this post was submitted on 28 Aug 2024
609 points (98.0% liked)

Technology

59534 readers
3143 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] sugar_in_your_tea@sh.itjust.works 34 points 2 months ago (5 children)

You can use a username only for finding and adding friends, you only need the phone number to create an account. That's probably because Signal started as an alternative to Messages (or whatever it was called back then), so you could send SMS if you wanted, or secure messages to friends w/ Signal. The whole point was to be a gentle transition from SMS to private messaging. However, they eventually dropped the SMS feature, but it seems they kept the phone number as username thing.

It kind of sucks, but I think that's a reasonable limitation since the vast majority of people using this service will have a phone number. You could probably even sign up for a free trial of something (e.g. Google Fi) to sign up for Signal, set up the username, and then drop the phone number service. I don't know if there are any problems with this, but I don't think they do anything with your phone number after everything is set up.

[–] EpicGamer@lemmy.world 14 points 2 months ago (1 children)

I think another reason they use a phone number is that it can mitigate issues with people or bots creating hundred of accounts maybe

But there are plenty of other services that don't require a phone number that also seem to mitigate that issue, so while it may be a convenient option, it's hardly the only option.

[–] 01189998819991197253@infosec.pub 8 points 2 months ago (1 children)

Yeah. And I don't fault them for this route. I just with I could sign up without a phone number. Maybe the username thing is a predecessor to allowing usernam-only registration in the future.

[–] sugar_in_your_tea@sh.itjust.works 4 points 2 months ago (2 children)

Yeah, hopefully. It would also be awesome to have a web login so I could access messages and whatnot when using someone else's computer w/o having to install something.

I don't know what direction they're going, but I'm honestly okay with the caveats that currently exist.

[–] 01189998819991197253@infosec.pub 5 points 2 months ago (1 children)

Having web logon would mean they would need to hold the decryption key in some form (or have a weak decryption key, your credentials), so, while convenient, I think it would degrade security and possibly privacy. Unless you mean to receive new messages, the way the desktop app works?

[–] Manalith@midwest.social 2 points 2 months ago

I'd be more interested in allowing more than one Android device at a time like MySudo. They let you link Windows with a phone so I wouldn't think it would be too hard to implement.

[–] vulgarcynic@sh.itjust.works 5 points 2 months ago (2 children)

Big concern with your number being recycled and a new user receiving the signal activation key on that number.

[–] sugar_in_your_tea@sh.itjust.works 3 points 2 months ago (1 children)

Sure, and I think that would send a message to all of your contacts that a new account is using that number, but I'm honestly not sure. If you have an active account (i.e. on a desktop or something), I think you can just change your number if that happens (i.e. get another temp number).

It's certainly more convenient if you use a longer-term number, but I think it's feasible with a throwaway number. Once your account is set up, Signal doesn't need your number for anything if you disable publishing that.

[–] vulgarcynic@sh.itjust.works 1 points 2 months ago

It does send a "your safety number has been updated with user" message. But not as an automated message. Only when a new signal thread is started.

Haven't tried when only logged in to desktop and changing devices / numbers so I can't speak to that.

[–] Neon@lemmy.world 3 points 2 months ago

You need to enter your Signal Pin, otherwise you will get removed from all groups etc

[–] EngineerGaming@feddit.nl 4 points 2 months ago (1 children)

Another issue with phone numbers is that it makes it easier to censor - from what I heard, in Iran the confirmation SMS just would not arrive, making rentals the only option (thus making you risk your account being deleted by the new owner).

My personal biggest issue with Signal, though, was the inability to register from the official desktop client. They were pushing to register on mobile instead. There are ways around it, like Signal-Cli (what I used) and Android VMs. However, the fact that they push people onto mobile at all is worrying, because phones are much harder to make private (while you can install Linux onto pretty much any given laptop/desktop, only certain phones are compatible with alternative OSes, and mine wasn't so I could not trust it with my chats).

[–] sugar_in_your_tea@sh.itjust.works 2 points 2 months ago (1 children)

Hmm, I guess then you'd need to get a VPN that works in your country (not sure how hard that is in Iran) and find a VOIP service that either doesn't require any payment, or accepts payments from Iran.

It's certainly not ideal, and I wish they'd eliminate the dependency on phone numbers, but until then, there are options for most people to create an account w/o having a permanent number.

[–] EngineerGaming@feddit.nl 2 points 2 months ago (1 children)

You can use Monero for payment, I started doing this ever since sanctions began. Free services are not really viable because they're far more likely to have all their numbers already used up.

But yea, the overall point is that it is a large inconvenience and a possible point of failure (the next number user deleting the account).

[–] sugar_in_your_tea@sh.itjust.works 2 points 2 months ago (1 children)

Yeah, it's certainly problematic, and I'd very much prefer that it not have that dependency. But I think it's still worth using Signal despite needing a number, because it's a really low barrier to getting new users on it.

If you want something truly private w/o the dependency on a number, there are better options, such as SimpleX. However, the barrier to entry there is a bit higher.

[–] EngineerGaming@feddit.nl 2 points 2 months ago

I have a few problems with Simplex (I worry about it being effectively centralized for now and that the VC funding may get it to either enshittify or stop development)... But I do use it quite a bit and even have the servers (which were very easy to set up and don't consume a lot of resources). I like a lot of what it does (including being very easy to use), and hope it succeeds as it matures!

[–] EngineerGaming@feddit.nl 2 points 2 months ago (1 children)

Google is a very bad choice because it requires a phone number on its own. Also heard that there may be additional KYC.

[–] sugar_in_your_tea@sh.itjust.works 2 points 2 months ago (1 children)

Are you suggesting you need a phone number to get a phone number from Google Fi?

And yeah, it'll definitely to KYC, because that's a federal regulation. My point is that you don't need the number long-term, so the number will only be associated with you for like a week while the trial period lasts. So sign up for Google Fi trial, create a Signal account, then cancel the trial. That sounds pretty reasonable to me.

[–] EngineerGaming@feddit.nl 2 points 2 months ago* (last edited 2 months ago) (1 children)

Yea. Don't you need a Google account first to use such a service? Those do need phone numbers to register.

And also KYC is unacceptable in this case, imo. If the number is needed only for a short time, there are similar, non-KYC options like what you would find on kycnot.me.

[–] sugar_in_your_tea@sh.itjust.works 2 points 2 months ago (1 children)

Yeah, I think you'll create a Google account as part of the Google Fi account creation process.

If that really bothers you, use a different MVNO. Some offer free trials, but even if not, it's not too bad to buy a month of service. My provider is Tello, and the minimum service that'll give you SMS is $5/month. If you're clever, you can probably also find a VOIP provider that does SMS for really cheap.

My point isn't that Google Fi specifically is what you should use, just that it's an example of a service that offers a free trial, so you can sign up for Signal for free.

[–] EngineerGaming@feddit.nl 3 points 2 months ago

I get the point, I just said how bad of an example this is, lol