Signal introduces "username" feature
Its finally happening, you will be able to chat on Signal without disclosing your phone number to anyone.
Sadly usernames are required to have at least 2 numbers at the end of it, so you cannot get "og" names. However 01 at the end is pretty unique, I have compiled the beta version of Signal and checked many popular and "cool" words, and they are pretty much all unclaimed and you can have them with .01 at the end.
Its still in beta and supposed to launch in a few weeks.
https://signal.org/blog/phone-number-privacy-usernames/
https://support.signal.org/hc/articles/6712070553754

Comments
You're still required to use a phone number with Signal. We still do not know what their server is doing with people's data. User beware!
VPS providers to check out:
Their server is open source: https://github.com/signalapp/Signal-Server
You can use an anonymous eSim such as https://silent.link/
Here is what feds receive from Signal when they subpoena your data: https://signal.org/bigbrother/santaclara/
Also what data are you talking about? Everything is verifiably encrypted. There are even Signal client forks with baked in Tor routing and other security/privacy features, one of them being https://molly.im/
Signal implemented MobileCoin in their messenger without publishing any public code updates for almost a year, as we learn from this video https://www.bitchute.com/video/tJoO2uWrX1M/
The MobileCoin devs also removed the statement "At MobileCoin, we believe governments have a legitimate interest in regulating the economic lives of their citizens." Feel free to search the original evidence shown at this link https://web.archive.org/web/20201127142851/https://mobilecoin.foundation/about
I do not trust Signal, I do not believe anyone should trust Signal, but you're welcome to trust them & free to have your opinion about how what this company has done is not nefarious.
VPS providers to check out:
Thanks, works with the 7.0.0-beta.1 desktop app.
The Signal Protocol, not the current company, is a great protocol. The problem is the current implementation being funded by the Silly Con Valley company called the Signal Foundation.
VPS providers to check out:
It proves absolutely nothing in terms of your "data" claim.
You are more than welcome to trust anything currently being run out of Silly Con Valley.
VPS providers to check out:
I trust it enough to use with close friends and family. I wouldn't trust it in scenarios where anonymity is a requirement, I value its security and not privacy/anonymity.
Did you know that the Signal CEO resigned and then the WhatsApp co-founder took over in 2022?
https://www.rt.com/news/545730-signal-founder-resigns-state-dept/
VPS providers to check out:
Also in 2022, the Swiss Army banned their military from using Signal Messenger. If it is "so good" then why the ban?
https://www.rt.com/news/545502-switzerland-army-ban-whatsapp-privacy/
VPS providers to check out:
Except its not true. Brian Acton is a president of Signal non-profit, since 2018.
Signal new CEO is Meredith Whittaker.
Because their own encrypted app, Threema is a requirement and is contracted for this purpose.
At their place I would support a local company too.
Hi @treesmokah!
Do you know how Signal works?
Are / were the phone numbers involved in some kind of verification that senders and receivers really are on the devices they said they were?
Is it now going to be the case that a Signal user can take his username along while hopping across various devices?
It used to be that the only info Signal said they kept was the phone number, account creation date, User-agent, and the last time the client was seen. It just can't be true that Signal now is going to keep both phone number and username together?
Now:
Coming soon (hopefully very wrong):
Thanks!
Tom
Phone numbers correspond to public keys, they are presented to the user for verification. By default you give your contacts "limited" trust, and have to check qr/public key using another form of communication to be 100% sure you are talking to who you think you are.
You are able to pair different devices to one Signal account, its been like that for a long time. Username cannot be associated with multiple accounts at once, you have to pair your devices.
I assume it will be this way, there is no other way around it. Username is internally tied to your Phone Number/account.
finally! because the fundamental design flaw with signal is/was that everyone who wanted to write about signal knew my phone number. what a madness. but what else is to be noted, this guy behind signal (morklinblabla) is he serious? at least he seems to be active in the field of cultural appropriation and rather a politically left-wing bird, right?
Historically most of apps like this were created by Left-wing extremists or Anarchists using them to undermine the Government. It wouldn't surprise me if it was the case this time, but I'm not worried about it too much.
Tor is also "proudly" left-wing and supports fellow anarcho-communists such as Riseup. In this case it was a little bit more worrying as I witnessed Tor developers trying to exploit Tor to deanonymize services of people they don't agree with politically.
Comments under this Tweet are absolutely hilarious with basically nobody supporting this cringe virtue-signaling obviously forced by extremely Jewish Team-Cymru CEO serving as higher up in Tor foundation(who is no more after they have been exposed to be a NSA and Israeli intelligence contractor).
Cymru has also hosted essential infrastructure of Tor, such as authority servers.
Got mine.
.
Thanks, rastacat
Have you tried turning it off and on again?Nothing should be tied to your phone number as your PII & data are more valuable than anything in the world right now. Signal Messenger will never change their need to require a phone number and this username facade is just to muddy those waters even more.
VPS providers to check out:
Here's a great article I would urge anyone in the LES community using Signal Messenger to read. Information & knowledge of what we're using is very important.
https://dessalines.github.io/essays/why_not_signal.html
VPS providers to check out:
It all depends on your threat model. Good fucking luck getting your friends and family to install a XMPP client with OMEMO and teach them how federation works.
I treat Signal as less aids Whatsapp alternative, nothing more than that.
Also regarding this article, first recommended alternative being Matrix. If you dig deep enough you will find ties and funding from Israeli Intelligence agencies. I personally knew one of Matrix developers, and their protocol is absolute leaky garbage(almost like it was made on purpose).
I do not recommend anyone use Matrix/Element, its even worse than Signal.
https://hackea.org/notas/matrix.html
"If you were building a secure platform, and wanted to use an identifier, what would be the worst thing to use? Phone numbers." - this is the fundamental design flaw of signal!
It costs a whole $0.06 to have an "anonymous" Signal account.

Again, it all depends on your threat model. Signal was supposed to be normie friendly, and it is.
I would not trust for anonymous communication, I trust it with secure communication with my friends and family.
@treesmokah this might be offtopic, but since you seem to be quite active in the privacy scene, have you heard of or even tried Session by Oxen? I used it once with a friend, but we quickly stopped doing so, because unlike Signal nobody of our friends even knew Session. Session doesn't require a phone number to sign up and seems to send messages and route calls through an Onion networks where messages and files appear to be like separated encrypted shard where one server never holds enough data to decrypt a message. They're also F-Droid: https://getsession.org/
Ympker's VPN LTD Comparison, Uptime.is, Ympker's GitHub.
0,06$ for what? more details please.
I'm an early adopter and a friend of developers(now ex-developers) of Session, Oxen and Lokinet.
I do not recommend usage of any of their products. They have officially sold out to feds, they are not a privacy-coin anymore instead they are an ERC20(Ethereum) token now, and have defrauded their investors(or at least they feel like it).
Session codebase is a fucking mess, I cannot express it enough, it fucking sucks ass. Their management is a bunch of retards, especially Kee Jefferys(CTO or whoever the fuck he is there now). I have witnessed him baking in a hardcoded blacklist of SOGS(Session Open Groups) after he was contacted by some organization that allegedly fights CP distribution, he has not verified anything, he has received SHA512 hashes of said groups and just told his developers to bake it in to the software(with absolutely no legal grounds, to do it in the first place). After protest of Employees and close group of community members, it was ditched and 99.99% of the people don't even know it happened.
Oxen was fairly ok. Lokinet was my favorite with a truly passionate developer(i2p veteran), who has since quit after recent developments inside Oxen(OPTF Foundation), and the community died so did the project as a whole. I used to run the largest Lokinet services around and be very active in the community, but oh well. Any old member of the community should know who I am.
I could go on about it for hours, but to shorten it up.
Oxen is dead, Lokinet is dead, Session is unusable and trash and will soon be dead. Entire OPTF will soon be dead, they are out of money, completely, and try to find it in the worst places imaginable.
Their pathetic management ran this project to the ground. Who thought trusting Australians with anything was a good idea.
For a phone number that can be used for Signal, then you set 2FA(or whatever they call it) so someone cannot recover your account if they get the same number somehow, and that's about it. I've been doing it like that on Telegram for ages.
What's the name of this service? The ones I found are more expensive.
https://onlinesim.io/
Thanks for the summary. What a shame.
It sounded promising when I first heard about it, however, when I recently saw a video ad from Session on Instagram I couldn't believe it was from them. The video seemed really odd and even someone in the comments said it doesn't instill confidence. Adding your information it seems like I am not likely to use Session again.
I was between Signal and Session when I was looking for a WA alternative that I could use to communicate with friends/family and it's definitely been easier to convince (some of) them to use Signal than Session. Looking forward to the username feature! Not that I expect to be anonymous using Signal, but similar to what you said earlier, I trust it to chat with family/friends.
Ympker's VPN LTD Comparison, Uptime.is, Ympker's GitHub.
@Ympker what about threema?
Session requires you trust the masternodes, so you put your trust into the people running those to use it. It is also using the OXEN (used to be LOKI) cryptocurrency for the chats.
VPS providers to check out:
@treesmokah How do you pay onlinesim.io without losing your privacy?
Monero, or shielded Zcash or the mixed version of Dash.
They support them all.
Not really, your messages are routed by a minimum of 3 nodes(much like Tor) and stored in swarms distributed among nodes, encrypted. Attachments are stored by servers controlled by OPTF(on Hetzner I believe), and are also encrypted.
Nah, you don't really have to trust any node. Only node that sees your IP is Guard, that has nothing but encrypted string that is supposed to be forwarded to another node(with its public key), and so on. On paper, correlation is extremely difficult. Hence the name "Onion routing", its being gradually decrypted by nodes.
No, It isn't. Oxen is a PoS Monero fork with "masternodes" that store blockchain and "mine" blocks.
They are also used for relaying Lokinet traffic(UDP) and Session data(special TCP based proto, while Lokinet integration is "on its way" since forever, it will most likely never come). Messages or anything related to Session(besides ONS) are never stored on the blockchain, instead in special swarms on nodes for a period of 7(or 14 days, I don't remember), not permanently. So you have to open Session from time to time to get messages before they expire in swarms, similarly to Jabber and offline queue(XEP-0160).
In LOKI days it was done much differently, it wasn't a PoS coin with "relaying" functionality. They used something called "proxy routing" but its not important anymore.
Session voice and video chats are entirely P2P(with centralized STUN), not onion routed/anon. Lokinet integration was supposed to allow wrapping it and making it anon, but as I mentioned above, it will most likely never come. They started writing bindings, but I haven't checked on it since forever.
I doubt Signal is doing anything malicious with user data if what the US government gets is essentially only Unix time since sign up and last access. If they had other data they would have been required to provide such data...
It's hard enough to bring (non techy) friends to switch away from WhatsApp or at least use an alternative messenger as is. Threema being a paid messenger app, even if only 6€, isn't something they're going to consider after using WhatsApp, fb, insta etc free (ofc paying with data, but you know "free") for years. Convincing them to use a paid messenger won't do. Trust me, it's been hard enough to convince them to give Signal a chance.
Right now about 20 of my contacts have Signal and about 3 of them actually use it/reply to messages sent on Signal. The others usually just continue using WhatsApp. And those 20 contacts only include about 5 ppl I was able to convince to use Signal. The rest already had it when I installed it.
Ympker's VPN LTD Comparison, Uptime.is, Ympker's GitHub.
People with smartphones concerned about privacy > @Ympker said:
People who use smartphones (and pay with cards) needn't worry about their privacy.
🔧 BikeGremlin guides & resources
Well, yeah. Their argument to install Signal ofc wouldn't be intrinsic motivation but just because some friend (me) tells them to use an alternative for some techy and privacy reasons they don't want to or can't follow. It's a bit like Dale Carnegie says in his books "A person convinced against their will, is of the same opinion still". This is probably why I got 20 contacts on Signal but only 3 are actively using it/replying while the others probably have been convinced again their will and set it up, but don't use it.
Personally, I didn't install Signal because I thought I'd be anonymous or get super privacy on an Android phone. However, I thought it would be at least a better choice than only relying on Meta apps to communicate with friends. Naturally, I am still bound to WA due to many other contacts :P
Ympker's VPN LTD Comparison, Uptime.is, Ympker's GitHub.
I find it inconvenient that many messengers exist.
So, Russians mostly use Telegram, Serbs use Viber, and others mostly use WhatsAp.
Of course, I keep all that stuff muted and check them once per day or less frequently.
If something's urgent, people just call me.
🔧 BikeGremlin guides & resources
i buy threema licences and give them away to my oh-so-poor friends who buy a cup of coffee every day for the value of a lifetime threema licence. if i tell them that, they feel very ashamed.
Fair enough. I totally agree that the license's pricing is more than fair, but as a student, I'm not gonna hand out free licenses. That's why Signal is my best bet atm. I actually DO know lots of my friends that have setup Telegram and, contrary to Signal, actually use it. However, they don't seem to be aware that Telegram chats by default aren't e2e encrypted, only "secret" chats. At least that was the last time I read about Telegram. Ironically those that use it, also installed it for "privacy" reasons but then use it without e2e. Others I know use it for the TG bots to get media etc
Ympker's VPN LTD Comparison, Uptime.is, Ympker's GitHub.
I would argue that practically nothing is really e2e encrypted.
🔧 BikeGremlin guides & resources
Personally, I lack the technical knowledge to verify Signals e2e claims. But it being open source at least bears the possibility of more knowledgeable people than me verifying those claims, which in the end makes it a tad better than WhatsApp imho. Of course, WhatsApp has the bigger userbase and in the end I can only do as much as try to opt for a better solution while probably still having to stick to WA for years to come.
Ympker's VPN LTD Comparison, Uptime.is, Ympker's GitHub.
I like that Threema is paid and therefore not having to rely on external funding (at least according to their own marketing materials). That said no one in my circle is going to be convinced enough to pay for it, so Signal it is. Still keep it on the back burner though.
It gets decrypted on your device. Your device is connected to the Net.
🔧 BikeGremlin guides & resources
And then there's me using IRC
Jokes besides (it's not a joke but w/e) an XMPP-compatible IM is all it's required and there's no need to constantly reinvent a wheel.
Getsession has been mentioned, there are a few other "secure & pseudonymous" approaches out there. SimpleX has received some nerd hype recently as well. Matrix is convenient for its bridges, anyway it's has received some security-wise criticism has already been noted (obviously it ultimately depends on your threat model). Briar received some hype a while ago for its censorship-resistant features. Still, what matters with IMs is adoption.
Matrix recently launched an appeal for fundraising, this has raised some concerns about its future. Signal has massive costs too, so it's no surprise that some "coins" or some revenue strategy is devised along the road. Telegram did the same too, without bothering too much about security details and practices (and not just for the fact that E2E isn't enabled per default, some bug have enabled to snoop on non-public groups using unofficial clients and other clients have been devised to be ToS-breaching) ; Telegram success eventually boils down at presenting itself as overly "convenient" for its userbase (and for some developers, since it exposes an API for various bots); it has become quite adopted and "premium" features (and coins) have been introduced. It also started to have "stories", like Instagram. Signal hopped on that boat too.
XMPP has nothing wrong. It has been interoperable with Google Chat until 2011 I think, at that time Google/Facebook et al decided to make their XMPP implementation non interoperable. It remained interoperable with GTalk for a few years after that.
Not every XMPP server and client have the same set of features; Snikket offers modern XMPP features making it completely interoperable with non-Snikket clients (e.g. Conversations on Android) yet offering clients for every device (including Apple-based ones) with the goal of offering a seamless user experience. If you're planning or open to self-host it (even on a raspberry pi), it could be really convenient. Sure your peers are supposed to have installed at least an XMPP-compatible client, if not Snikket itself.
But as said, what matters with IMs is adoption. Matrix with its bridges may allow a willing sysadmin to offer a chatroom more or less available for every (or most) IMs actually used by its users, winning over the innate resistance to download yet another app for IM. A bridge may be convenient yet it will slow down actual adoption and will just add security issues.
Will I use an username on Signal, after all these years? I don't think so. Maybe a vanity username at this point in time.
Will Signal get more users thanks to this move? I don't think so.
Here what I see is "Whatsapp for people I know, Telegram for groups/people I don't know/trust that much" (since you aren't supposed to share your phone number)
I found less resistance to invite people to Snikket et al than to Signal, mainly because there's a perceived lower barrier at signup (I guess that giving out a personal phone-number is perceived as musky) and Message Carbons and other features
Let's take a look in this article from 2021 to learn more
https://www.rt.com/op-ed/513732-signal-messenger-us-national-security/
VPS providers to check out:
Telegram also rolled their own encryption instead of using an already trusted and vetted type.
https://resources.infosecinstitute.com/topics/cryptography/the-dangers-of-rolling-your-own-encryption/
Any messaging service that uses centralized servers is bad news. I see that SimpleX looks promising & you can host your own servers.
VPS providers to check out:
Thank you @treesmokah for the heads-up about registering usernames. I just did this for me and my wife.
With regards to Threema, the idea sounds great, but that paid license... ouch!
I find it really easy for me to grab a license since I appreciate privacy, but it would be hard to convince others in buying such license. The best use for such software would be inside a company, where a manager should want complete privacy within their company.
Cloudcone | Crunchbits | Dartnode | Dedirock | Georgedatacenter | Gigahost | Hostbilby | Host-c | Hostdzire | Hostsailor | Namecrane | Nuyek | Realtoxmedia | Servarica | Terabit | Tnahosting | Virmach
or do a good deed and give away licences (worth the equivalent of a good cup of coffee)!