In short, I just don't know what to use.
Edit: Session looks great but is not fully released yet: https://getsession.org/ This might be what I'm looking for in the future.
In short, I just don't know what to use.
Edit: Session looks great but is not fully released yet: https://getsession.org/ This might be what I'm looking for in the future.
I would strongly advise against picking a tiny new-comer without some serious research beforehand... They're not battle-hardened, so will typically be less reliable than any of the existing larger players.
What if someone registers with my old number?
If someone were to register with your old number on a new phone, then they will have an empty message history. Your contacts will also be made aware of a safety number change if they start messaging with the old number.
https://support.signal.org/hc/en-us/articles/360007062012-Ne...The app is easy to use, but people are not using it. They use sms and FB etc. to message friends.
Most importantly, you can host the server yourself without cutting off from the network.
...Including the unstable frenemy-guy who was only in my contacts so I'd recognize the number if he called and I'd know not to answer...
....who immediately PM'd me on Signal to push his latest delusion and make sure I didn't disagree.
Great, just great. For a privacy-focused product, that's a pretty colossal fuckup.
Your local Signal installation regularly checks if any of your contacts (with the phone numbers you have of them) are registered at the Signal servers - and then lets you know it, such that you can text this contact securely.
Many people might have my phone number, possibly from a long ago. But the number itself is pretty safe -- there is no way to tell if this phone is in use or not.
Signal breaks that assumption -- it immediately tells every other user that this number is alive, valid, and can be contacted right now.
This is a terrible idea to do by default, especially if one cannot disable it.
This is all based on your address-book so it doesn't matter if the other party knows your number or not.
A check for "aliveness" of a number can be done without Signal. Just call and see if it is ringing. You get the same information. Your Signal profile name and picture, however, will only be shared when you accept it.
Anyone who says Signal has good privacy is just wrong. When Signal say they have good privacy, that's false advertising.
Of course, Telegram does the same thing. I have Telegram installed, and I use it, but it wasn't really a choice. I needed to access a forum which is only on Telegram :/ Unfortunately that meant I had no choice but to have people who know me notified that I installed it. Someone messaged me about 30 seconds after I installed it to say hi. I'm not comfortable about this, but as I say, I didn't really have a choice.
Then there's WhatsApp. I was surprised to read an article which recommended that, of the three, WhatsApp is probably the most privacy-respecting of the apps. I have WhatsApp installed after a long period of avoiding it, because of all people recruiters started expecting it. Hmph. I still refuse to grant it access to my contact list, because I'm not handing that over to Facebook. Which means every message is associated with a raw phone number only, and I have to guess who it is from the content :-)
You can tell WhatsApp doesn't reveal so much, by the people who have sent WhatsApp messages without being told that the recipient doesn't have WhatsApp installed and won't see the message. I've known a few people this happened to. One installed WhatsApp and found they'd been sent a message a year earlier, from someone they thought wasn't talking to them. They were talking, but the sender assumed of course the recipient would have WhatsApp.
All three of Signal, Telegram and WhatsApp make me a bit off about using them for various reasons. None of them are what you'd call "user's privacy first".
As it is, I'm currently having occasional confidential chats (at someone else's request) on Telegram secret chats, and at least that probably is what it says it is.
I don't think any of these three apps are awful.
They are pretty slick, and useful.
I don't feel too bad actually using them, any more then using say MSN, Yahoo or Freenode.
They just don't meet the advertised bar of respecting individual privacy first. And I find that really misleading in the case of Signal and Telegram in particular, which emphasise the privacy angle, and then without letting you know, sprays everyone you ever interacted with outside Signal with a notification, including professional contacts, customer service agents, people you don't like, spammers, etc.
However, all of these bloody messengers mean that my contacts list is spread across a multitude of programs: we need the iOS/Android equivalent of pidgin.
so is regardless of user count
Edit: Generally, Threema seems interesting feature-wise, but I think the price (4€) will prevent my contacts from using it...
Can someone elaborate?
The second one is more difficult to evaluate. If you use the above mentioned "secret chat" feature, Telegram employs their own closed-source encryption scheme. That's usually an indicator to be cautious from the get-go. Since it's closed source, it can't really be trusted.
See [Wikipedia](https://en.wikipedia.org/wiki/Telegram_(software)#Security) for a timeline in regards to the security.
https://telegram.org/apps#source-code
Encryption for secret chats doesn't involve server, so technically it can be analyzed.
It's a pity Telegram decided to roll their own encryption scheme. I use Telegram a lot for daily business because it's superior desktop messenger product. I would gladly participate if somebody started a crowd-funding for Telegram's security and encryption audit.
Except if you are on desktop, you have no secret chats at all. And "desktop" includes GNU/Linux phones.
I've also had terrible reliability issue with imessage in the past, messages not delivering, not showing up, errors sending, showing up on one device but not another, etc. Was a mess that caused a lot of confusion.
Which isn't end to end encrypted which defeats the whole point in terms of this conversation.