4 ms·
What do you recommend instead?
by math_and_stuff 8y ago
What do you recommend instead?
- woodruffw 8y agoI don't know if I have any strong recommendations. In terms of what I use: Keybase and iMessage, depending on who I'm talking to.
- unicornporn 8y agoMatrix/Riot.im is federated and has E2EE. It also has brigdes for IRC, Telegram etc. Here's a native client for macOS: https://neilalexander.eu/seaglass https://neilalexander.eu/seaglass Web client: https://riot.im/experimental/ https://riot.im/experimental/
- im3w1l 8y agoMatrix is also experimental. About a year ago it kept losing my key meaning I couldn't decrypt old messages. I still use matrix, but I don't have any illusions that it's more secure than tox.
- Arathorn 8y agoWe're not aware of any bugs where Matrix clients lose your e2e keys (other than one where changing your password may cause clients to log out and remove keys for safety). If you saw it keep losing keys, i'm going to guess you configured your browser to delete local storage when you close the tab... in which case, unless you export the keys, we have nowhere else to store them. That said, we've also just implemented the optional ability to encrypt and backup your keys on the server, but obviously comes with other tradeoffs. In terms of security, the core crypto has been audited, as per https://matrix.org/blog/2016/11/21/matrixs-olm-end-to-end-encryption-security-assessment-released-and-implemented-cross-platform-on-riot-at-last/ https://matrix.org/blog/2016/11/21/matrixs-olm-end-to-end-en...
- im3w1l 8y agoIt hasn't happened in a year (I still use it) so whatever the issue was I don't see it anymore :)
- crtasm 8y agoI tested riot.im in a private Firefox window recently, obvious with hindsight but it didn't occur to me I should export keys and I didn't spot anything in the interface to make me aware or prompt me to action. Great to hear you've added the option for server stored keys now.
- Arathorn 8y agoyeah, it's a tricky one because by the time you've closed the window, it's too late to export keys. The new online key backup stuff landed a few weeks ago on the develop branch, and will be making it onto the main release over the coming weeks :)
- jake_the_third 8y ago> I don't have any illusions that it's more secure than tox. That conclusion doesn't follow. How does the client loosing your key cause you to consider matrix itself as less secure?
- ndnxhs 8y agoMatrix has also had a proper security evaluation
- jstanley 8y agohttps://ricochet.im/ https://ricochet.im/ is a great protocol, but the UI could use work.
- mirimir 8y agoYes. Each client runs a Tor .onion service, and there's end-to-end encryption. So arguably, users are mutually anonymous (except for their .onion addresses). But it's only available for Windows, macOS and Linux. On Android, there's Briar, which is similar.[0] But Briar can also connect via Bluetooth and WiFi. That's useful when the Internet is unavailable. But it's bad because user anonymity could be blown. 0) https://briarproject.org/ https://briarproject.org/
- jstanley 8y agoI was working on a self-hostable web interface for a while. There's a public instance at https://ricochet-web.org/ https://ricochet-web.org/ but unlike the official client it hasn't been professionally (or otherwise, for that matter) security-tested and is vulnerable in various ways the official client isn't. It also has quite a few known and unknown bugs.
- crankylinuxuser 8y agoI used tox for a while until I realized just how sketchy the devs and community is. Now, I recommend using xmpp(Open fire) over Tor. That allows things like Crankylinuxuser@onion-v3-verylongkey.onion To send messages. And my server can also send messages out via tor gateways or to other torified messaging servers. Tl;Dr. Use secure protocols and combine with Hidden Services.