-
-
Notifications
You must be signed in to change notification settings - Fork 6.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Inadvertently sent insecure messages via SMS without clear notification #4390
Comments
There is a pop-up warning the first time you send a message to a contact that has unregistered from Signal. But despite that I've been bitten by this more than once because I have a lousy memory. 😵 Edit: Well, I'm not sure about the above any more. I just unregistered my test device today and now I was able to send an SMS to that number without the warning popping up. There is a big invitation banner at the top though. And there's always the "Send unsecured SMS" string in the compose box. |
How about a warning looking like the missing call message, that says something like the pop-up warning? |
Well I didn't see the invitation banner. Maybe because my Signal users directory wasn't refreshed? Just happened again, this time with the recipient. Since in my country phone numbers had a number change, I re-registered it with Signal. But the recipient still had my old number that was just deregistered. The recipient sent messages too that were unsecure SMS before I could warn it. |
The current behaviour (3.9.0) seems to be:
In conclusion there is always a warning or information of the transportation method. |
I still experience the same (or similar issue). Every once in a while, Signal will "forget" a contact has registered with the directory, and without notice, my phone will fallback to insecure SMS. This happens seemingly at random, and I have experienced it with two contacts, neither of whom have unregistered from the directory. The messages they send to me are still encrypted, however. |
i would like an option to set that i never ever want to send (unencrypted) sms with this app, no matter what. |
Why an extra option? Signal shouldn't send SMS when SMS and MMS are turned off (with the setting that currently exists). |
GitHub Issue Cleanup: |
I've sent several messages to a recipient before I realized they were being sent as unsecure SMS, even though I had disabled the app to send via SMS. The recipient had not advised me the app was uninstalled from the other end.
I remember previously, maybe when the app did still encrypt over SMS, that whenever the message was downgrading from Push messages to SMS, it did pop up an alert.
I suggest an option in settings to disable any way to sending over SMS. Now my sensitive data has been sent out in clear plaintext overseas between carriers.
The only UI portion that could warn me was the grey text "Send unsecure SMS" inside the textbox that is immediately replaced if you quickly start typing, and the Send button was with a very small unlocked lock icon.
Before even the bubble texts were in a different color.
I just want some way to prevent inadvertent sending of unencrypted messages. Maybe a way to make it a default option to only send securely and always warn you the first time it has downgraded to unsecure SMS.
I do not use Signal as the default SMS app, and since the contact had uninstalled the app, I had no way of knowing it, since the conversation still appeared on the conversation list.
Thank you!
The text was updated successfully, but these errors were encountered: