Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It may very well be the case for the smartphone-flipping demographic that prefer WhatsApp and TikTok, but I think it's a misunderstanding/misrepresentation of the crowd that go for e.g. Signal and Telegram.


Large swaths of my non-tech social group are on Signal because it offers a large amount of practical security and privacy without the kinds of sacrifices people seem to assume signal users want to take. Signal has successfully and dramatically increased the number of people enjoying privacy in their communications by not making that assumption.


The majority of my signal contacts aren't particularly tech-literate. The crowd that go for signal and the crowd that go for telegram are different crowds, in a large part because signal designed itself to be accessible to nonexperts.


So they are tech-literate enough to use a smartphone, and apps for it, and they are tech-literate enough to type in their Signal password reminder in a hidden text field (and probably also passwords on dozens of web pages because password/keychain apps are "hard") but typing in e.g. an anonymized "user token" to add a buddy would be too "tech" for them? I refuse to believe a word of what you're saying.


> anonymized "user token" to add a buddy would be too "tech" for them? I refuse to believe a word of what you're saying.

How do you transmit said anonymous user token securely? Using the secure messaging app you're already using? Meeting up in real life? Posting it on keybase? Each of these has downsides that are all solved by a phone number.


I don't see why the user token ("account name") has to be secret in every conceivable way. It just needs to be anonymous. What's wrong with meeting in real life, or exchanging account names in whatever way you initially exchanged phone numbers? You don't seem concerned over the security problem of account activation codes being sent over SMS, so I don't see why you should be concerned over exchanging anonymous account names in the same or more secure ways.


> What's wrong with meeting in real life

I regularly DM people I haven't seen in person in years. I'm not going to fly cross-country to bootstrap a communication channel.

> or exchanging account names in whatever way you initially exchanged phone numbers?

Well because I exchanged phone numbers irl 7 years ago. I do not have a time machine.

> You don't seem concerned over the security problem of account activation codes being sent over SMS, so I don't see why you should be concerned over exchanging anonymous account names in the same or more secure ways.

Correct, because the bit of information "I have a signal account" is far less revealing than the bit of information "I have shared my signal account with a particular individual".

You avoid that only with some kind of public attestation of your signal identity (in keybase or on twitter or whatever) which is the best option, but generally requires everyone have a known public index of their forms of contact, which my friends from high school, generally speaking, don't.


Signals very explicit goal is making something that's usable for everybody. If they'd wanted to make a nerd-messenger they'd make a different product.

(I still consider it a major downside that the phone number is the only lookup key)


Sounds pretty drastic to me to draw the line between "everybody" and "nerds" at the point of the contact book being available or not.


Feel free to insert your word choice of "smartphone-flipping demographic" instead. The point is that if you argue based on "the crowd that goes for signal", that crowd being everyone is the clear aim of Signal, and thus they design around that goal.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: