Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Please actually read

  > Registration Lock expires after 7 days *of inactivity*
I don't know why you dropped "of inactivity" and changed it to "or less".

If you use signal once a week you're fine. Maybe it should be longer but that's a different argument and there's no reason to be disingenuous about it



It does not matter if you lose control of the number, the new person will be able to register. The 7 days period is for you to get control of the number back or make sure all your contacts know about the issue.


am I reading it wrong? but on my phone if i activate reglock again it says that if pin fails the account is blocked for seven days. I asume that after 7 days one still needs the pin to register or am i wrong?


You'll get the opportunity to change the pin.

There's a balance they want to strike. You can't assume phone numbers are unique to a person across time. So they need to be able to expire when someone stops using a number.

But again, acting on the other side also gets a notification in the chat stating that the security number has changed. The new person doesn't have the signal chat history. So if you're talking about sensitive things then it's a strong indication you should reverify their identity. Not practical for every day users but that's also not a typical threat scenario


Seems like you missed reading the entire context above. The discussion was about a number being seized or taken over by someone else. So your reply on inactivity is irrelevant since the new owner of the number can just wait a mere week and use it with Signal.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: