Curated List of Privacy Respecting Services and Software
github.com
github.com
> Alternatives:
> Signal - Uses Signal Protocol.
Pretty sure both WhatsApp and Signal both use the Signal's crypto for encryption, and both "suffer" from the same "design defect" / "usability improvement".
That said, I still think WhatsApp only encrypts text messages E2E, and doesn't bother for videos/photos/anything else, based on how efficiently it forwards videos compares to sending them for the first time (accounting for video conversion time), so I'd still put WhatsApp in the bad list, but not for that reason.
Being owned by Facebook is enough of a good reason in itself at this point too, mind.
EDIT: Just read through the full list. This is superb. Thank you for putting this together!
EDIT AGAIN: Just read through some of the comments, Iridium in particular is what got my attention as awesome, prior to learning that it's not been updated in 5 months, which is beyond dangerous given the number of security fixes that will have come out in that timeframe. Sad times :-(
Also I agree with you on WhatsApp. I mention now that it does use Signal protocol. However WhatsApp sends user's entire contact books to their servers as well as them logging all the metadata around messages which is very revealing.
Same goes for Siri AFAIK - I don't personally have any use for it, but it's a feature of the iPhone that you pay for and isn't ad/targeted ad supported.
Also, the last update for iridum (one of your browser recommendations) was over 5 months ago. That's dangerously out of date for something as exposed as a web browser.
> - Windows - [Microsoft shares Windows 10 telemetry data with third parties](https://betanews.com/2016/11/24/microsoft-shares-windows-10-...).
In the citation:
>Update: Microsoft says that the deal with FireEye doesn't involve the sharing of telemetry data.
Maybe fully check through your sources next time?
Of course I am, but I'm okay with a more honest business model: when I type the words "wallaby porn" into their website, they'll show me ads from people who have bid on those words. (I assume there is porn for that, because there is porn for everything. I don't really want to know.) When I later search for "crosscut saws," they'll show me ads for saws, and not try to "retarget" me with wallaby porn, or mountain bikes, or whatever else I once browsed. They won't become a world-bestriding colossus, but they can make an honest living showing ads next to search results. I remember a company that used to do that. Name started with a "G".
I changed the link for Windows. When I saw this source, there was no `Update` clause. I don't use Windows myself so not sure what I should add there instead and what category I should move it to. From what I know, Windows shows you ads in the OS itself which I find absurd.
But I am open to ideas on how to improve the list.
You could start by making all of the entries link to some 'proof' on why the service is either privacy respecting or privacy breaching.
On top of that, some alternatives require significant efforts to set up and you should order them by technical level and resources required.
You should also include the license of each solution proposed.
Note that self hosted software is already compiled in a much more extensive list:
I like these kinds of list, though, as I sometimes I learn about things I didn't know existed.
I will be so sad if it's as bad as Whatsapp in privacy department :(
From here https://telegram.org/faq#q-how-are-secret-chats-different
""" Q: Why not just make all chats ‘secret’? All Telegram messages are always securely encrypted. Messages in Secret Chats use client-client encryption, while Cloud Chats use client-server/server-client encryption and are stored encrypted in the Telegram Cloud (more here). This enables your cloud messages to be both secure and immediately accessible from any of your devices – even if you lose your device altogether. """
They claim that it's encrypted, but that uses a different kind of encryption.
Maybe this has changed recently?
The quality of the text is btw very questionable and dubious as e2e encryption has nothing todo with where the message is stored. See email where your gpg encrypted message is stored on a lot of systems on its way to reach its final destination. This text makes me distrust Telegram even more, thank you for sharing this!
I am on your side regarding Telegram though and that's mainly because of using non encrypted chats by default and not having encryption for group chats which is just unacceptable in this day and age.
1. localhost (depending on your OS)