Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>How do you find each other?

by exchanging public keys over an established communication channel

>If it's feasible for an end user, say 30 seconds of a phone's CPU, you can be sure that a spammer could generate millions.

yeah, that's an inherent limitation of PoW, so it has to be an option rather than a requirement. then people who don't care about privacy can do the SMS thing, and those who do can opt to do the 30 minute PoW.

but this is irrelevant to Signal. it's not the phone number verification itself that people have problem with. if the only purpose it served was to prevent attacks on the service by ratelimiting it to one account per one phone number, that would be largely fine. the problem is that your phone number is your Signal identity, which is utterly moronic for a "privacy-first" service, and the reasoning and excuses for this stink to high heaven.



> by exchanging public keys over an established communication channel

I get the appeal, but seems like requiring out of band key exchange will add significant friction and make signal much less popular compared to the competition. I've got a few dozen signal contacts, only a few of them close enough to do a key exchange. If I only had a few, not sure I'd use signal.

Signal has been resisting making special cases for the few, and I get it. Why spend developer time on some feature that's not going to benefit the majority of users?

> the problem is that your phone number is your Signal identity, which is utterly moronic for a "privacy-first" service

I can't think of anything that would work as well and result in so many (40M monthly) people communicating securely. They do seem to be considering their options to help with this, in particular: https://signal.org/blog/secure-value-recovery/

Allowing social networks, surviving the death of your phone, frictionless on boarding, account recovery, etc all interact in complex ways.

Personally I like that there's not a contact database/social graph inside signal.


>requiring out of band key exchange will add significant friction

how do you exchange phone numbers and email addresses with people?

>and make signal much less popular compared to the competition

is popularity among the (COMPLETELY) tech-illiterate worth giving up privacy for?

>I can't think of anything that would work as well and result in so many (40M monthly) people communicating securely.

and virtually everyone who had ever used the internet has an email, despite its apparently cumbersome sign-up and contact discovery procedures.

>surviving the death of your phone, ... , account recovery

are less likely if your account is tied to the phone number or email. they can be lost, they can be stolen, they can be seized.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: