Hacker News new | ask | show | jobs
by samatman 1590 days ago
Either you don't understand how Signal works vis a vis phone numbers, or you're expecting something unreasonable.

The behavior which is reliably objected to by someone on HN, every time Signal is mentioned, is that the app sends a user an alert when someone in their contacts list is on Signal.

Phone numbers are the only resolution mechanism in Signal. Should that change? Separate question.

Having someone's phone number is by definition a way to contact them. Registering for Signal is by definition agreeing that anyone who searches for your phone number can send you a message on Signal.

What is the privacy violation in pushing awareness of that affordance? What about pull-only is better?

Signal does what I want it to here, and my trouble understanding why someone would be ok with everything about Signal except the push notification on join to people who have your number is genuine.

It's easy for me to understand why people don't like that a phone number is inherent to Signal, don't much care for it myself. But it's unrelated.

2 comments

Whether or not I use Signal is private info, which is separate from my phone number info. Signal is mixing the two as if it was the same.

A username kinda restore that, but it could be taken a step further and ask for a secret token when adding contacts. That way you know exactly who has you in their contact list, and this token could be revoked (equivalent of blocking the person).

At least personally, the privacy violation is most clear if you are not part of a community that uses encrypted messaging by default (nearly everyone I know who uses SMS/FB messenger). The fact that someone I know has downloaded Signal then reveals that they now care about using encryption, which usually has the very obvious inference that they are involved in activism/have journalistic sources/other more nefarious activity that they care about encrypting. You can usually figure out which it is if you know anything else about that person. I would not know this if Signal didn't push the information to me, since I am not going to constantly search my entire contact list to find this info.