Do you use Signal for chatting securely with friends and loved ones? Us too! We endorse it wholeheartedly, and rely on it for nearly all our communication.
But the vibes are deteriorating here in the US, and we should have a communications contingency plan for if Signal goes down.
38 Comments
Cyberflunk@lemmy.world · 17 pts · 201d
eodur@piefed.social · 10 pts · 201d
Didnt threema just get bought up by VC?
Cyberflunk@lemmy.world · 10 pts · 201d
HumbleExaggeration@feddit.org · 3 pts · 200d
How well does matrix hold up in comparison to Session or SimpleX? Maybe i have been living under a rock, but i did not hear much about them.
pineapple@lemmy.ml · 2 pts · 200d
It's a fine alternative. While not super secure it is decentralized which is nice.
The biggest problem I think is that it isn't very easy to use, I think it's a better replacement for discord rather than instant messages.
ArcaneSlime@lemmy.dbzer0.com · 1 pts · 199d
I moved away from it because:
Kirk@startrek.website · 5 pts · 201d
Got a citation for that? Genuinely curious
Cyberflunk@lemmy.world · 7 pts · 200d
Blaze@piefed.zip · 3 pts · 200d
https://delta.chat/en/help#message-metadata
https://support.delta.chat/t/reach-near-zero-metadata-with-latest-delta-chat-releases/4321
Cyberflunk@lemmy.world · 4 pts · 201d
Blaze@piefed.zip · 4 pts · 200d
https://delta.chat/en/help#message-metadata
https://support.delta.chat/t/reach-near-zero-metadata-with-latest-delta-chat-releases/4321
astropenguin5@lemmy.world · 4 pts · 200d
Strikeout might have to not have the spaces between the tilde and the words?
test test testEdit: yeah just remove those spaces between the tildes and the contents
autonomoususer@lemmy.world · 3 pts · 200d
No spaces,
seeCyberflunk@lemmy.world · 2 pts · 200d
oranki@sopuli.xyz · 2 pts · 200d
I thought Delta Chat encrypts all messages. Don't even know how to send unencrypted ones.
https://delta.chat/en/2024-03-25-crypto-analysis-securejoin
I can't say about the header stuff, but please check your statements. As far as usability (for regular people) goes, Delta Chat beats the other options by far.
SrMono@feddit.org · 14 pts · 201d
If the vibes keep on deteriorating and there would be a crackdown on messengers and signaling infrastructure a messenger is the last of your worries.
And if Signal gets specifically targeted, there will be warning signs and time to shift away.
Vegan_Joe@piefed.world · 8 pts · 200d
The warning signs are there
SrMono@feddit.org · 9 pts · 200d
Nope. That's not how Signal and E2E encrypted messaging works.
If a government asks Signal for user data they get an almost empty sheet of paper. Search for " what data does signal collect" to confirm that.
If - on the other side - your smartphone is compromised or unlocked there is almost nothing Signal can do to prevent governments from looking into your data. Also it reads like some agents simply joined a group chat. Again: nothing Signal could prevent.
Vegan_Joe@piefed.world · 9 pts · 200d
I was not suggesting that the encryption was compromised. I was suggesting that signal is being targeted.
Likely, they are infiltrating Signal groups specifically. Not through breaking encryption, but still joining these groups BECAUSE of the encryption.
The fact that these groups are using private encrypted messages are what piques the interest of the FBI in the first place. Signal is just the most popular and thus the most likely target.
SrMono@feddit.org · 9 pts · 200d
Any software used by enough people will be targeted.
iByteABit@lemmy.ml · 3 pts · 199d
Still, adding feds to a group chat is a management issue, same as inviting people to your home
Neptr@lemmy.blahaj.zone · 14 pts · 200d
OpenPGP for encryption through autocrypt is a BIG NO for me. OpenPGP is inherently flawed, read any reasonable cryptographer's opinions on it. DeltaChat is a significant security downgrade from Signal. I would much rather use SimpleX or Briar.
GaumBeist@lemmy.ml · 1 pts · 194d
I couldn't find any criticiques of OpenPGP aside from LibrePGP's. Do you have sources I could look into?
Neptr@lemmy.blahaj.zone · 2 pts · 193d
https://soatok.blog/2024/11/15/what-to-use-instead-of-pgp/
GaumBeist@lemmy.ml · 2 pts · 191d
This article was more constructive (suggesting alternatives) than destructive (leveraging critiques), but it did link to several critiques/vulnerabilities with OpenPGP.
Unfortunately, half are about implementation issues (granted, it's made more difficult to implement something correctly when it's as convoluted and all-encompassing as PGP)—which are hopefully not applicable to Delta due to their 3rd party, applied cryptography audit—and the rest are obsolesced by the 2024 updates to the standard—RFC 9580, the so-called "crypto-refresh."
Do you have any critiques that address the current state of the PGP protocol's security?
artyom@piefed.social · 14 pts · 200d
If you're in a country that is shutting down servers, then your contingency plan should involve serverless p2p apps like Quiet or Keet.
IratePirate@feddit.org · 6 pts · 200d
This is the second time I stumble across Keet this week. It sounds interesting, and yet it appears not to be open source. All I could find is a Github page where they publish their APKs, but no source whatsoever. Is it really closed source? Because I don't to "trust me, bruh" crypto.
autonomoususer@lemmy.world · 5 pts · 200d
Worse, it fails to include a libre software license text file. We do not control it, anti-libre software.
IratePirate@feddit.org · 3 pts · 199d
Well, there's no license because there is no code on their Github. They claim their P2P framework is open source. Yet, that is just the part that allows clients to connect. But I also need to check that what is transferred through that connection is truly encrypted. And if there's no code, there's no basis to even develop trust.
autonomoususer@lemmy.world · 1 pts · 199d
'Open source' misses the point of libre software.
Blip6338@lemmy.ca · 13 pts · 201d
The reticulum project with the Sideband client is probably a lot more censorship resistant than DeltaChat or Meshtastic.
jet@hackertalks.com · 11 pts · 201d
https://eylenburg.github.io/im_comparison.htm
Falling back to email isn't a most preferred backup, I'd rather do simplex
eodur@piefed.social · 9 pts · 201d
If Signal gets blocked, why not use a Signal Proxy?
artyom@piefed.social · 8 pts · 200d
You can use all the proxies you want, it won't matter if the servers are shut down.
raicon@lemmy.world · 5 pts · 201d
matrix.org is my new favorite
Calmarius@lemmy.ml · 3 pts · 200d
You can move to any other service, but once it becomes popular enough to draw attention they might also get blocked as well. If it's centralized, then the central servers can be blocked and it's not longer working. If it's decentralized and peer to peer, then the bootstrap nodes can be blocked and it's no longer working.
Even if it's self hosted and not advertised, the adversary can run active probes to detect banned services and block it if it detects any.
The only thing that can work reliably is something that can be concealed and can't easily be detected.
A simple HTTPS website that runs a small blog, forum or an image board, can have a lot of bot traffic, and human traffic that makes the traffic analysis hard, it also provides plausible deniability if someone asks why you visit that site often, you can say that you are playing games or browse images there. Such website can have a secret interface that can be used as an interaction point for secure chatting (in a store and forward manner), which responds only if the requests are cryptographically signed by the participants, otherwise the server can play dumb and show a 404 error. Therefore an active prober can't easily detect that the website hosts that interface the first place, because they cannot produce a signed request unless they manage to compromise one of the participants.
Threat analysis:
Someone should make an app that works this way. Only one tech savvy person of the given group need to set this up (preferably someone who alredy have a website), then others in the group can be invited into it and can use it without much friction.
la93@thelemmy.club · 1 pts · 192d
Good idea. (Also "server not found" on your link.) Here for the info. Please mention if these methods allow for video and voice calls.
Alb@sh.itjust.works · 1 pts · 201d
take a look at Jami.
enterpries@sh.itjust.works · -10 pts · 200d
Does Signal host its user's data?
Not sure why privacy-conscious people would be recommending it over something like Matrix. Unless they're paid off or stupid.
WhyJiffie@sh.itjust.works · 5 pts · 199d
it does not. and the reason is, matrix clients and servers are fucking unstable, and spam is still an unsolved thing.
enterpries@sh.itjust.works · -2 pts · 199d
I've never experienced either of these issues.
WhyJiffie@sh.itjust.works · 1 pts · 198d
I'm still a user, I experience it frequently with element x, but old element was no different in regards to that.
pucker4676@lemmy.ml · -1 pts · 199d
I like matrix as well.