cross-posted from: https://lemmy.world/post/12200311
Signal Finally Rolls Out Usernames, So You Can Keep Your Phone Number Private
Whittaker says that, for better or worse, a phone number remains a necessary requisite
Worse. It is for the worse. We sure did wait a long time for this half measure, Signal.
Removed by mod
Jami doesn’t require a phone number, which is p2p. Xmpp (+ Omemo) doesn’t require a phone number and it’s federated… I mean, if a service is willing to rid of phone numbers, it’ll do totally without them.
The challenge of having your device solve a nasty PoW that takes minutes would not deter most people: a timer once is better than evil captchas, phone numbers, etc. I don’t understand why they use hCaptcha and not that.
Removed by mod
A lot, but farming phone numbers from poor countries is also cheap and Signal sends them insanely expensive SMS. There is no perfect solution, spammers aren’t stupid. Since Signal is centralised they can enforce PoW incrementally if they get reports for spam, I still think it is way better than hCaptcha which is garbage.
Removed by mod
Removed by mod
It’s the signal metadata that they want to keep associated with an identity
They still can fulfill government requests for who is talking to who and how often
Removed by mod
Got proof for that last claim?
I thought their sealed sender feature was meant to prevent exactly this scenario.
Maybe use a VOiP for verification?
If anyone knows how to get the beta without having to join the beta programme on Google Play please let me know; my phone is degoogled. They do have an apk on their site but it’s not the beta.
Fucking beta release . I’m not making google account to download the apk
Slim shady
Signal is one of those apps that is good because it is popular and old.
However, they need to step up there game if they want to compete with other messagers.
Its also the only really free messenger. Free as in freedom and no money.
- Session
- Briar
- Simplex Chat
- Jami (unproven)
I use Jami daily. The pro is that it is completely decentralised: it doesn’t need a server to run, all communications are over DHT. The cons is that not all messages are delivered instantly, and both sender and recipient need to be online at the same time.
Be careful as its not been audited
I am not expecting security from it, just complete decentralisation.
Yeah mainstream messenger that other people have. I personally like briar but it sucks my battery dry in houra.
You still need to put in your phone number to use their increasingly limited service though. Either go full bare sms/RMS integration or go full anonymous username only. This half ass approach please no one.
I still cannot comprehend their logic for why having full SMS integration would be such a disaster. It just makes no sense and I wish they’d admit that it isn’t a security concern but is just that they don’t want to do it. They just don’t want to, and don’t care that this policy makes it harder for users to adopt and use their service.
I know that SMS is a US-specific thing. But at least in the US, most people regularly interact with SMS. Having a platform that supports SMS means you can basically live in that platform – this is a major part of the success of iMessage.
The idea that it would create huge security gaps… I just don’t believe. I think the kind of user who wants to be on Signal clearly understands that SMS is not secure. All they need to do is have a clear visual indication when you are texting instead of using Signal, which isn’t that complex.
Instead, people like me who might try using it as their primary platform just see no point. None of my friends use it. So why should I even have it installed? And none of my friends see a reason to install it because I and everyone else don’t have it installed. If I could use it as my SMS app I might have it installed and lived-in, which greatly lowers that barrier.
Removed by mod