I hate having to rely on my phone for texting people.
Whatsapp's web client is just an UI to the mobile app meaning you also need to have phone connected to internet always for it to work.
Telegram is much more responsive compared to the Whatsapp.
umm... citation needed?
There's an open $200k bounty for years now. Some "expert in the field" (who just happens to work for not one but two competitors -- yes, I'm looking at you, /u/moxie) posted a blog post right afterwards, about a competition not being the same as a proper design / security audit, and that's correct. But I've seen people try and fail over the years: the crypto holds. Moxie and co would have loved to see it fall too much not to have had a stab at it, never mind the bounty, but apparently they failed.
I think the e2e in Telegram is solid. If you're really paranoid about some file in particular, you can always send an encrypted zip or GPG encrypt it -- I'd recommend that anyway, since otherwise your chat's encryption keys (which are in use all the time, thus quite easy to get at) also unlock that sensitive file.
> For non-phone related use I'd go for Wire https://wire.com/en/ encryption wise.
I would recommend Wire.com too. This needs more awareness, since it does everything we've ever wanted, has the protocol everyone seems to support, is open source, works on all popular platforms, etc. Except nobody uses it, so the network effect is not there :(
I'm a Telegram user (because network effects) and I agree it's a fast, slick app with both good mobile app and web interface, but I do not expect it to be secure.
Depends on your standards and your use-case. If you message from your phone most of the time, you can open an encrypted chat[1] with someone and it's properly encrypted.
If you use desktop too a lot, then this doesn't work because the desktop client doesn't support end to end encryption. In that case, you're at the mercy of them not reading your messages. Pretty much the same as with WhatsApp (closed source), Facebook messages, and virtually every other chat application out there.
(Except Wire.com, by the way: they're really cool but nobody uses it, so no network effect there unfortunately. I wish I had a good reason to get people off of Telegram except for "maybe some sysadmin is laughing at your jokes too".)
[1] the application calls it a "secret chat", and recommends people not to use the terminology encrypted chat "because all their chats are encrypted" (yeah just like https: until they're in your datacenter, no matter what they claim). So I'll use the proper term instead of the marketing term: encrypted chat.
The advantage over Signal would be that 1.) you don't have to share your telephone number and 2.) you don't rely on a single service provider/accounts are decentralized (there are various services for free and paid accounts and you could also host your own server)
e: Dear stranger, I'd be very interested in an explanation for your downvote. thanks!
https://www.jabber.de/clients/android-ios/conversations-guid...
But I agree: it should be even simpler to set up.
Conversations could go even further and hide the XMPP details, connecting to (or creating an account on) a default server, and have the "advanced" settings behind a "I already have an XMPP account" link.
Push notifications aren't magic -- they also have to maintain a consistent connection to the server, and re-activate it after a sleep. What having a push notifications provider like Play Services does is let you keep just one connection open for all apps. But adding just a few more doesn't make a big difference.
I also have an IMAP IDLE connection open all the time (K9 Mail), and it doesn't move the needle, either.
https://conversations.im/#optimizations
Those extensions are pretty standard stuff nowadays. Here you can find an explanation with a few more details (section "Battery drain"):
I'd also suggest Riot/Matrix along those lines.
Overall, I feel much better than to use some data hungry WhatsApp or some walled garden Signal app. Yes, it is a little more complicated to setup, but in the end it works as good as the others (e.g. in terms of energy consumption) and you don't have to worry about some company having different plans than you.
PS: While I sympathize with the decentralized nature of Matrix I still like the XMPP clients better.
And this is quite literally true. It really only is a little more complicated. This is not a handwaving statement. You don't need any technical know-how to get Conversations running. It's only the fingerprint thing you have to explain to people who are not tech-savvy. But if you hit the right tone they'll have no problem with that either.
- Explaining decentralization aka. 'Its like E-Mail: you need an address'
- Choosing a good provider (reliable to stay for some time, server features)
- Registering an account (many providers require a registration via browser)
- Obtaining Conversations:
-> Play store: and pay for it - 'yes, its worth it and you support the development'
-> Fdroid: free, but more complicated
- Adding contacts (as Conversations doesn't scan your address book you have to do it manually)
- Enabling OMEMO (not enabled by default)
- Adjusting settings as some default settings are kinda weird (e.g. disabling green background of encrypted messages, show online status, enabling confirmation of receipt)
So to solve those issues I have a few Ideas:
Provider selection: The App could score all available providers (important features, years of service), sort by score and let the user select the desired domain extension. Afterwards it could perform an in-band registration (it already does so if the server supports it).
Price: While I find the app totally worth its price, I think it hurts the adaption to some extent. So if I could decide it, I would make it available for free and see to make the money somewhere later in the customer journey, as setting the price up-front kills the network effect.
Contacts: Actually, I do not like it when Google & co. scan my whole address book and send it to their servers and keep it there for future use. But think there could be some compromise like: I can decide to publish my own address as a hash to some central service and use my address book to ask if someone else has registered the address (rate limited). Yes, you would still have to trust the central service to some extent, but that should be an acceptable and completely optional way of contact discovery.
OMEMO: Should be enabled by default.
Default settings: Maybe some day I will create a pull request.
While this list looks kinda intimidating, using Conversations after the installation is pretty much the same as WhatsApp/Signal.
Yes, I completely agree. I couldn't understand why it isn't default either.
As for the other points, they're all true but like you say yourself they are no show stopper especially since most people have at least one friend or family member who can assist them. People who don't understand technology have resorted to those who do for decades. Getting an e-mail adress and configuring an e-mail program was no more complicated 10-20 years ago. It's a matter of minutes to set everything up.
The adoption problem isn't one of technology but mindset. If there were a heavy marketing department behind Conversations it wouldn't be a market leader but the market share would increase significantly.
So yes maybe for ultra secure comms with specific parties, but useless as a day-to-day solution.
Then, when they send you a message from it, the message will be E2E because you have Signal installed, too.
I have also noticed that even phone calls to the other side of the world are crystal clear, really nice.
It works a lot like WhatsApp so I don't think anybody has been confused by it.
One resolved issue that impacted usability was they used to send pics from the selector screen without confirmation, and this resulted in some funny/awkward situations in group chats.
Winning people's confidence back is not easy to do, but they have done a remarkable job.