• someone@lemmy.today
    link
    fedilink
    arrow-up
    3
    arrow-down
    5
    ·
    15 hours ago

    this is bullshit designed to respond to increasing use of simplexchat and other platforms

    and they still want to tie it to payment (so a credit card) so they can track people

    and they are implementing it only after many years

    a complex captcha that takes 10 minutes to solve would work just as well as payment, but they aren’t doing it, and it certainly leaves me wondering if they are a honeypot. i can’t prove it, but it’s really suspicious it’s taken so long to possibly roll out something that may require a credit card

    • Eggman@thelemmy.club
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      13 hours ago

      I have watched the futo video and i think don’t think its very likely it will become a paid feature. The CTO said they would want to have the registration require some kind of cost but it was almost certainly meant as a computing cost not money. Link to the same video in case you can’t play it https://i.imgur.com/QMDjn7T.mp4

  • scytale@piefed.zip
    link
    fedilink
    English
    arrow-up
    35
    ·
    2 days ago

    GitHub commit d7447b1 states that “accounts without phone numbers can never get phone numbers, and accounts with them can never lose them”.

    So you’ll have to register a new account if you want to decouple your number.

    • TobuscusLover2001@lemmy.zip
      link
      fedilink
      arrow-up
      3
      ·
      2 days ago

      I mean, they also were developing usernames five years ago AFAIK. Adding usernames for everyone was the hard, but necessary step they finally managed to do. Only now is it possible to make accounts that are discoverable AND aren’t tethered to phone numbers. I’m assuming with passkeys/TOTP(?)

      • asdfasdfasdf@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        1 day ago

        No, apps (at least on Android) require a specific permission to read your phone number. The phone capabilities of Signal go through their own VoIP service, not your phone.

      • mote@lemmy.ca
        link
        fedilink
        arrow-up
        14
        ·
        2 days ago

        It’s not entirely dystopian (just barely), we have newer messengers like SimpleX and DeltaChat (I/we use Delta) on the up and coming which deliver on all the same e2ee promises as Signal. It’s just network effects as usual, getting people to try is the real hurdle.

        What they share in common (mostly) is the architecture - they’re built natively decentralized, utilizing caching relays with no single source of truth, or device of truth, to be used to create a profile of you like a phone number does. Encryption keys owned by the user and no single servers. Generally this is the Nostr design as well, so we have 3 different teams all focusing on the same natively decentralized architecture patterns.

  • quick_snail@feddit.nl
    link
    fedilink
    arrow-up
    13
    arrow-down
    4
    ·
    2 days ago

    Bullllllllshit.

    They’ve said that for years. It’s easy to do. But they won’t do it

    • XLE@piefed.social
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      2 days ago

      How’s it easy?

      Not the technical part (which definitely looks as easy as just dropping a requirement), but the spam/abuse prevention part.

      • quick_snail@feddit.nl
        link
        fedilink
        arrow-up
        2
        arrow-down
        5
        ·
        2 days ago

        It’s pretty easy to detect spam. I guess user reports and noticing when someone suddenly messages many new users and those users do not respond.

        Anyway, it’s not an issue on Wire or SimpleX or the dozens of other platforms that don’t require phone numbers. It’s obviously a solved problem. Signal is just making up fake excuses.

        • Sina@beehaw.org
          link
          fedilink
          arrow-up
          1
          ·
          9 hours ago

          It’s pretty easy to detect spam. I guess user reports and noticing when someone suddenly messages many new users and those users do not respond.

          It’s not so easy, because you could even register a new account for each new spam message, or register 100k accounts & only send out 3 messages a day / account…

        • far_university1990@reddthat.com
          link
          fedilink
          arrow-up
          8
          ·
          1 day ago

          It’s pretty easy to detect spam.

          Tell that to… any social media. Lol. If was easy to detect bot you think they not big problem anymore.

  • onlinepersona@programming.dev
    link
    fedilink
    arrow-up
    13
    arrow-down
    9
    ·
    2 days ago

    Boy… We are going to get spammed.

    I never understood the “phone numbers are evil” people, whining about signal requiring them. As soon as this arrives, they will find another thing to whine about.

    Hopefully Signal will make it possible to block any and all communications from people wohtout a phone number, unless I reach out to them. And that that feature also be introduced to groups. Because otherwise maintaining public groups is going to be turboshit.

    • GreenKnight23@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      simplex doesn’t require phone numbers or emails to sign up.

      instead you need to scan codes for a trust. it’s actually everything I wanted in a messenger. well…I wish they had gifs like telegram.

    • GottaHaveFaith@fedia.io
      link
      fedilink
      arrow-up
      13
      arrow-down
      1
      ·
      2 days ago

      mobile numbers require government identification in many countries. But yeah, not seeing an easy solution to the spam problem

      • onlinepersona@programming.dev
        link
        fedilink
        arrow-up
        4
        arrow-down
        2
        ·
        edit-2
        1 day ago

        mobile numbers require government identification in many countries

        Yes and all they will know is “person A has installed signal”. Nothing more. If you haven’t degoogled tour phone or use one with a fruity logo, the government knows that you have the app already. It won’t need phone number.

        • leds@feddit.dk
          link
          fedilink
          arrow-up
          2
          ·
          9 hours ago

          Remember metadata , they also know person A send message to person B at specific time. Of course knowing phone number also gives them your location from cellular towers.

  • katy ✨@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    5
    ·
    2 days ago

    just go the matrix route; username, password, 2fa, then any other connection requires you to verify with a current logged in session (or recovery code).

    • ImgurRefugee114@reddthat.com
      link
      fedilink
      arrow-up
      13
      arrow-down
      1
      ·
      2 days ago

      As someone who uses matrix and runs a matrix server, matrix fucking suuuucks jfc why are so many privacy tools soooooo bad at what they do on so many levels like wtf the proto the servers the clients the ux the metadata issues like so much wrong

      Edit: and if anyone tells me to use XMPP I’ll slap them

  • toofpic@lemmy.world
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    2 days ago

    I don’t understand why an email registration is not an option? it was the default from when online services and apps appeared in the first place, and until about 5 years ago (depending on types of services/apps), and it’s security and anonymity was purely based on you using your “main” address or a throwaway.

    • scytale@piefed.zip
      link
      fedilink
      English
      arrow-up
      11
      ·
      2 days ago

      The article says their main reason is spam/abuse, as requiring a phone number adds some sort of gate to lessen that. Emails are easier to create en-masse. I don’t agree with using phone numbers either, I’m just relaying their reasons.

      • quick_snail@feddit.nl
        link
        fedilink
        arrow-up
        3
        arrow-down
        9
        ·
        edit-2
        1 day ago

        Yep, that’s the bullshit they always say. Fortunately it’s easy to see through this PR shite

    • refalo@programming.dev
      link
      fedilink
      arrow-up
      10
      ·
      2 days ago

      I would guess the sudden influx of massive amounts of traffic would force them to charge for the service, and they don’t want to do that. Requiring a phone number, while invasive to some, does cut down on a tremendous amount of automated/bot/spam traffic.

        • quick_snail@feddit.nl
          link
          fedilink
          arrow-up
          2
          ·
          23 hours ago

          Yeah, their history of claiming they’ll do this, but never do. All their decisions to require a phone number or some other identity link

        • quick_snail@feddit.nl
          link
          fedilink
          arrow-up
          3
          arrow-down
          4
          ·
          2 days ago

          And I’m telling you, it won’t happen. They will probably require some other UUID.

          Signal had made it clear that they need to identify their user’s identities.

          Mark my words: if you try to create an account on TAILS, and your fingerprint isn’t unique, you’ll get an error when you try to create the account.

      • 𝕸𝖔𝖘𝖘@infosec.pub
        link
        fedilink
        arrow-up
        1
        ·
        2 days ago

        When you send a message, and it gets delivered when the recipient is online?
        Delta has that, but you have to be online for the message to be sent later, since there’s no central server to cache it.

        • quick_snail@feddit.nl
          link
          fedilink
          arrow-up
          2
          ·
          2 days ago

          Yes, that means it’s synchronous.

          My point is that we need servers for asynchronous messaging (or some clever network where everyone is a server relaying messages for others). Lacking asynchronous messaging is not going to be a practical solution for 99% of people.

          Encryption works. We don’t need to trust servers. They’re not inherently an issue for security nor anonymity.

          • 𝕸𝖔𝖘𝖘@infosec.pub
            link
            fedilink
            arrow-up
            4
            ·
            16 hours ago

            Thank you for the clarification. I just wasn’t sure on the terminology, but this makes perfect sense.

            We don’t need to trust servers. They’re not inherently an issue for security nor anonymity.

            For me, my issue with a central server infrastructure is less that it can be snooped on (because, to your point, properly implemented encryption does work) and more that it’s easy to be taken down or censored, since it is a central server infrastructure.
            The benefit with the every-client-is-a-server infrastructure, such as the one that Delta uses, is that if one of the many servers gets taken down, the network, as a whole, keeps working.
            Something similar can be said about the Lemmy infrastructure, really any of the Fediverse. If one of the servers gets taken down, there are still hundreds, thousands, or millions more that are serving content, even if not the exact same content, allowing the social network, as a whole, to not be subject to mass censorship.

            For the everyday, central infrastructure, such as the one that Signal uses, works perfectly fine. For those “special locations”, a decentralized every-client-is-a-server infrastructure might be a requirement. So it really is situational.

            • quick_snail@feddit.nl
              link
              fedilink
              arrow-up
              4
              ·
              13 hours ago

              That’s a good point.

              I guess the best is a hybrid where the server is just optional for asynchronous messaging, and if the server is temporarily down, the service just becomes temporarily degraded into synchronous mode.