TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ephemeral usernames safeguard privacy and make Signal harder to subpoena

97 pointsby georgecmuover 1 year ago

9 comments

wolverine876over 1 year ago
It sounds great and well thought through, as always for Signal. I wonder how they handle two potential security holes:<p>1. Imagine a journalist publicizes a username for a long time, then changes it. The old username would persist in data stores online and in address books, and would be used in error. An attacker could acquire the old username and impersonate the journalist. Perhaps a solution is to make at least some usernames, possibly at the user&#x27;s option, non-reusable.<p>2. One strength of Signal is not only do they not collect much user data, they can&#x27;t. Under some court order, they could retain the hashed usernames.
johnnyoover 1 year ago
It’s not clear to me, but can usernames be reused?<p>Let’s say I create a username and then later delete it as they suggest.<p>Can someone else then create the username and continue the conversation?<p>Is there a means to know if I’m talking to the same “Bob.smith.123” I was a few weeks back?
评论 #39598357 未加载
评论 #39600130 未加载
评论 #39598272 未加载
dangover 1 year ago
Recent and related:<p><i>Keep your phone number private with Signal usernames</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39444500">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39444500</a> - Feb 2024 (872 comments)
evbogueover 1 year ago
I&#x27;m trying to imagine the code behind this ephemeral username strategy. I imagine a kv store under Signal&#x27;s control where you are allowed to set a key &quot;username23&quot; and a value &quot;773-510-8601&quot; and the cool thing is I can make a lot of keys that point at my phone number.<p>Maybe it&#x27;s more complicated than that?
评论 #39595620 未加载
TwoNineFiveover 1 year ago
It really bothers me that they are calling these &quot;usernames&quot; at all when they are clearly not.
andrewjlover 1 year ago
I might be missing some background on the topic but is this a real-world example of a differential privacy[1] technique?<p>[1]: <a href="https:&#x2F;&#x2F;privacytools.seas.harvard.edu&#x2F;courses-educational-materials" rel="nofollow">https:&#x2F;&#x2F;privacytools.seas.harvard.edu&#x2F;courses-educational-ma...</a>
评论 #39597890 未加载
badrabbitover 1 year ago
Won&#x27;t be going back to Signal anytime soon, too secure (lost important stuff due to their poorly designed backup system) for me. But this has always been why I claimed Signal can&#x27;t be trusted and I&#x27;m glad I can&#x27;t say that anymore.<p>Assuming of course that you can use Signal on the desktop with usernames without ever involving a mobile app. If they haven&#x27;t fixed that then I&#x27;m leaving them in the untrusted bin.
评论 #39601056 未加载
评论 #39601113 未加载
johndoughover 1 year ago
All this would not be necessary if Signal did not collect phone numbers at all.<p>The usual excuse is that they need phone numbers to combat spam, but that is only because they allow arbitrary contact requests form random people. It would be easy to imagine accounts without arbitrary contact permission. Contact requests could still be exchanged by e.g. meeting offline in person or with time-limited friend request codes.
评论 #39595986 未加载
评论 #39595331 未加载
mr_spothawkover 1 year ago
I remain unconvinced that phone manufacturers are unable to read the screen. Username obscurity is neat for p2p privacy, but does nothing against &quot;the cops&quot; if you&#x27;re doing something they don&#x27;t want you to.
评论 #39597960 未加载
评论 #39597682 未加载
评论 #39595997 未加载
评论 #39601308 未加载
评论 #39599742 未加载