKUs


LDAP, or...

Linux/BSD as the identity/runtime layer, SSH is the protocol boundary, and your web backend is the command gateway.


Too many of these low end resellers are unreliable, root your VM and unprofesionally fight with customers in the forums. They are children. Go with one that owns the hardware.


Yeah. Back in ~2011, when I was in high school, I used to sell these kinds of VMs as a host and advertised on LowEndBox. Literally as a minor. I don't really trust any small time host with my data.

Meanwhile I recently migrated a $5 DigitalOcean VM that's been running flawlessly for over 6 years. It was in dire need of an Ubuntu upgrade. I expect this one to keep going for just as long!


Not necessarily. I've been using a couple of RackNerd VPSs for non-critical stuff for a few years now and they have been rock solid. Hetzner and Contabo are also reputable providers with competitive pricing.


I recently migrated from Digital Ocean to Scaleway. Digital Ocean was great but I had to make sure my stack was entirely in the EU in case the US decides to hit a kill switch for some mental negotiation tactic. Pricing and interface and performance are all similar.


All reputable.


No idea why you're being downvoted. I've bought el cheapo LowEndTalk-style VPS specials on two or three occasions and have gotten what I paid for each time. They either sold a microscopic slice of some over-provisioned 15-year-old POS or outright lied to me about specs then argued until I did a chargeback to recover my money.

For app hosting I'd either 1) use cloudflared and a cheap Lenovo Tiny box to host from my house, 2) write something serverless that runs on Cloudflare Workers, or 3) use a real host that isn't 18 months old and run by hucksters in a race to the bottom.


I’ve been using super cheap VPS just for the public static IP. They reverse proxy straight into my homelab.

The wireguard tunnels haven’t gone down after years of no maintenance use.


These cheap resellers are also magnets for spammers, scammers, and hax0rs, so good luck running anything you don't want caught up in a subnet ban.


So just like DigitalOcean then. It's the first ASN I block when setting up a new website or server.

https://urlhaus.abuse.ch/asn/14061 https://threatfox.abuse.ch/asn/14061


To be fair most data center blocks are in ban lists.


I sure do love the Apple logo imprint it leaves on the screen, like my nanny's lipstick!


1. Ctrl+F systemd

2. Alt+Left Arrow


I went on a date with a LinkedIn connection, here's what I learned about lead generation:


This comment is pure gold


I see what you did there, and really appreciate it.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: