and still no app for Android tablets ffs
this is bullshit designed to respond to increasing use of simplexchat and other platforms
and they still want to tie it to payment (so a credit card) so they can track people
and they are implementing it only after many years
a complex captcha that takes 10 minutes to solve would work just as well as payment, but they aren’t doing it, and it certainly leaves me wondering if they are a honeypot. i can’t prove it, but it’s really suspicious it’s taken so long to possibly roll out something that may require a credit card
I have watched the futo video and i think don’t think its very likely it will become a paid feature. The CTO said they would want to have the registration require some kind of cost but it was almost certainly meant as a computing cost not money. Link to the same video in case you can’t play it https://i.imgur.com/QMDjn7T.mp4
GitHub commit d7447b1 states that “accounts without phone numbers can never get phone numbers, and accounts with them can never lose them”.
So you’ll have to register a new account if you want to decouple your number.
didn’t they announce this like five years ago
I mean, they also were developing usernames five years ago AFAIK. Adding usernames for everyone was the hard, but necessary step they finally managed to do. Only now is it possible to make accounts that are discoverable AND aren’t tethered to phone numbers. I’m assuming with passkeys/TOTP(?)
At this point, if it’s on a phone app, it probably doesn’t matter. They have your number.
No, apps (at least on Android) require a specific permission to read your phone number. The phone capabilities of Signal go through their own VoIP service, not your phone.
It’s not entirely dystopian (just barely), we have newer messengers like SimpleX and DeltaChat (I/we use Delta) on the up and coming which deliver on all the same e2ee promises as Signal. It’s just network effects as usual, getting people to try is the real hurdle.
What they share in common (mostly) is the architecture - they’re built natively decentralized, utilizing caching relays with no single source of truth, or device of truth, to be used to create a profile of you like a phone number does. Encryption keys owned by the user and no single servers. Generally this is the Nostr design as well, so we have 3 different teams all focusing on the same natively decentralized architecture patterns.
Simplex is a dog though compared to Signal.
I haven’t tried SimpleX yet, as they can’t share the same profile to multiple devices (it’s explained in detail in the FAQ) which makes it a normie usability deal killer. I’ve heard it has really bad battery life on mobile too, but that’s just reading random comments. Right now we’re using Delta (and running a relay) and it’s just fine.
Don’t forget Briar!
Briar fits into it’s own niche (operational design), making it a choice for certain activities but not what I would call your general normie chat app. It makes tradeoffs (using the local network, no caching relays, etc.) to increase security posture at the expense of general use. IIRC, Jack Dorsey’s BitChat was modeled after the same designs? (which is interesting, because Nostr his other pet doesn’t)
Is any of these apps good for phone calls or video calls, or just text messages?
At this rate Canada would probably ban anything they can’t get records from eventually if it got popular enough. I hate this timeline.
And Canada is supposed to be “the good guys”.
no good guys out there as state actors, some are the “lesser evil” and we all have to live somewhere
They have great PR, but other than that no, unfortunately
I started self-hosting xmpp recently, and the calls work perfectly! You don’t need to self-host either, there are plenty of public servers.
Arcane chat (a delta chat client) offers video/audio calls as well
Delta has it native.
Must be a newish update.
I think it is. I don’t remember seeing it before.
Thanks!
Bullllllllshit.
They’ve said that for years. It’s easy to do. But they won’t do it
How’s it easy?
Not the technical part (which definitely looks as easy as just dropping a requirement), but the spam/abuse prevention part.
It’s pretty easy to detect spam. I guess user reports and noticing when someone suddenly messages many new users and those users do not respond.
Anyway, it’s not an issue on Wire or SimpleX or the dozens of other platforms that don’t require phone numbers. It’s obviously a solved problem. Signal is just making up fake excuses.
It’s pretty easy to detect spam. I guess user reports and noticing when someone suddenly messages many new users and those users do not respond.
It’s not so easy, because you could even register a new account for each new spam message, or register 100k accounts & only send out 3 messages a day / account…
Obviously not. Because this isn’t an issue elsewhere
It’s pretty easy to detect spam.
Tell that to… any social media. Lol. If was easy to detect bot you think they not big problem anymore.
Social media is different from a platform that’s literally just DMs.
No need, using https://keet.io/
So, no asynchronous messaging? Kinda kills it.
just go the matrix route; username, password, 2fa, then any other connection requires you to verify with a current logged in session (or recovery code).
Cannot decrypt message
As someone who uses matrix and runs a matrix server, matrix fucking suuuucks jfc why are so many privacy tools soooooo bad at what they do on so many levels like wtf the proto the servers the clients the ux the metadata issues like so much wrong
Edit: and if anyone tells me to use XMPP I’ll slap them
I don’t understand why an email registration is not an option? it was the default from when online services and apps appeared in the first place, and until about 5 years ago (depending on types of services/apps), and it’s security and anonymity was purely based on you using your “main” address or a throwaway.
The article says their main reason is spam/abuse, as requiring a phone number adds some sort of gate to lessen that. Emails are easier to create en-masse. I don’t agree with using phone numbers either, I’m just relaying their reasons.
Yep, that’s the bullshit they always say. Fortunately it’s easy to see through this PR shite
I would guess the sudden influx of massive amounts of traffic would force them to charge for the service, and they don’t want to do that. Requiring a phone number, while invasive to some, does cut down on a tremendous amount of automated/bot/spam traffic.
Because Signal wants a link to your identity.
Why would they? Do you have anything to back that opinion up?
Yeah, their history of claiming they’ll do this, but never do. All their decisions to require a phone number or some other identity link
The post is literally about Signal developing a way to log in without that link
And I’m telling you, it won’t happen. They will probably require some other UUID.
Signal had made it clear that they need to identify their user’s identities.
Mark my words: if you try to create an account on TAILS, and your fingerprint isn’t unique, you’ll get an error when you try to create the account.
Boy… We are going to get spammed.
I never understood the “phone numbers are evil” people, whining about signal requiring them. As soon as this arrives, they will find another thing to whine about.
Hopefully Signal will make it possible to block any and all communications from people wohtout a phone number, unless I reach out to them. And that that feature also be introduced to groups. Because otherwise maintaining public groups is going to be turboshit.
simplex doesn’t require phone numbers or emails to sign up.
instead you need to scan codes for a trust. it’s actually everything I wanted in a messenger. well…I wish they had gifs like telegram.
And how’s the spam on simplex?
nonexistent.
unless someone literally invites you to the chat you’re not getting in.
unless you literally allow someone to scan your code, you will not be able to send them messages.
Wat? What about public groups?
they are currently in beta but really don’t exist.
mobile numbers require government identification in many countries. But yeah, not seeing an easy solution to the spam problem
mobile numbers require government identification in many countries
Yes and all they will know is “person A has installed signal”. Nothing more. If you haven’t degoogled tour phone or use one with a fruity logo, the government knows that you have the app already. It won’t need phone number.
Remember metadata , they also know person A send message to person B at specific time. Of course knowing phone number also gives them your location from cellular towers.
If you’re using text messages, yes, but not with signal. They just know that you have it, nothing more.
huh? you can’t see the difference between a grapheneos burner linked to a gov ID backed phone number and one that isn’t?
like what happens when you go to a protest and they pull out a Stingray and get your IMEI+ICCID down that’s directly linked to you? you’re telling me you don’t see any issues with cops/ICE being able to know exactly who goes where?
this has strong “I don’t need freedom of speech because I have nothing to say” vibes - it’s fine if you don’t see the value but I can assure there very much is
You’re fighting a scarecrow in your head that you built. “This has a vibe so I’ll vibe comment”
Once you come back down to earth and want to talk seriously, ping me. I don’t debate paranoid snow bunnies.
ah yes the paranoia of documented evidence…
i wish I could live in your fantasy land where fascists weren’t in power and being an antifascist wasn’t a terrorism offence
Buddy, how are you going to communicate with people via Signal even without a username? Are protests full of free WiFi?
If you think getting rid of phone numbers on an internet connected application will help you at a local protest where you should be using a local network for communication (Bluetooth for example), you are just lost.
Having your phone number will only reveal that you’re using signal, not who you’re talking with nor the groups you belong to.
look you obviously don’t do grassroots political organising if you’re asking such silly questions - this whole thread was about you thinking numberless signal accounts aren’t useful - and being more worried about your made up spam boogieman - than the actual threat of fascistic state violence
prepaid sims exist, yes briar exists but it’s not viable when people need to communicate over whole city distances (eg for spotting), if the cops can connect your burner to your actual ID at an anti-ICE protest - they can very easily raid your house after the fact - and no they don’t even need a warrant due to the extraordinarily powers given to “anti-terror” police forces.
please touch grass and stop being an armchair security expert and let the adults think about applied security in the real world
SimpleX, Cwtch, Briar?
SimpleX is awesome SimpleX is awesome.
I think only SimpleX has asynchronous messaging
When you send a message, and it gets delivered when the recipient is online?
Delta has that, but you have to be online for the message to be sent later, since there’s no central server to cache it.Yes, that means it’s synchronous.
My point is that we need servers for asynchronous messaging (or some clever network where everyone is a server relaying messages for others). Lacking asynchronous messaging is not going to be a practical solution for 99% of people.
Encryption works. We don’t need to trust servers. They’re not inherently an issue for security nor anonymity.
Thank you for the clarification. I just wasn’t sure on the terminology, but this makes perfect sense.
We don’t need to trust servers. They’re not inherently an issue for security nor anonymity.
For me, my issue with a central server infrastructure is less that it can be snooped on (because, to your point, properly implemented encryption does work) and more that it’s easy to be taken down or censored, since it is a central server infrastructure.
The benefit with the every-client-is-a-server infrastructure, such as the one that Delta uses, is that if one of the many servers gets taken down, the network, as a whole, keeps working.
Something similar can be said about the Lemmy infrastructure, really any of the Fediverse. If one of the servers gets taken down, there are still hundreds, thousands, or millions more that are serving content, even if not the exact same content, allowing the social network, as a whole, to not be subject to mass censorship.For the everyday, central infrastructure, such as the one that Signal uses, works perfectly fine. For those “special locations”, a decentralized every-client-is-a-server infrastructure might be a requirement. So it really is situational.
That’s a good point.
I guess the best is a hybrid where the server is just optional for asynchronous messaging, and if the server is temporarily down, the service just becomes temporarily degraded into synchronous mode.
Trump hates this plan














