Introducing Automatic Key Verification

33 points by cinemast a day ago on lobsters | 13 comments

lake | a day ago

I'm not qualified to comment on the cryptography. But I remember seeing this appear in my Signal verification options a couple of weeks ago, and disregarding it because the help page said

Automatic Key Verification is available only when Signal has your contact’s phone number.

I am generally disappointed that Signal has been built around having a phone number as a hard requirement (I know this has been debated before, with pros and cons; the biggest of the latter is that it makes Signal much more susceptible to privacy breaches and censorship). I was hoping to see Signal move away from using them. This, however, now has them hang another feature off storing people's phone numbers. Even if it's very optional, I feel that's a step in the wrong direction.

Also, I was very curious to see who the "trusted auditors" were:

For Signal’s implementation of key transparency, Cloudflare and Trail of Bits serve as trusted third-party auditors

For reasons I cannot describe other than "bad vibes", I don't like that Cloudflare is one of them.

heavyrain266 | a day ago

I don't like that Cloudflare is one of them.

Same, for whatever reason Cloudflare turned from the “frontier of the internet” into “crypto bro”. How am I supposed to trust them as a DNS, firewall and anything else related to security, while their latest product is a questionable “Agentic AI Wallet” that gives agents access to stablecoin cryptocurrency payments…

That's part of the "bad vibes" (the other big one for me is just how much of our digital infrastructure is now centralised on them).

To be fair, Signal has also played with cryptocurrency, albeit (thankfully?) without much commitment. But buried in the app settings you can still find a section for Payments, which will offer to sign you up for a coin no one has ever heard of.

heavyrain266 | 9 hours ago

Signal’s MobileCoin was indeed concerning, closely related to Signal’s co-founder (Moxie Marlinspike) who was involved in its development. It was “privacy-preserving” or whatever. A bit different case beccause Signal is managed by the non-profit organisation that shouldn’t be involved in vague finances related crap like crypto.

gnafuthegreat | 22 hours ago

Centralization and requiring a phone number and mobile app are definitely the reasons Signal has never been an option for me.

abeyer | 19 hours ago

I think those are perhaps secondary effects of them simply being so single-mindedly focused on a very specific security/threat model. The design and use of the system are molded to fit that model... which perhaps you could argue is the "right" way to do that security. But I agree that the result isn't something I've felt a desire to use, even so.

gnafuthegreat | 19 hours ago

Signal makes sense to me as a messenger for a narrow purpose (that I don't need), but it doesn't make sense to me as the general purpose messenger it has ended up being for so many people. Some folks seem to want it to be a WhatsApp alternative, but it's a step in the wrong direction for folks like me who want a WhatsApp alternative that specifically doesn't require a mobile number or centralized walled garden.

nicoco | 5 hours ago

Even if they were focused on other "security/threat models", it still wouldn't be something I'm excited about. A cool blog post I read here had this brilliant quote:

Do things out of love, not out of fear

Signal absolutely fails having any "love" attached to it. It has a top-down governance, it is centralized, it is not hacker-friendly, it requires a mainstream mobile OS, it asks for donations while having top execs on ridiculous payrolls [...]. In computing just like in other parts of life, focusing on security and nothing else is taking part in building a sad, sad world.

This really speaks to me. I appreciate Signal as a strictly more secure text message replacement, or as a kind of iMessage that you can run on more than just Apple devices. It's definitely less icky than WhatsApp. But you're right, there is very little fun or joy in Signal, and it does feel very paternalistic in how it presents security (which is ironic given that Moxie was an outspoken anarchist).

They're not in the same category, but I think about how different it feels to use Matrix. It's kind of a mess, but it's decentralised, very hacker friendly by necessity, and has a very enthusiastic community of people who do pour a lot of love into it, and create a lot of joy in it. And it does have e2ee (unlike e.g. Discord or Slack).

Signal feels very "cold" to use by comparison. I'm glad it exists for situations where my alternatives are SMS/RCS or WhatsApp. But I agree it does not inspire excitement, and contributes to the idea of open computing as scary and hostile.

danlamanna | 23 hours ago

I am generally disappointed that Signal has been built around having a phone number as a hard requirement

There has been some news around this.

Signal CTO Ehren Kret said responding to a question at FUTO's Don't Be Evil conference:

"that is something we are looking a hopefully for later on this year adding a way to sign up without phone numbers. Uh the main uh downside at the moment and the reason we don't have that yet today is removing accounts who are are spamming people or otherwise engaging in abuse of the service is sort of our our primary way of protecting people from spam and other sort of issues like that that would affect the operational stability of the service."

About Signal spotted several commits on Signal's GitHub with commit messages that reference accounts with no phone numbers, such as "Don’t allow or set registration lock on accounts with no phone number," heavily suggesting that Signal is actively working on a feature allowing you to sign up without a phone number.

More references in Signal's source code suggest this feature will be called "Signal Login" and will indeed be a paid feature.

Since payment info can be just as identifying as a phone number, its unclear how Signal plans to protect the privacy of users' payment info.

Hm. I got briefly hopeful this is finally happening. Especially since for me the censorship part is not hypothetical -- it's extremely hard to get Signal's sign-up SMS in e.g. Russia (and elsewhere), especially if the person registering is not tech-savvy. I have some contacts that have been unable to sign up for Signal as a result.

But if it's paid, that would pretty much negate the improvements. I get that Signal is worried about spam, but in places where you can't get Signal's texts, you'll probably have a hard time paying them, too, even if you want to (and yes, you're once again subjected to KYC to use a service that claims to prioritise privacy). Let's see what it looks like if/when it comes out.

Sanity | 4 hours ago

I really hope they have a solid defense against spam before they allow phone-number-less signups.

Sanity | 4 hours ago

I don't quite see what problem this is meant to solve. Is it just to ensure that the Signal contact you added previously with phone number 636-555-3226 still has phone number 636-555-3226?

Comment removed by author