Top
Best
New

Posted by keyboardJones 5 days ago

Signal Secure Backups(signal.org)
983 points | 440 commentspage 7
mtzaldo 5 days ago|
I would like to have the option to have chats without encrypting the media. It will nice to backup the media directly to a NAS.
autoexec 5 days ago||
I'm glad that this is opt-in (at least for now).

I wish they'd done that for all the other data they collect and permanently store in the cloud (name, photo, phone number, signal contacts, etc.) since you can't even opt-out of that data collection.

I wonder if now signal will finally update their privacy policy which still opens with the outright lie: "Signal is designed to never collect or store any sensitive information."

max_ 4 days ago||
Signal has over $50m in endowments.

But their desktop app is built with electron.

It's extremely clunky (over 200 MB) very slow and probably inherits all electron's security issues.

I have noticed the same issue with desktop apps from Proton Mail.

Why is it that rich corporations with lots of money like shortcuts and don't care about the quality of thier software?

nout 5 days ago||
What is the UX for the 64 characters key? Does it at least use a wordlist (e.g. like BIP 39)?
fastest963 4 days ago|
Just 64 characters but they do integrate with a password manager and have a 1-click button to add it. The integration was pretty seamless and saved it in 1Password.
john01dav 5 days ago||
They need to add some free way to backup to my own server. I have my own raid array with backups sitting in my basement. I'll back up to that. I do not want to pay them for cloud storage.

Right now, theoretically, I can do this by backing up to my phone and then copying the file over. But, this has many issues. Firstly, it is manual, so it will happen way less. Secondly, it is not differential, so the storage requirements will explode. Thirdly, if my signal message archive is bigger than the free space on my phone (especially if it takes more than 50% of total space) then I'm just fucked — there's no way to back it up anywhere else. Fourthly, the backup system is EXTREMELY buggy, to the point that it takes me HOURS babysitting it every time I make a backup.

A good solution would be let me put FTP/FTPS/SFTP/SCP/WebDav/SMB/etc. credentials in the Signal app and have it do periodic differential backups to there. Let me decide if I want it to be encrypted or not based on my threat model. Tell my contacts if this is enabled and let me exclude and/or encrypt specific chats if you want to let other people apply their security model too.

Only supporting any reasonable (meaning automatic and convenient) backup system with their paid cloud and not supporting my own server smells like a money grab to me. This is utterly unacceptable in a supposedly non-profit app. I have no problem with their paid cloud being an option, to be clear.

Another problem with Signal is that they only provide an official Linux package for Debian-based distributions. This forces people using other distributions to either do repeated manual effort to pull it out of their .deb files or build it themself (which is made way harder than it should be), or rely on sketchy third parties for packags. Given how much privatea information goes over Signal, such third party packages are an extremely tempting target for anyone from criminals to national spy agencies. This lapse in security due to not packaging for any Linux except Debian-based Linux (or even providing an ideally auto-updating portable binary!) is a much larger security lapse than letting me backup to my own server conveniently. So, their cries of security concerns relating to backups ring hollow.

Overall, it's quite a shitty app. I only use it because the alternatives are worse.

Tepix 4 days ago|
I agree.

> Right now, theoretically, I can do this by backing up to my phone

You don't have this option on iOS right now.

Ericson2314 5 days ago||
That's great they are doing a paid feature, but I really just want my desktop to back up my phone.

They clearly think people have bad desktop security, and still don't want this to happen. Patronizing...

Edit on

> Our future plans include letting you save a secure backup archive to the location of your choosing, alongside features that let you transfer your encrypted message history between Android, iOS, and Desktop devices.

That's good, but they've said that before. I feel a bit burnt on this.

jdthedisciple 5 days ago||
perhaps said too much on a whim, but why should I backup my Signal... or WhatsApp, or any other communications. live in the moment. let things pass. there is probably no fortune hidden in it anyway...
Sanzig 5 days ago||
IIRC, that used to be the opinion of the Signal project as well, but backups are such a requested feature it looks like they've finally decided to offer it.
JoshTriplett 4 days ago|||
If you don't want to back it up, don't back it up.

I'd like to replace all my SMS usage with Signal. I have every text message and photo I've ever sent/received. I want to do the same with Signal.

john01dav 5 days ago|||
As an example that I experienced, I wanted a picture that someone took 2 years ago and sent to me on Signal. Since I am a data hoarder, I was able to retrieve it.
mihaaly 5 days ago||
perhaps others see it differently
brikym 5 days ago||
Hi Signal, can you please add a 'send without sound' feature.
Someone 4 days ago||
FTA: “This is the first time we’ve offered a paid feature. The reason we’re doing this is simple: media requires a lot of storage, and storing and transferring large amounts of data is expensive”

Those costs are for doing backups to their servers. If this supported making encrypted backups to Google drive/OneDrive/iCloud/etc, they wouldn’t have those costs, and, AFAICT, that would not be less secure, given (also FTA):

“At the core of secure backups is a 64-character recovery key that is generated on your device. This key is yours and yours alone; it is never shared with Signal’s servers. Your recovery key is the only way to “unlock” your backup when you need to restore access to your messages. Losing it means losing access to your backup permanently, and Signal cannot help you recover it.”

⇒ I think it’s more of “we were looking for a new revenue stream, and picked this as a way to get that”

There’s nothing wrong with that, but presenting it as “to get secure backups, we have to make costs” is disingenuous.

neobrain 4 days ago|
> ⇒ I think it’s more of “we were looking for a new revenue stream, and picked this as a way to get that”

This seems highly implausible given the 2 USD/mo pricing, the existence of a free storage plan, and the non-negligible operating costs that obviously do exist.

I'd be interested if you have data that supports the idea of the economics working out though.

Someone 4 days ago||
I do not have data, but I do have arguments.

If the economics do not work out, why did they chose to create infrastructure and take on the burden of supporting it instead of implementing backups to the popular cloud providers, and not having that extra operational burden?

Also, iCloud gives individuals 2 terabytes of storage for $11 a month. OneDrive and Google Drive are similar. S3 is less than 3 cents/gigabyte (with extra costs for reads and writes)

I guesstimate backups will take less than 100GB per user. At Apple’s consumer pricing that is slightly over half a dollar.

So, if they buy storage at bulk and get a sufficiently high number of customers, I do not see why they couldn’t make money on $2/month.

More comments...