leevlad | 4 years ago | on: Crypto.com accounts had unauthorized withdrawals
leevlad's comments
leevlad | 4 years ago | on: Improving first impressions on Signal
Yes, they do upload your contact list, but I believe there's a prompt at setup time that allows you to opt out? It might even be an OS-level prompt to the tune of "Signal would like to access your Contacts". Not 100% sure on that one as I haven't set up a brand new Signal installation in years.
It's done to help their user acquisition. It uploads your contacts to match against other contact lists and let you know who's on Signal. I recall seeing a blog post explaining how they are doing it in a fully encrypted way, possibly using Secure Enclave (? though I think the 2021 version of that would probably involve ZK proofs/homomorphic encryption of some kind, and I hope they put some time into that).
I don't recall ever having to set a PIN specifically for that. And besides, a 4-6 digit PIN would be a terribly insecure way to "encrypt" anything server-side :) But yes, that would be a shame if it were the case.
leevlad | 4 years ago | on: Improving first impressions on Signal
The PIN is a security option that prevents a SIM-swapping attacker from registering a new device under your phone number unless they know the PIN. You can opt out of it (and it might be opt-in to begin with). You can also easily opt out of PIN reminders. Both of these options are in Settings -> Account.
As for server state - my understanding is that Signal attempts to be zero-knowledge overall, but they definitely store some state on the server. I believe it's encrypted using your private key that's not backed up to the server. Setting the PIN does not change that.
Server state comment aside, it seems your main complaint is about a pop-up PIN entry UI that can be opted out of? I get that it might seem annoying, but it feels like a fairly weak criticism of a messaging platform, certainly not one that should warrant an impression that Signal is "on the way out"?
leevlad | 6 years ago | on: Firefox Multi-Account Containers
* Work/personal separation
* Multiple AWS accounts
Also, I am very impressed with how well they're integrated into Firefox. For example, opening a link in a new tab will preserve the container. CMD+Shift+T will restore a recently closed tab and remember its original container. I really like the color coding too.
leevlad | 6 years ago | on: Firefox Replay
leevlad | 6 years ago | on: 16-inch MacBook Pro
leevlad | 6 years ago | on: 16-inch MacBook Pro
leevlad | 6 years ago | on: Alphabet in bid to buy Fitbit
leevlad | 6 years ago | on: Firefox 70
leevlad | 6 years ago | on: NordVPN confirms it was hacked
leevlad | 6 years ago | on: iOS 13’s privacy pop-ups of Facebook data grabs
leevlad | 6 years ago | on: Firefox 69.0 Released
leevlad | 6 years ago | on: MITM on HTTPS traffic in Kazakhstan
leevlad | 6 years ago | on: Is Firefox better than Chrome? It comes down to privacy
leevlad | 6 years ago | on: Mazda is purging touchscreens from its vehicles
Mazda punches far above its price in terms of driving dynamics and interior quality, but I think their infotainment system is plain garbage and they should be absolutely ashamed of such poor quality.
leevlad | 6 years ago | on: Switch from Chrome to Firefox
leevlad | 7 years ago | on: AirPods with Wireless Charging Case
leevlad | 7 years ago | on: An update about Redis developments in 2019
leevlad | 7 years ago | on: Toyotas and Chevys Are Holding Up Better Than Most Luxury Brands
leevlad | 7 years ago | on: Open Source Messenger App for Android – Real-Time Messaging, Voice and Video