As far as I know, the only app that fits this requirement with a minimum viable community such that it can be used day to day is Signal.
As far as I know, the only app that fits this requirement with a minimum viable community such that it can be used day to day is Signal.
- Is being open source, and some eager and independent security researchers having done an audit enough to convince you (or some other well-informed part on the thread) that no clever flaws are intentionally in the source?
- Do the funding or institutions which support the development of a piece of tech change the answer to the above question? E.g. I've been encouraged to avoid Signal b/c it was created partly with US State Dept funding (via the Open Technology Fund). The main point made during that conversation was that the US supports projects like Signal and Tor as a means of supporting dissidents in other countries. But a side implication was that it may be naive to rely on tools (indirectly) provided by the state to avoid surveillance by the state.
Another positive is Signal have been very intentionally slow and transparent about security considerations when it comes to adding new features (gif search, link previews)
Telegram appear to be more focused on feature parity with competitors than "crushing the core" of secure messaging