Last year, I outlined the specific requirements that an app needs to have in order for me to consider it a Signal competitor.
Afterwards, I had several people ask me what I think of a Signal fork called Session. My answer then is the same thing I’ll say today:
Don’t use Session.
14 Comments
zephorah@lemm.ee · 44 pts · 1y
Cliff notes: end to end encryption is borked.
ChairmanMeow@programming.dev · 14 pts · 1y
So borked in fact that the author's fursona face-palmed in response.
haverholm@kbin.earth · 22 pts · 1y
I weren't even aware it was a Signal fork! What kept me away was their heavy integration of the Oxen crypto token (now apparently replaced with their own "Session token" instead). Anything that deep into web3 is a red flag to me, but the security flaws discussed in the above blog post look white hot.
LWD@lemm.ee · 8 pts · 1y
Oxen is the company behind Session, for anybody unfamiliar. They were a crypto company that made (well, cloned) a messaging app to promote this token.
And Oxen itself was a clone of Monero.
jet@hackertalks.com · 14 pts · 1y
Strong agree. Session is not security focused it's marketing focused. Last I checked they still use central servers for file uploads.
Melody@lemmy.one · 7 pts · 1y
Nice writeup as always. I always wondered about Session but it seems like they have the same "I rolled my own" crypto nonsense as Telegram has; and we all know how bad that one actually is as it's not correctly implemented at all; even if the underlying protocol is otherwise good.
ParetoOptimalDev@lemmy.today · 3 pts · 1y
Use simplex.
mypasswordis1234@lemmy.world · 1 pts · 1y
That's nice you're mentioning SimpleX but its design is way too complicated compared to alternatives (e.g. Signal) that no one will use it.
Even as a tech-savvy person, I was shocked that I have to scan a QR code to chat. I can't imagine how it feels for non-tech people.
As a result, who will you actually chat with? 🙂
peregus@lemmy.world · 2 pts · 1y
It would be nice to read the basic points of your statement, then if someone wants to go in detail, there's the link to your article.
noodlejetski@lemm.ee · 3 pts · 1y
it's not my article.
peregus@lemmy.world · 1 pts · 1y
Ops. However a small TL;DR would be useful instead of just copying/pasting links.
Soatok@pawb.social · 7 pts · 1y
TL;DR from oss-security:
mako@lemmy.today · -1 pts · 1y
Jesus Christ, get fucked
jaggedrobotpubes@lemmy.world · 1 pts · 1y
Thanks for the notice!
Regular Signal for lyfe.