3 ms·
That’s not really a big deal since the session encryption was insecure anyway. It feels almost like a honeypot after they've removed forward secrecy. If you’re
by RandomGerm4n 6mo ago
That’s not really a big deal since the session encryption was insecure anyway. It feels almost like a honeypot after they've removed forward secrecy. If you’re looking for a decentralized alternative SimpleX Chat is a more secure option.
- Jigsy 6mo agoMy issue with SimpleX is that the company is in the UK, and it's developed in the UK under UK law. https://simplex.chat/transparency/ https://simplex.chat/transparency/ Considering how fiercely anti-encryption the UK is/has become (because "only child molesters care about encryption!"), this is sadly reason enough for me not to trust it. Do I believe they have a backdoor in their software? No. But if the UK passes a law demanding they introduce one...
- graemep 6mo agoIts FOSS so such a change would be visible. What government are you certain will never introduce a backdoor requirement?
- seanw444 6mo agoOr the mature and robust XMPP + OMEMO.
- RandomGerm4n 6mo agoThe problem with XMPP is that most clients use an outdated and insecure implementation of OMEMO. This includes popular clients such as Conversations and Gajim. Currently only Profanity and Kaidan use the latest version and you must always assume that the encryption has been secretly downgraded because the other person is using an insecure client. I highly recommend Soatek's blog post on this topic. https://soatok.blog/2024/08/04/against-xmppomemo/ https://soatok.blog/2024/08/04/against-xmppomemo/
- zaik 6mo agoI do not understand the security implications of this "Invisible Salamanders" post, but I would prefer XMPP even without any end-to-end encryption over a walled garden like Signal or Session.
- paulnpace 6mo agoDoes that blogger discuss metadata, at all? I'm not saying the stuff pointed out in various non-Signal tools isn't valid, but I don't see any discussions on the dangers of metadata.
- some_furry 6mo agoYes, I do. See my review of Signal for more: https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/ https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...