Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not sure that this is a benefit. It gives users a false sense of security. Screenshots or pictures can always be taken on the other end.

Didn't signal used to be explicitly against this feature.



"Disappearing messages are a way for you and your friends to keep your message history tidy. They are a collaborative feature for conversations where all participants want to automate minimalist data hygiene, not for situations where your contact is your adversary — after all, if someone who receives a disappearing message really wants a record of it, they can always use another camera to take a photo of the screen before the message disappears."


This should be strictly a recipient controlled option, only affecting the recipient's view then. Anything else is still a misleading UX for the sender, and assumes people read the fine print. They don't.


This is horrible logic and ignores important opt-in/opt-out dynamics which are critical to our conception of privacy. By enabling "self-destruct," (or "disappear") the sender merely forces the recipient to "opt-in" and take affirmative action in order to archive the message (i.e. Screenshot). This is how telephone conversations generally work -- no recording unless one party takes action to tape it. Despite this ability to tape, we certainly still consider telephone to be more "secure" due to this archival distinction. Very often it is the advice of lawyers to avoid putting something in writing, and communicate it in person or over the phone instead. Disappearing messages brings us closer to this desirable ephermerality.


If you want a recipient controlled option that already exists as you can set the number of messages you want to save before old ones are deleted.

Not deleting the messages from the senders view just to teach users a lesson about security doesn't make any sense and would just confuse people. Showing a warning about it still being possible to take a picture of the phone with another camera would make more sense but seems a bit silly.


It's very simple. In the same feature as pruning old messages by count, add by time. Allow this on a per-conversation level. Done.


If their sense is that -- after configuring 1 week self destruct, the people they're talking to likely won't be keeping months and months of chat logs on their phone anymore -- it's a very true sense of security.


At least until the Jailbreak tweak is released with patches out this feature, allowing people to retain everything they want.

I don't disagree that it works for the average user, but I do agree with the sentiment that it is a false sense of security.

Unless maybe you cryptographically verify the deletion (is that possible?) and notify the other party of the successful deletion. But even then a copy could be made beforehand, on-device or with an external camera...

I think it's much better to maintain zero expectation of message destruction with all end users.


There's no need to jailbreak anything. The code for the client is open source; you merely have to remove the code that obeys the remote request to delete, and rebuild and reinstall.


Yeah: I kind of want to release such a hack just to make the point (even though I do not use this program nor do I know anyone else who does). This is simply lying to users :/.


[deleted]


What good is a seatbelt if the person sitting next to you can stab you? The blog post makes a point of this not being secure if the person you're messaging is malicious and that's not what it's for.

I think these two comments make good points:

I just had an interesting conversation with a friend who was recommending that I use Telegram/Wickr, and I told him that Signal was where it's at. Then he asked me if it had self-destructing messages, and I said "Why bother? That can be easily circumvented". His reply was that in some countries phones had been confiscated, and even though one person had enabled local encryption, the user with the confiscated phone had not enabled it; thereby implicating everyone who had communicated with that person (even though the messages were delivered secure over the network). So while self-destructing messages are in many ways a flawed guarantee of privacy, they can perform a very useful function in cases where the users are not malicious, but rather are security ignorant (i.e. most people with a phone).

https://whispersystems.discoursehosting.net/t/automatically-...

I've always been thinking that the critique of such a feature is based on a false underlying premise.

Yes, it's true that the recipient can make a screenshot of the message. But the recipient in the absolute majority of cases is not a "threat" in a classical sense, not someone with bad intentions or someone who is not supposed to know the contents of that message. After all, the sender trusts the recipient, as he is the one sending the message to the recipient in the first place.

The usual scenario is a recipient who is not that security-aware and doesn't think about those things that much if at all. Personally, I'd say most of my contact are that way.

The sender might send this recipient a message containing something especially critical, say, a user name and a corresponding password, and doesn't want to see that information in the wrong hands if e. g. later on, the recipient loses their phone, the phone gets stolen, etc. Also note that this kind of recipient is unlikely to use a general passphrase for Signal as this lessens convenience.

So what's essentially happening here is a security-minded sender taking security measures for or in place of a thrustworthy, albeit forgetful, non-security-minded, etc recipient.

https://whispersystems.discoursehosting.net/t/automatically-...


Yes, this is a very insightful comment, and I think it should have been mentioned in the blog post. Many people don't use security passwords on their phones, and people can also be coerced into providing that information. Providing the option for automatically expired messages is a nice redundancy measure.

Great job on the app! It's one of the few apps I use every day.


[deleted]


Yes, if everyone switches to a fork that doesn't have a particular feature, then they won't have that particular feature.


> The usual scenario is a recipient who is not that security-aware and doesn't think about those things that much if at all. Personally, I'd say most of my contact are that way.

Relying on this user to not have disabled your self-destructing messages seems like a really dumb move.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: