Based on all information out there, in year 2020, what is the most secure IM app?
What do you recommend to your friends if they care about privacy?
Based on all information out there, in year 2020, what is the most secure IM app?
What do you recommend to your friends if they care about privacy?
Matrix is interesting and I hope it will catch up eventually, but currently it is not E2EE by default and it leaks way more metadata than Signal. These point make it strictly worse than Signal for 1:1 IM.
The advantage of Matrix is in federation, but regarding privacy / security, it is still behind (much to my regret).
Other apps that could provide similar guarantees in theory are less used and have received less scrutiny, so more not yet exposed bugs and design flaws should be expected. Other apps have been relatively well studied, but have well-known design flaws that also make them worse than Signal (WhatsApp and Wire leak way more metadata).
Bear in mind, the server is open source only in name, the state of documentation and configurability is extremely hostile towards running it yourself, to the point that the only way to configure it to run correctly requires reading the code to find the type, size, syntax and everything else about every piece of configuration because none of it is documented or clear.
I did this as part of my day job, which included, at the time, documenting it. It's impossible for me to share that documentation I did on company time. As for doing it again, I'd have to check my contract and/or discuss it with said employer.
Matrix is significantly less proven, leaks a bit more metadata (at the moment) and has had a few incidents that make people cautious about trusting it for real activism -- but it's a more future-proof investment if you're not currently an activist, and some of the stuff they're working on (most recently around P2P and mesh networks) may be really valuable in the future.
Matrix is taking an explicit stance that concepts like federation and custom clients are not antithetical to privacy. It's yet to be seen whether they're right about that, but a lot of us want them to be right. We'd prefer to live in the world that they describe.
Apps like WhatsApp and Telegram also exist, and I guess some people like them, but I don't see any reason to bring them to the table since Signal already exists and is already the gold standard for privacy. The only reason Matrix is on the table is because Matrix is fundamentally different from Signal in ways that are worth caring about.
So in short:
- If you really need to make sure nobody reads your messages, use Signal. Hands down, not even a contest.
- If you're invested in the future of apps like this, and you have auxiliary concerns around federation, openness, and bridges that might outweigh your worries about potential vulnerabilities, then consider using Matrix.
Nearly all of these apps are better than doing something like encrypting an email. Email encryption is a minefield of insecure clients and foot-guns.
In addition I have a private mattermost server, which is heavily restricted in terms of firewall and users but this is reserved only for a very small selected group of people that I trust and I am 1000% sure that they know what they are doing.
Unlike Signal, it does not rely on a single server.
[0]: https://www.reddit.com/r/privacy/comments/gukg5z/threema_win...
Well gouv.ch might, but Crypto AG was an NSA front for decades so I wouldn't be so certain about the companies.
If I wanted to lure people in on the pretence of security and privacy, Being Swiss would be good bait.
Can someone explain the downvote? I am not complaining but are there security problems with it? Could you explain or highlight them?
Secondly, you were probably downvoted because you didn't add any content to the discussion other than a link.
Session goes a long way to fixing Signal's problems like its reliance on a centralized server and phone numbers but it's still very early days with an unproven product. Messages still get lost all the time and if you thought it was hard to find your friends on Signal, it's the Sahara Desert on Session. You'd be putting in months and months of fervent pontification to friends and family you've probably just managed to migrate to your other privacy chat platform of choice.
The new XMPP hotness is OMEMO. Conversations is a good mobile client that supports both PGP and OMEMO.
OMEMO is five years old, and supported by all major clients, so it's not very "hot" anymore".
OTRv4 is somewhat hot and new. It's not in wide use (yet) and it's unclear if it is enough of an improvement to take over.
No. OTR depends entirely on fingerprints for identity. The poster was referring to the difficulty of knowing for sure that you are really end to end. PGP has the advantage here in that you can be completely sure because you can exchange the keys yourself.