• Pfosten@feddit.de
    link
    fedilink
    English
    arrow-up
    9
    ·
    1 year ago

    For a project like Signal, there are competing aspects of security:

    • privacy and anonymity: keep as little identifiable information around as possible. This can be a life or death thing under repressive governments.

    • safety and anti-abuse: reliably block bad actors such as spammers, and make it possible for users to reliably block specific people (e.g. a creepy stalker). This is really important for Signal to have a chance at mass appeal (which in turn makes it less suspicious to have Signal installed).

    Phone number verification is the state of the art approach to make it more expensive for bad actors to create thousands of burner accounts, at the cost of preventing fully anonymous participation (depending on the difficulty of getting a prepaid SIM in your country).

    Signal points out that sending verification SMS is actually one of its largest cost centers, currently accounting for 6M USD out of their 14M USD infrastructure budget: https://signal.org/blog/signal-is-expensive/

    I’m sure they would be thrilled if there were cheaper anti-abuse measures.

      • BearOfaTime@lemm.ee
        link
        fedilink
        English
        arrow-up
        7
        ·
        1 year ago

        Bad actors can buy one.

        What does it cost to buy hundreds? It’s a great deterrent to bad actors creating many accounts.

        I really, really, really dislike using my phone number to verify. Like so much so it kept me off signal until about 6 months ago.

        I get it. I don’t like it, but I get the compromise until they can develop a better mechanism

          • jet@hackertalks.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            You could run a network like signal, and either charge a small amount of money per message, or a larger amount of money to register with the network.

            Hell you could do the WhatsApp model, charge a dollar for new users, the pay for the registration verification. The same thing.

            You just need some mechanism to add friction for mass spamming, be that money time or complexity.