signalapp / Signal-Android

A private messenger for Android.
https://signal.org
GNU Affero General Public License v3.0
25.58k stars 6.14k forks source link

PIN should not be mandatory #9853

Closed ML-Chen closed 4 years ago

ML-Chen commented 4 years ago

Bug description

Signal now mandates all users to create a PIN, and then uploads user data to the cloud. Never mind that a PIN (which is typically just four digits long) is not strong enough to securely encrypt anything on the cloud. Creating a PIN is highly inconvenient, especially if you're trying to get your friends and family on Signal and makes it more difficult for them to remember, and overall this decreases the privacy and security of users. Signal should revert to how it was just a few months ago, when it didn't require a PIN.

This may be by design, but if so, it is a poor design decision that should be reconsidered and considered a bug.

Steps to reproduce

Actual result: Describe here what happens after you run the steps above (i.e. the buggy behaviour)

Signal requires you to create a PIN, before you can access your messages. (Also, this is a violation of GDPR)

Expected result: Describe here what should happen after you run the steps above (i.e. what would be the correct behaviour)

Creating a PIN should be optional.

greyson-signal commented 4 years ago

As of 4.66.x, You can opt-out of PINs in Settings > Advanced > Advanced PIN settings. There's also a three-dot menu in the top right to opt-out of creation during registration.

Usability commented 4 years ago

I would like to report that a 75-year-old user did not see the three-dot menu in the top right to opt-out of PIN creation during registration.

Maybe because similar dots/stars on the same screen are decorative only? Or being unfamiliar with the three-dot menu as an iOS user (ups, just realizing I write this in the Android repository - sorry)?

Can you please consider a better visibility of the PIN opt-out option during registration?

Unfortunately, this person also had a surreal but strong opinion against "another PIN to remember" :-/.

Please keep up the great work! I love using Signal. Thanks.