this post was submitted on 30 Jul 2026
183 points (100.0% liked)

Privacy

4962 readers
97 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] scytale@piefed.zip 45 points 4 days ago

GitHub commit d7447b1 states that “accounts without phone numbers can never get phone numbers, and accounts with them can never lose them”.

So you’ll have to register a new account if you want to decouple your number.

[–] Zachariah@lemmy.world 39 points 4 days ago (2 children)

didn’t they announce this like five years ago

[–] TobuscusLover2001@lemmy.zip 5 points 3 days ago

I mean, they also were developing usernames five years ago AFAIK. Adding usernames for everyone was the hard, but necessary step they finally managed to do. Only now is it possible to make accounts that are discoverable AND aren't tethered to phone numbers. I'm assuming with passkeys/TOTP(?)

[–] Zephorah@discuss.online 8 points 4 days ago (2 children)

At this point, if it’s on a phone app, it probably doesn’t matter. They have your number.

[–] asdfasdfasdf@lemmy.world 6 points 3 days ago* (last edited 3 days ago)

No, apps (at least on Android) require a specific permission to read your phone number. The phone capabilities of Signal go through their own VoIP service, not your phone.

[–] mote@lemmy.ca 15 points 4 days ago (3 children)

It's not entirely dystopian (just barely), we have newer messengers like SimpleX and DeltaChat (I/we use Delta) on the up and coming which deliver on all the same e2ee promises as Signal. It's just network effects as usual, getting people to try is the real hurdle.

What they share in common (mostly) is the architecture - they're built natively decentralized, utilizing caching relays with no single source of truth, or device of truth, to be used to create a profile of you like a phone number does. Encryption keys owned by the user and no single servers. Generally this is the Nostr design as well, so we have 3 different teams all focusing on the same natively decentralized architecture patterns.

[–] 52fighters@sopuli.xyz 2 points 2 days ago (1 children)
[–] mote@lemmy.ca 2 points 2 days ago

Briar fits into it's own niche (operational design), making it a choice for certain activities but not what I would call your general normie chat app. It makes tradeoffs (using the local network, no caching relays, etc.) to increase security posture at the expense of general use. IIRC, Jack Dorsey's BitChat was modeled after the same designs? (which is interesting, because Nostr his other pet doesn't)

[–] hanrahan@slrpnk.net 1 points 2 days ago (1 children)

Simplex is a dog though compared to Signal.

[–] mote@lemmy.ca 3 points 2 days ago

I haven't tried SimpleX yet, as they can't share the same profile to multiple devices (it's explained in detail in the FAQ) which makes it a normie usability deal killer. I've heard it has really bad battery life on mobile too, but that's just reading random comments. Right now we're using Delta (and running a relay) and it's just fine.

[–] vanillama@programming.dev 8 points 4 days ago (11 children)

Is any of these apps good for phone calls or video calls, or just text messages?

[–] BurgerBaron@quokk.au 6 points 4 days ago* (last edited 4 days ago) (3 children)

At this rate Canada would probably ban anything they can't get records from eventually if it got popular enough. I hate this timeline.

load more comments (3 replies)
load more comments (10 replies)
[–] quick_snail@feddit.nl 12 points 4 days ago (3 children)

Bullllllllshit.

They've said that for years. It's easy to do. But they won't do it

[–] XLE@piefed.social 11 points 3 days ago (5 children)

How's it easy?

Not the technical part (which definitely looks as easy as just dropping a requirement), but the spam/abuse prevention part.

load more comments (5 replies)
load more comments (2 replies)
[–] someone@lemmy.today 1 points 2 days ago (1 children)

this is bullshit designed to respond to increasing use of simplexchat and other platforms

and they still want to tie it to payment (so a credit card) so they can track people

and they are implementing it only after many years

a complex captcha that takes 10 minutes to solve would work just as well as payment, but they aren't doing it, and it certainly leaves me wondering if they are a honeypot. i can't prove it, but it's really suspicious it's taken so long to possibly roll out something that may require a credit card

[–] Eggman@thelemmy.club 2 points 2 days ago* (last edited 2 days ago) (1 children)

I have watched the futo video and i think don't think its very likely it will become a paid feature. The CTO said they would want to have the registration require some kind of cost but it was almost certainly meant as a computing cost not money. Link to the same video in case you can't play it https://i.imgur.com/QMDjn7T.mp4

[–] A_norny_mousse@piefed.zip 1 points 6 hours ago

it was almost certainly meant as a computing cost not money

Agreed.

I think he makes a lot of sense. I mean, just look at Telegram (which is ironically going the opposite route now).

[–] cupcakezealot@piefed.blahaj.zone 9 points 4 days ago* (last edited 4 days ago) (2 children)

just go the matrix route; username, password, 2fa, then any other connection requires you to verify with a current logged in session (or recovery code).

[–] quick_snail@feddit.nl 17 points 4 days ago

Cannot decrypt message

[–] ImgurRefugee114@reddthat.com 14 points 4 days ago* (last edited 4 days ago) (1 children)

As someone who uses matrix and runs a matrix server, matrix fucking suuuucks jfc why are so many privacy tools soooooo bad at what they do on so many levels like wtf the proto the servers the clients the ux the metadata issues like so much wrong

Edit: and if anyone tells me to use XMPP I'll slap them

[–] modem_down@thebrainbin.org 3 points 9 hours ago (1 children)

What are your main issues with Matrix?

[–] ImgurRefugee114@reddthat.com 1 points 5 hours ago* (last edited 5 hours ago)

Unencrypted by default (among other bad defaults), leaks metadata like it was built to do so, makes it surprisingly difficult to tell what's encrypted and what's not, filled to the brim with bugs and exploits, bad feature interop between most clients (most of which have known vulnerabilities or abandoned dependencies), defacto-standard "just use synapse/element if you want things to work properly" (and still doesn't), bad user communication about well everything but mainly teaching new users what all the things mean (session, verification, 1:1 vs jitsi, when you're using what,...), ton of federation issues and bugs, ...

And despite all that it somehow has a massive csam seeding problem, which really just makes me think the whole thing is a telegram-like fed psyop but one level higher on the tech competency ladder.

... Multi-device session chaining is a neat feature and surprisingly user-friendly (tho no one maintains their session list or verification; half pebkac admittedly), so that's something nice I can say about it... But almost nothing else.

Seriously, Signal is basically a joint three-letter-agency sigint project and I still think it's safer and easier to use than matrix for the vast vast vast majority of people

[–] toofpic@lemmy.world 7 points 4 days ago (7 children)

I don't understand why an email registration is not an option? it was the default from when online services and apps appeared in the first place, and until about 5 years ago (depending on types of services/apps), and it's security and anonymity was purely based on you using your "main" address or a throwaway.

[–] scytale@piefed.zip 15 points 4 days ago (1 children)

The article says their main reason is spam/abuse, as requiring a phone number adds some sort of gate to lessen that. Emails are easier to create en-masse. I don’t agree with using phone numbers either, I’m just relaying their reasons.

load more comments (1 replies)
[–] refalo@programming.dev 11 points 4 days ago

I would guess the sudden influx of massive amounts of traffic would force them to charge for the service, and they don't want to do that. Requiring a phone number, while invasive to some, does cut down on a tremendous amount of automated/bot/spam traffic.

load more comments (5 replies)
load more comments
view more: next ›