signalapp / Signal-Android

A private messenger for Android.
https://signal.org
GNU Affero General Public License v3.0
25.62k stars 6.15k forks source link

Confidentiality issue : Private stickers pack can be downloaded by everyone #10484

Closed DeanBebek closed 3 years ago

DeanBebek commented 3 years ago

We leave Whatsapp for security, but now everyone can download ALL of your stickers pack when you share only one stickers.

Some of the stickers are private and dont want everyone to have access it! This is a huge security bug !! Please fix this ASAP or alot of people will leave Signal for this issue!

DeanBebek commented 3 years ago

This should be fixed on desktop, android and ios !

grandchild commented 3 years ago

Stickers are public by default. Which makes this a feature request. Please discuss these in the Signal Forums.

Also, please don't delete the issue template. Additionally writing "a lot of people will leave" feels a little bit threatening, and is very unlikely to make anyone implement the feature you want any faster.

Thank you!

DeanBebek commented 3 years ago

Well, this feature is not well implemented, we should be able to allow your private stickers pack to be public or not.

Because in whatsapp people make stickers of friends. If i share a funny stickers in a signal work group i don't want them to download all my stickers (private one) withing the pack.

I'm not the lonely one having this issue, alot of forum talking about that

DeanBebek commented 3 years ago

Stickers are public by default. Which makes this a feature request. Please discuss these in the Signal Forums.

Also, please don't delete the issue template. Additionally writing "a lot of people will leave" feels a little bit threatening, and is very unlikely to make anyone implement the feature you want any faster.

Thank you!

Sorry if you feel threatened this was not intended. What i meant is alot of people (not to say more than 50%) of Whatsapp users, which was hard to convince to use Signal amongs all other chat apps, they will be easier to them to leave Signal and switch to another app that provides more confidentiality regarding their stickers.

So, i'm sorry this is not a feature but a bug. All other chat app you can't just download the full stickers pack of people when they share one stickers.

I'm not asking to develop this feature for me, but just saying to keep Whatsapp user, just fix this because that annoys all whatsapp stickers users which is alot of users not just me.

grandchild commented 3 years ago

The difference between "develop this feature" and "fix this issue" is only semantics. Both need development effort.

I just talked to someone that's created whatsapp stickers (of their own face) with "Sticker Maker" (app to create custom stickers) -- and they weren't even aware of this distinction, that not everyone could download it. So the "all whatsapp users" claim is a bit hyperbolic.

For what it's worth, I agree with you that this would be a nice feature to have! (Not that I use stickers much myself...)

I still think that just because something works differently than another app, it's not necessarily a bug. Just a mismatch of expectations -- which, again, is completely understandable. I agree with your desire for private stickers, even if I might not agree with the level of urgency for Signal...

greyson-signal commented 3 years ago

Because we have no sticker store, the sticker feature was designed to make it easy to share packs. If you have the link to a sticker pack, you can see all the stickers in that pack. We don't have any plans to change this in the near future. If you'd like to limit what stickers other people see, I recommend breaking your sticker packs into smaller packs.

P.S. It's worth noting that the Signal service does not keep any record of who uploaded a pack, nor do we know anything about the pack contents (since the service does not have the keys to decrypt the pack). All of this makes it unlikely that we'd be able to easily implement anything like this, but it does give you different types of protections.