[1] http://techland.time.com/2013/08/14/google-says-gmail-users-...
[1] http://techland.time.com/2013/08/14/google-says-gmail-users-...
It uses the same crypto as WhatsApp (same developer), but values your privacy and has properly working audio calls - better than WhatsApp in my experience.
It's essentially WhatsApp minus Facebook. And it's open source.
The company (and person - Moxie) behind Signal, OpenWhispherSystems, worked with Google and Facebook to add end-to-end encryption to Facebook Messenger, Google Allo and WhatsApp. It's literally the same protocol and Moxie is a highly regarded cryptographer / security researcher.
Telegram, which some are suggesting, has encryption as opt-in and their encryption scheme has been widely criticized for being dodgy (see: https://moxie.org/blog/telegram-crypto-challenge/).
There's a table comparing Wire and other systems here. [2]
I still have Signal and update it whenever there are updates, mainly to see what's new or changed, but prefer Wire for the better feature set and UX. Telegram still remains my most used messaging client due to its UX and speed (even Wire is slow and lacks some basic features like message delivered and message read indicators).
I've been waiting for a long time to switch to Signal (or to Wire), but the improvement seen is quite slow over time (just my experience). Telegram has been moving rapidly on feature addition.
[1]: https://wire.com
The thing is, as long as we're using phone numbers as user handles, you have to trust the provider with your phone book. Signal tries as hard as possible to avoid it (all phone numbers are hashed), but if they wanted, they could simply brute force all the hashes since the search space is so small. There's no good solution to this.
I ask knowing very little about their security model.
It seems like we (most humans who use communication devices) are doomed to be stuck in advertising-based-single-corporate-walled-garden solutions.
They don't have to - Open Whisper Systems is a non-profit with strong community support. It works out so well that they actually pay any contributor a few dollars per commit. That's the best monetization there is for an organization which serves the community.
I like the idea, but don't know of a good method to get my contacts to use Signal as well without making myself look extreme in my views. Any suggestions for this? For example, do you know of any short and crisp messages that get the point across, without getting into a never ending discussion of privacy and its value?
My advice: Except Telegram, none of the others (Signal or Wire) are ready as a replacement for WhatsApp in UX or speed as of this moment. But Telegram has end-to-end encryption only for device specific, one-to-one chats (called "Secret chat"). Normal chats are only encrypted during transport and are stored as plain text on the servers and on the devices to support quick searching and multi-device/multi-platform sync.
Secondly, Signal does not have multi-device support and multi-device sync. Coming from Telegram, where I can catch up on messages on multiple devices and choose to switch to a computer keyboard to respond with longer messages, as opposed to a small touchscreen keyboard, I very much prefer having the ability to use different systems. Signal's desktop "app" is just with Chrome and AFAIK, it needs to be authenticated every time (with Telegram, I authenticate my desktop app once and it works fine across restarts). It's still tied to one device (the phone).
Wire allows users to signup or find other people using phone number or email address. Even Telegram depends on a phone number as the sole identifier for a user.
Overall, none of the current set of messaging apps or platforms are extremely appealing to me. All of them have some drawbacks. My dream platform would be a "decentralized and federated" system like email without having to be in individual walled gardens.
One checkmark: delivered to server, two checkmarks: delivered to recipient. Works for me.
> Secondly, Signal does not have multi-device support and multi-device sync. > Coming from Telegram
Telegram has, to my knowledge, either end-to-end encryption or multi-device sync.
The way it works with WhatsApp and Signal is that your key is generated on your phone and never ever leaves it. The web client actually establishes a connection to your phone and routes all messages over it.
Now, the Axolotl ratchet protocol does support encrypting messages to multiple keys (it's what they use for group chats), but doing it properly requires time and effort in order to remain secure.
wire.com/privacy for security whitepaper.
For me, multi device support is not important since I have my phone with me all the time, and if I'm on my laptop there's the web client.
Apparently XMPP with Conversations + OMEMO provides secure multi device support, haven't tried it though and I'm not sure if I could get any of my non-tech friends to use it.
After some of my friends swiched a few groups, switching has happened naturally group by group since Telegram arrived and today I just have to struggle with my siblings and a local group that also contains a number of elderly people that I won't force to change.
(For those who are not aware Telegram is dimilar to Whatsapp but with less focus on formal verifiable crypto but with other advantages like not-owned-by-neither-Facebook-nor-Google, simpler anf more powerful UI, opensource, a choice of multiple clients, better desktop client, bot API etc etc. The lack of verifiable crypto is still an issue but as long as Facebook owns Whatsapp it seems crypto doesn't help too much :-/ )