TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Signal: Safety number updates

107 pointsby thecoffmanover 8 years ago

7 comments

cafover 8 years ago
Enabling the advisory mode by default seems like a mistake, at least with the current UI. It is so unobtrusive that it carries a very distinct implication of <i>&quot;we&#x27;ve looked into this for you, and you don&#x27;t need to worry about it&quot;</i>, which is not the case. The iconography of the shield also implies this - it says &quot;Signal is protecting you&quot;.<p>The message probably needs to be more explicit: <i>&quot;Voltairine de Cleyre isn&#x27;t using the same safety numbers anymore. Probably this contact just has a new phone or reinstalled Signal, but you might want to confirm the new safety numbers with them.&quot;</i>. And the accompanying icon should be an ! or ? or something.
评论 #12983200 未加载
评论 #12985340 未加载
评论 #12983979 未加载
nickikover 8 years ago
One features that Threema has is that you can see that you have verified the other persons key. I think Signal should have that too. If the other person reinstalls you just drop down back to a lower trust level.<p>Threema does it with 3 dots red, orange ad green, but other versions of this might be experented with.
beardogover 8 years ago
One of Signals worst problems is that it entirely relies on Google to not provide a malicious APK during initial installation of the app.<p>(Yes, it is open source, but most people don&#x27;t have the knowledge or time to compile software themselves)<p>I still think Signal is one of the best secure messengers though.
评论 #12985232 未加载
vengefulduckover 8 years ago
The problem is non security minded users probably won&#x27;t take the time to verify the numbers in the first place. They should look into a method that verifies identities without user interaction. Possibly by having signal store users public keys after they verify their phone numbers or better yet provide users with signed certificates for verification purposes.
评论 #12984431 未加载
评论 #12984046 未加载
breakingcupsover 8 years ago
There was something weird going on when I set up Signal for my partner today. She had downloaded and installed Signal through the play store and we tried to scan and exchange safety numbers. My phone gave me the message that <i>her</i> version was outdated. The other way around gave her the same message.<p>When I updated my version it all worked out.
r1chover 8 years ago
These changes seem to bring it much closer to the implementation in WhatsApp, although WhatsApp defaults to accepting modified fingerprints.
macraelover 8 years ago
How do you view safety numbers on iOS?
评论 #12983325 未加载