Conversation

This Tweet was deleted by the Tweet author. Learn more
Replying to and
Hopefully as a toggle so that it's still possible to have a registration lock PIN without contact syncing, as it was before this was introduced. Most people are going to use the defaults so that's what really matters, and a user-generated PIN + SGX is not a secure approach.
1
6
twitter.com/DanielMicay/st By the way, blocked me for this tweet. I think that says a lot. As I feared, the toggle is for the PIN feature as a whole. It also doesn't address that they're still going to be encouraging using a weak PIN for a remote backup/sync feature.
Quote Tweet
Replying to @chrisrohlf @signalapp and @moxie
Hopefully as a toggle so that it's still possible to have a registration lock PIN without contact syncing, as it was before this was introduced. Most people are going to use the defaults so that's what really matters, and a user-generated PIN + SGX is not a secure approach.
1
3
At least on Android, Signal already had an encrypted backup feature using a strong key generated by the app rather than the user. This could be made more usable via a seed phrase as others have suggested rather than providing it as numbers. Not even an option for the new feature.
1
3
It's also confusing to have multiple backup implementations. The existing backup implementation covers all the data stored by the app with strong encryption. Also, seems like a valid complaint that the registration lock PIN feature got gobbled up into a feature that does sync.
1
1
It's a major usability issue with the app and remains one. People switch phones and lose message archives they want to keep along with their safety numbers changing. The existing backup implementation covers all that. It could be substantially easier to use and more flexible.
2