GitHub commit d7447b1 states that “accounts without phone numbers can never get phone numbers, and accounts with them can never lose them”.
So you’ll have to register a new account if you want to decouple your number.
Icon base by Lorc under CC BY 3.0 with modifications to add a gradient
GitHub commit d7447b1 states that “accounts without phone numbers can never get phone numbers, and accounts with them can never lose them”.
So you’ll have to register a new account if you want to decouple your number.
didn’t they announce this like five years ago
I mean, they also were developing usernames five years ago AFAIK. Adding usernames for everyone was the hard, but necessary step they finally managed to do. Only now is it possible to make accounts that are discoverable AND aren't tethered to phone numbers. I'm assuming with passkeys/TOTP(?)
At this point, if it’s on a phone app, it probably doesn’t matter. They have your number.
No, apps (at least on Android) require a specific permission to read your phone number. The phone capabilities of Signal go through their own VoIP service, not your phone.
It's not entirely dystopian (just barely), we have newer messengers like SimpleX and DeltaChat (I/we use Delta) on the up and coming which deliver on all the same e2ee promises as Signal. It's just network effects as usual, getting people to try is the real hurdle.
What they share in common (mostly) is the architecture - they're built natively decentralized, utilizing caching relays with no single source of truth, or device of truth, to be used to create a profile of you like a phone number does. Encryption keys owned by the user and no single servers. Generally this is the Nostr design as well, so we have 3 different teams all focusing on the same natively decentralized architecture patterns.
Don't forget Briar!
Briar fits into it's own niche (operational design), making it a choice for certain activities but not what I would call your general normie chat app. It makes tradeoffs (using the local network, no caching relays, etc.) to increase security posture at the expense of general use. IIRC, Jack Dorsey's BitChat was modeled after the same designs? (which is interesting, because Nostr his other pet doesn't)
Simplex is a dog though compared to Signal.
I haven't tried SimpleX yet, as they can't share the same profile to multiple devices (it's explained in detail in the FAQ) which makes it a normie usability deal killer. I've heard it has really bad battery life on mobile too, but that's just reading random comments. Right now we're using Delta (and running a relay) and it's just fine.
Is any of these apps good for phone calls or video calls, or just text messages?
At this rate Canada would probably ban anything they can't get records from eventually if it got popular enough. I hate this timeline.
Bullllllllshit.
They've said that for years. It's easy to do. But they won't do it
How's it easy?
Not the technical part (which definitely looks as easy as just dropping a requirement), but the spam/abuse prevention part.
this is bullshit designed to respond to increasing use of simplexchat and other platforms
and they still want to tie it to payment (so a credit card) so they can track people
and they are implementing it only after many years
a complex captcha that takes 10 minutes to solve would work just as well as payment, but they aren't doing it, and it certainly leaves me wondering if they are a honeypot. i can't prove it, but it's really suspicious it's taken so long to possibly roll out something that may require a credit card
I have watched the futo video and i think don't think its very likely it will become a paid feature. The CTO said they would want to have the registration require some kind of cost but it was almost certainly meant as a computing cost not money.
Link to the same video in case you can't play it https://i.imgur.com/QMDjn7T.mp4
it was almost certainly meant as a computing cost not money
Agreed.
I think he makes a lot of sense. I mean, just look at Telegram (which is ironically going the opposite route now).
just go the matrix route; username, password, 2fa, then any other connection requires you to verify with a current logged in session (or recovery code).
Cannot decrypt message
As someone who uses matrix and runs a matrix server, matrix fucking suuuucks jfc why are so many privacy tools soooooo bad at what they do on so many levels like wtf the proto the servers the clients the ux the metadata issues like so much wrong
Edit: and if anyone tells me to use XMPP I'll slap them
What are your main issues with Matrix?
Unencrypted by default (among other bad defaults), leaks metadata like it was built to do so, makes it surprisingly difficult to tell what's encrypted and what's not, filled to the brim with bugs and exploits, bad feature interop between most clients (most of which have known vulnerabilities or abandoned dependencies), defacto-standard "just use synapse/element if you want things to work properly" (and still doesn't), bad user communication about well everything but mainly teaching new users what all the things mean (session, verification, 1:1 vs jitsi, when you're using what,...), ton of federation issues and bugs, ...
And despite all that it somehow has a massive csam seeding problem, which really just makes me think the whole thing is a telegram-like fed psyop but one level higher on the tech competency ladder.
... Multi-device session chaining is a neat feature and surprisingly user-friendly (tho no one maintains their session list or verification; half pebkac admittedly), so that's something nice I can say about it... But almost nothing else.
Seriously, Signal is basically a joint three-letter-agency sigint project and I still think it's safer and easier to use than matrix for the vast vast vast majority of people
I don't understand why an email registration is not an option? it was the default from when online services and apps appeared in the first place, and until about 5 years ago (depending on types of services/apps), and it's security and anonymity was purely based on you using your "main" address or a throwaway.
The article says their main reason is spam/abuse, as requiring a phone number adds some sort of gate to lessen that. Emails are easier to create en-masse. I don’t agree with using phone numbers either, I’m just relaying their reasons.
I would guess the sudden influx of massive amounts of traffic would force them to charge for the service, and they don't want to do that. Requiring a phone number, while invasive to some, does cut down on a tremendous amount of automated/bot/spam traffic.