Conversation

I've been a user and supporter of Signal for years. I've disagreed with various design decisions, but there has always been sensible reasoning behind their decisions based on facts and logic. I only used to disagree on certain priorities and had faith in them. No longer the case.
7
68
Replying to
I'm well aware of that. It doesn't address anything that I've talked about. My thread was posted with the full awareness that they are making PINs optional. I suggest reading twitter.com/DanielMicay/st, my other earlier posts and this thread.
Quote Tweet
Replying to @chrisrohlf @signalapp and @moxie
Hopefully as a toggle so that it's still possible to have a registration lock PIN without contact syncing, as it was before this was introduced. Most people are going to use the defaults so that's what really matters, and a user-generated PIN + SGX is not a secure approach.
1
3
Replying to
This feature was previously only a registration lock PIN. It should be possible to set a registration lock PIN as before without it enabling remote backup / sync with it used to derive an encryption key. It also matters that users are encouraged to use a weak PIN for remote sync.
1
2
Replying to
Use the option to set a strong alphanumeric passphrase and store it in a password manager with end-to-end encryption so you don't lose it. You CAN use a strong passphrase so that this uses strong encryption. It's also only syncing contacts, profile, etc. at the moment.
1
3
Show replies