3 ms·
Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisati
by ezst 20d ago
Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims about being privacy conscious.
- fredski42 20d agoDoes the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
- zx8080 20d agoXMPP. Run your own (federated) server, chat with anyone outside it, with e2e encryption.
- fsflover 20d agohttps://matrix.org https://matrix.org is used by public agents of France's central administration, Germany's national healthcare system, Germany's armed forces, the Swedish Social Insurance Agency and more: https://en.wikipedia.org/wiki/Matrix_messaging https://en.wikipedia.org/wiki/Matrix_messaging
- ezst 20d agoRealistically nothing is ever perfect, but XMPP comes very close. You've got Signal-introduced double-ratchet encryption if forward secrecy is your jam (so it's as "E2E-secure" in practical terms) and you've got a healthy ecosystem of independent client and server implementers, and service providers to choose from.
- Tomte 20d agoIs there a messenger that allows anonymous group chats, i.e. for union organizing in a company? As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it. Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.
- wasting_time 20d agoI think you can do this with Jitsi: https://jitsi.org/ https://jitsi.org/
- piltdownman 20d agoWhy not? Plenty people already use a dedicated '2FA' phone for Work under BYOD policies when they don't want to install any 'work' software on their 'personal' phone.
- Tomte 20d agoBut they won‘t buy a second personal phone to protect their privacy in a chat group.
- deleted 19d ago[deleted]
- jeroenhd 20d agoDepending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you have to pick your poison. If E2EE is important, you also need to determine how encrypted you want your messages to be (as both XMPP and Matrix carry quite a bit of identifying metadata in its unencrypted headers). For most people and use cases, either will probably do, but if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal.
- ezst 20d ago> if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delivery? I mean, as opposed to using something like XMPP which you can completely use over Tor and never even reveal which server you use/that you use XMPP, from a client running a secure and minimalistic OS and no service-in-the-middle ? Some would label Signal as a honeypot and it would be difficult to falsify that.
- zeratax 20d ago> Or throwing it all away anyways when it's using Apple/Play services for notifications delivery? What do you mean by "all"
- amiga386 20d agohttps://www.wired.com/story/phone-notifications-reveal-more-than-you-realize-how-to-lock-them-down/ https://www.wired.com/story/phone-notifications-reveal-more-... Apple, at least, maintained a historical database of your phone's notifications, that it did not clean up after they expired. That includes all notifications from Signal telling you that person XXX has sent you a message that starts YYYY <facepalm>
- TacticalCoder 20d ago> Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)? (Note that I don't care about cryptocurrencies except for the cryptography behind it) There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made for (anyone with a copy of the chain can potentially be the recipient of either the money transfer or the encrypted message). If people were really serious about privacy and secure messaging they'd look into this instead of constantly attacking the concept. But then of course there are entire armies of shills who have a vested interest in pushing a narrative explaining that services, at best, collecting metadata and, at worst, being backdoored are offering "secure messaging". I'm only using Telegram and I don't believe for a second it's secure and private (it's got, supposedly, "one on one" E2EE but not for groups). But at least they're not posturing as the most secure and private messenger on earth.
- pas 20d agohttps://status.app/ https://status.app/
- RunSet 20d ago> 100% e2ee encrypted and decentralized and open https://getsession.org https://getsession.org https://docs.getsession.org/contribute-to-the-session-network/running-a-session-node https://docs.getsession.org/contribute-to-the-session-networ...
- user10235 20d agoNot decentralized (just like Signal), but open and 100% E2EE: SimpleX, Delta Chat, Matrix
- AceJohnny2 20d ago"Federation freezes the technology" https://signal.org/blog/the-ecosystem-is-moving/ https://signal.org/blog/the-ecosystem-is-moving/
- fsflover 20d agoThe answer from Matrix is here: https://matrix.org/blog/2020/01/02/on-privacy-versus-freedom/ https://matrix.org/blog/2020/01/02/on-privacy-versus-freedom... Related thread: https://news.ycombinator.com/item?id=21936929 https://news.ycombinator.com/item?id=21936929 See also: https://news.ycombinator.com/item?id=35141223 https://news.ycombinator.com/item?id=35141223
- ezst 20d agoThat's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/ https://gultsch.de/posts/objection/ In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardize and document, 3- I reserve the right to change the deal for whatever reason if I ever feel the need" which is not a good look
- jeroenhd 20d agoMatrix is a vastly different protocol with vastly different privacy implications. Things like leaking reaction metadata outside of the encrypted envelope (though there finally is an MSC to fix that) should make that obvious. Matrix is cool tech and I use it every day, but comparing Matrix to Signal doesn't make much sense. You can't do what Signal does with Matrix or XMPP, simply because the lack of federation affords privacy and security advantages that federated protocols cannot support. As for Moxie's post: all three points feel completely valid for a service they're offering for free. Moxie does know better than most users (most users don't know the first thing about software, programming, protocol design, or UX design) and it's a companies choices that drive users to their platform in the first place. Users who don't like it can choose from the dozens of other chat apps instead. As for the second point, Matrix's ever-moving target of a protocol makes selecting a client or server that covers all of your needs a massive pain. Currently, Matrix's primary server software, Synapse (which is also at the base of the matrix.org server many people default to when joining the network), is violating the Matrix protocol, making it impossible to invite users to chat if they are on compliant Matrix servers. On the XMPP side, there are two different methods of achieving E2EE communication, with seemingly no standard mechanism to support the use case "I want to log in to my chat on my laptop and be able to decrypt the messages in the group chat". I can't blame Signal for not wanting to deal with issues like that. One piece of server software, one set of client versions, with fixes ready to deploy when they're called for: Signal's current design saves a lot of time and effort. As for the third point, that's part of the reason I use Signal in the first place. I like federated networks as much as the next nerd and I like open standards even more, but the decisiveness behind the company, even when I disagree with their decisions sometimes, is what makes it clear what you can and cannot expect. On the XMPP defence: yes, I believe what they are saying, XMPP could in theory be a good product, just like Matrix could be, and like Signal is. However, currently, it isn't. XMPP is currently losing in terms of public marketshare to Matrix, which I also wouldn't exactly call a great success.
- 1vuio0pswjnm7 20d ago"...otherwise they would welcome third party clients..." Signal app can update itself at any time The app is constantly phoning home to Signal servers checking for updates even when it has not been launched and is not being used That means the client could change at any time, for any reason, unbeknownst to the user If the advanced user is free to write, edit and compile source code for a Signal client, software developers might call this a "third party client" because there is allegedly some "business transaction" between Signal Corporation and the user where Signal Corporation and the user are first or second parties (although, curiously, the Signal app and service are free) But it's arguable the more important use of the term "third party" in this context, i.e., "secure" communications, is to indicate a party that is not a first or second party to the communication, a potential eavesdropper Signal Corporation is a third party to the communication Because it forces users to use its closed source client software that can be updated at all times for any reasons when it's installed on a user's computer, there exists the potential for remote code execution and, for example, eavesdropping For example, a US corporation subject to US law could be legally forced to eavesdrop on a particular user. This could be done with an "update"
- ezst 19d agoAre you a LLM? In this context, a third party client clearly refers to "a Signal app/client software that's not distributed by Signal", The point I was making is that this goes against Signal's terms of service, and can get your user account terminated. That's a very oppressive clause in practice, you may want to use a non-signal client for all kinds of legitimate reasons (porting to a non supported platform, to adapt for accessibility needs, for privacy, for compliance, to remove nagging and dark patterns, etc). Signal don't want that, they want to control your user experience, even if this makes it worse for their user.