To be honest, privacy in a general-purpose messaging app is the least of my concerns, as I have other means of sending important messages to select people. What is really annoying about Whatsapp is its extreme device dependence* which forces me to depend on a single device for casual chat with friends, family and acquaintances (and not the most comfortable use one) when multi-device messenger apps have been around for more than a decade. Telegram is like a return to sanity in this respect, so any news about Telegram invading Whatsapp's space are great news to me.
*I say "extreme" because Whatsapp doesn't even like if you switch your SIM card from one phone to another. It's insane. I used to have two phones (one for regular use and a cheap old one for activities where it could get damaged easily) and I had to give that up because Whatsapp would force me to re-register every time I made the swap.
You know you have to do that only once yes?
The hard problem of messaging has not been solved yet, what people should build is a service like iMessage but with the public key pool per account publicly auditable and verifiable.
It reminds me a bit of the CAP-theorem: Security, Device Sync and Usability. Pick two.
My personal preference is solving DU, because I can do security aware stuff with GPG.
The problem is that the key pool is in Apple's hands. You cannot guarantee that they don't go and add a key do the pool and get all your messages anyways.
Seems like a low effort solution and would not satisfy my requirements, but it probably works for some people.
Edit: just verified. Phone is in flight mode and chatting away on signal-desktop works just fine.
[0]: https://gist.github.com/TheBlueMatt/d2fcfb78d29faca117f5
1) Your keys are safe (device was encrypted and/or you've wiped it remotely, whatever). In such situation you could be able to transfer keys from S-Desktop to new mobile. AFAIK there is no such functionality yet (remember, its Beta).
2) Your keys are not safe. In such case no recovery is possible. Notify all contacts about the fact that they should "reset secure session", forgetting your Signal identity and establish new Signal identity.
Anyway, this is the only solution on market with secure chats and multi-device sync.
I basically don't need other communicators right now for close family and part of my friends.
Occasional video call can be made using other platforms.
That unnecessary limitation really disgusts me, since I am the type who deletes his whole chat history weekly because I don't want to carry it around with me in case of another targeted stealing attempt. I'd love to integrate my whatsapp xmpp account into pidgin.
I've never used multi-device sync, ever. Not on iMessage, Viber, WhatsApp, ... The only one that I use across devices is Skype, but I don't use it except for video.
Sadly at the moment that's only WhatsApp and Telegram to some extent. If only there would be some protocol or standard that would allow me to communicate across different providers.
But unfortunately such a standard must be technologically impossible, otherwise it would be implemented and widespread already.
They just want a pretty GUI, their friends to be on it, and an easy way to send videos/photos/voicemails/whatever.
Granted, I've never wanted to send videos and sending photos works well on Signal right now. But until recently the GUI wasn't very polished.
In fact, Brazil's most popular chatting app that is recently banned there doesn't have multi-device sync. Hangouts does. Everyone could use hangouts, but not nearly as many people do.
Multi-device sync and privacy-awareness both are maybe reasons for a few individuals to switch but they both have problem with the number one feature of messengers: actually reaching other people.
Why something gets adopted is way more dependent on soft factors than on technical factors, as long as the basic requirements are satisfied.
Huh? I don't think this is correct. WhatsApp is huge in Europe, nearly everyone I meet prefers to use WhatsApp over SMS yet almost everybody has "unlimited SMS" plans.
I know only 1 guy who uses Signal and he is an AT&T systems administrator and linux addict. He understands the difference. The rest, use either iMessage or Telegram and don't really care about the rest.
Even if WhatsApp weren't using end to end encryption by default, they would have no way of complying with government requests like this one, because they simply don't have the messages. Telegram, on the other hand, is a surveillance dream.
My understanding of the Whatsapp end-to-end-encryption is that the use of the term is completely misleading, as the "ends" they are referring to are the client and the Whatsapp server (https://www.whatsapp.com/faq/en/general/21864047). Unless you know otherwise, I take that to mean the communications are in the clear at Facebook, and in my estimation that's tantamount to piping them straight into the US surveillance machinery through whatever they call PRISM these days, or some more or less distant relative of it. (This arrangement would still offer protection from bad actors that don't have some form of easy access to Facebook's internal information).
Both seem like dreadful options in absolute terms, but if we're comparing I'd slightly rather have that user base in the hands of someone possibly sincere and incompetent than with someone competent but almost certainly treacherous. At least there is a sliver of hope for improvement and, who knows, maybe once they're off the paved road of Whatsapp they'll wobble their way though other alternatives to something like Signal eventually.
Since we're fortunate enough to have you here anyway, would you mind commenting on how Signal would fare under a similar blockade? https://news.ycombinator.com/item?id=10750898
Would the service be taken down? Do you consider it a priority to try making it difficult to block in the default configuration?
That structure seems enlightening to understanding how Telegram has been able to create clients for so many operating systems in a relatively short time.
What I'd love is if they could also make it an email client too. Letting me send/receive insecure emails or (if the recipient has Signal) encrypted email using the same key management. I'd much prefur to give out an email address (totally in my control) than a phone number (could be taken away from me at any moment).
One digital communication app please.
Can Signal be taken down like WhatsApp if the same happens again in the future?
In principle, since both the Signal client and server are FLOSS, it should be possible to resist a block in some ways that might not be so easy with for example Whatsapp, but as far as I can tell, as things stand right now there is no built-in way to switch server, and asking millions of regular people to make changes to the source code of their cellphone software, recompile and manually reinstall does not seem like a recipe for success. I wonder if one might sensibly work around these things by fallback/optional connection to the server through Tor if Tor is available on the device?
It sit on the top of a close-source browser...
[0]: http://www.theregister.co.uk/2015/06/26/googles_not_listenin...
And I am! I can't wait for Novena! Also notice a difference. Having a close-sourced CPU is different than having a close-source browser which has much more possibilities to compromise you. It can start camera, microphone, read disk files, locate you and transmit everything to "cloud".