Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For me I stopped using Signal when they started permanently storing sensitive user data in the cloud, they were extremely unclear about doing it confusing many of their users, they ignored the objections and security concerns of their users who realized what they were doing and they never updated their privacy policy to reflect that information (and still haven't). For an app that insists that you be able to trust it, they just did not come off as remotely trustworthy.


Do you have anymore info on that?

Good sources to read?


Here are a bunch of threads I found:

https://community.signalusers.org/t/proper-secure-value-secu...

https://old.reddit.com/r/signal/comments/gmwheu/introducing_...

https://old.reddit.com/r/signal/comments/hkl914/welcome_to_t...

https://old.reddit.com/r/signal/comments/giqxug/whats_happen...

https://old.reddit.com/r/signal/comments/hkle3d/forced_pin_b...

https://old.reddit.com/r/signal/comments/ghsj5b/pin_cloud_st...

https://old.reddit.com/r/privacy/comments/hm2fwx/why_i_think...

Signal then announced that because of all the hate they'll make the feature optional, but opting out would just set a pin for you and upload your data anyway. This also caused a bunch of confusion.

https://old.reddit.com/r/signal/comments/hnok10/moxie_on_twi...

https://old.reddit.com/r/signal/comments/hrlmoe/pins_now_opt...

https://old.reddit.com/r/signal/comments/hoh7e9/moxie_marlin...

/u/PriorProject has a comment far down which sums up my view pretty well in this one:

https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin...

It's worth pointing out that they're collecting the type of data they still brag about not being able to turn over because they "don't keep user data".

https://signal.org/bigbrother/eastern-virginia-grand-jury/

In fact, this was posted just one month before all this went down: https://signal.org/blog/looking-back-as-the-world-moves-forw...

Between that and not updating their privacy policy it's a pretty massive red flag, but so many people don't even know about the data collection. Look at the answers this guy gets:

https://old.reddit.com/r/signal/comments/q5tlg1/what_info_do...

same with the top comment here:

https://old.reddit.com/r/privacy/comments/qpb8eh/mlat_order_...

It's insane, and I hope every user who has to learn what signal is really collecting from some random internet comment thinks long and hard about what that says about how transparent and trustworthy signal is.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: