Elektrine lite

← Feed

@bazkie@beige.party

Post #4326701

2026-08-02 09:20 UTC

@david_chisnall@infosec.exchange I mean I could, but I suppose that means I need to go do that again in a few months time, no? like find some phone again, put my GSM SIM card in there, enter PIN, relink to desktop.. I just don't understand why they do this also I'm reading that the PIN system is kinda new? so my account probably doesn't have one. my desktop signal never mentioned it, as far as I can remember.

Replies (1)

  • @bazkie@beige.party The model in Signal is that the authoritative device is the phone (partly because most chat users are phone-only or phone-first, partly because mobile operating systems include a load of security features that are missing or weaker on desktop operating systems). This is the device that is responsible for distributing paired devices to the rest of the other secondary devices and managing their access (you can revoke access by any desktop client from the phone). Keys roll over periodically, if you don’t have the device that handles the key distribution connected periodically then the other devices will lose access. If you have a phone that can receive SMS and a desktop, I’ve read that you can install the phone app in the emulator that comes with Android Studio and use that. As long as you turn it on every couple of weeks, you should remain connected. EDIT: To be clear, I don’t like this model. Signal was originally created as a WhatsApp alternative, funded by one of the original creators of WhatsApp, who walked away after seeing what Facebook did to WhatsApp. WhatsApp grew to a billion users rapidly by being a drop-in replacement for SMS on the phone that was free to use with people in different countries. It used phone numbers because most people already had their contacts phone numbers in their contacts to use with SMS, so switching was zero friction. Apple’s iMessage followed the same model. But this means that the phone is a single point of failure. It’s not the worse single point of failure because recovery requires the SIM and the ability to unlock the phone. Most providers make it possible to get a replacement SIM sent to the registered address of the account, so having the phone and SIM die is a recoverable failure mode in typical cases (whereas email recovery, when most people use free email provided by companies that can and do terminate free accounts without reason, is much more fragile). I would rather they built a consensus-based recovery flow, where users can configure which set of devices may be used for recovery and can nominate contacts that each get a secret share where a configurable subset of them can authorise account recovery after a period of inactivity.

    Open ##4326700