4 ms·
Depending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you
by jeroenhd 19d ago
Depending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you have to pick your poison. If E2EE is important, you also need to determine how encrypted you want your messages to be (as both XMPP and Matrix carry quite a bit of identifying metadata in its unencrypted headers).
For most people and use cases, either will probably do, but if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal.
- ezst 19d ago> if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delivery? I mean, as opposed to using something like XMPP which you can completely use over Tor and never even reveal which server you use/that you use XMPP, from a client running a secure and minimalistic OS and no service-in-the-middle ? Some would label Signal as a honeypot and it would be difficult to falsify that.
- zeratax 19d ago> Or throwing it all away anyways when it's using Apple/Play services for notifications delivery? What do you mean by "all"
- amiga386 19d agohttps://www.wired.com/story/phone-notifications-reveal-more-than-you-realize-how-to-lock-them-down/ https://www.wired.com/story/phone-notifications-reveal-more-... Apple, at least, maintained a historical database of your phone's notifications, that it did not clean up after they expired. That includes all notifications from Signal telling you that person XXX has sent you a message that starts YYYY <facepalm>
- zeratax 19d agoForgot about that and that def was bad, though imo not really on Signal and would have just as much affected any XMPP app, no? To me this definitely didn't "[throw] it all away" as in your messages were still only on your phone and never decrypted on any server or w/e.
- amiga386 19d agoWell that's the thing, you just don't know what happens once you let Signal send notifications via Apple/Google - clearly they get them plaintext, and who knows if they're retained and subpoena-able directly from Apple/Google. The leak via notifications DB not being cleaned up is just the shot across the bow. You pay a price for convenience. Anyway, I'm not OP, and they have a mad setup (XMPP via Tor) which is a flaky solution most people wouldn't go for. In general, if you're not going to such extreme measures of hiding among the crowd of Tor users to mask your metadata, you're better off directly connecting and hiding among the crowd of Signal users, rather than hosting your own instance.
- zeratax 19d agoto be clear though notifications do the decryption on device themselves. signal uses apple/play services only to notify the device that there has been a message, none of the contents are delivered over these services. if you cant trust the device to do that then no messaging app could ever be secure enough
- fsflover 19d ago> if you cant trust the device to do that then no messaging app could ever be secure enough This is the whole point. Signal actively prevents me from using it outside of the Apple-Google duopoly. Other messaging apps are not like this.
- throwaway74354 18d agoDe-jure it's against the ToS, but it's not being enforced besides "don't be an asshole, don't abuse the network and be careful with Signal branding". Technically, you can use Whisperfish on SailfishOS, Flare on mobile-linux-of-the-day or even signal-cli as a primary device.