← Back to context

Comment by traceroute66

9 hours ago

> What is a more private, usable solution for filtering them out than using a phone number?

Since when is giving out your phone number a "more private" option ?

You don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people.

If it's not, let us know a solution (to Signal's actual problem as stated in the GP) that is more private.

  • One possible solution is to only be able to contact someone if you have received an invitation code from them out of band. E.g. "scan this QR code to add me on signal". Such an invitation code should default to single-use but users should be allowed to generate standing invitations so that businesses and the like can print and post one in their store or whatever. Start getting spam from one of your standing invitations? Just revoke it and make a new one. Presumably the Signal folks can come up with more alternative solutions than the half baked one I came up with after thinking about it for a minute, they're clever cookies.

    • Welcome back to “key signing parties”. PGP never got enough adoption. At least Signal is simple enough that the (ahem) leaders of the US can (mostly) manage to use it.

      1 reply →

    • Imagine setting up a chat for an organization you're working with - will you be willing to process 20 out-of-band QR codes? 50?

      On a smaller scale, it's clear that Signal believes a functioning address book is necessary for end user adoption. For example, by default Signal notifies you of people in your phone contacts who are on or who later join Signal.

      > Presumably the Signal folks can come up with more alternative solutions

      I have yet to see a solution better than the one they chose, for their requirements. Notice that there are none in this discussion.