[1] https://en.wikipedia.org/wiki/Signal_(software)#Encryption_p...
[2] https://threatpost.com/signal-audit-reveals-protocol-cryptog...
[3] https://eprint.iacr.org/2016/1013.pdf [PDF]
[1] https://en.wikipedia.org/wiki/Signal_(software)#Encryption_p...
[2] https://threatpost.com/signal-audit-reveals-protocol-cryptog...
[3] https://eprint.iacr.org/2016/1013.pdf [PDF]
Shouldn't it be possible to delete your whatsapp chat and contacts data regularly from the cloud? Eg. one could delete the whatsapp account, clear data on cloud and make a new account again. Having more control over your data stored by Facebook would give more power to the users of enforced by the government.
They’re for aggregate metrics and attention collecting on the part of the company.
I do not have a Facebook empire, Twitter, TikTok or other social media presence.
I email academics I can’t visit.
I group text friends and family to make plans, and use the calendar built into my phone to remind myself of those events.
The reality is that WhatsApp is a requirement for social life. Any solution that doesn't start from that point lacks any practicality.
I get social inertia is a thing.
Somehow I’ve blown it off and life still works.
Summarizing it as “life begins and ends with WhatsApp” seems just as ridiculous to me.
Acquiesce and nothing changes.
Turn and face the strange.
If you are already well connected with your peers and friends and your social life doesn't depend on finding and exploring via the "social apps" sure you have the freedom to disconnect virtually and still remain connected socially.
All my family members live in a different country and there is no good medium for communication than whatsapp.
Spike on iOS is a client that wraps email in a chat like UI if the people are free to chat real time. Not sure if it’s on Android.
There a numerous video chat sites not connected to Zoom, or FB properties
whereby, etc
I gave my family an ultimatum and being the tech savvy one they jumped to Signal
Social inertia is a thing conceptually, but it’s not gravity. It can be bent any which way
Not all families respond well to ultimatums.
While that is true, what you have not accurately determined is why that value is low, and how much of that is your doing vs theirs.
If you're not in one of those countries, then I don't think you can speak for what a social life there is.
If I tell people they can only contact me via snail mail or in person (i.e. not have a phone at all), would you find it surprising that I will have a lot less of a social life?
Even 15 years ago I knew people in countries who had a difficult social life because they refused to use SMS - this was before the era of smart phones.
> HTTPs works with email, email works over data networks.
A lot of younger folks do not use email except for signing up for stuff and official work. When I left university a decade ago, many incoming freshmen were quite upset at the requirement to use email.
You can always have some social life, but in certain locales and circles, whether you use these apps or not will affect what type of social life you'll have.
> Acquiesce and nothing changes.
Sorry, but these types of statements are usually of little value, and only sound good. I could easily write:
Resist and nothing changes.
And it will likely be as true (and similarly lacking in entropy) as yours.
I've never owned a cell phone nor ever had a social media account in my life. Sure, it gets me the occasional eye roll but trust me, my social life is just fine.
Caveat: old person speaking.
In other words: even though cell phones and social media were around when I was younger, they didn't play the central role they do today, so presumably it was much easier for me to do without them and still have a normal social life than it would be today.
Here's a sad thought experiment though: if you can only remain an active part of your circle of friends if you use the same technology as they do, what does that say about the depth of that friendship?
When everyone was using SMSes to chat, how did the kid that did not have a phone felt? And people were social before phones existes too.
I think that being outside of the main mean of communication is going to have an impact on your social life, independently of what the medium is
There you have it. Class of 1950 uses letters to organize itself. Class of 2000 uses e-mail. Class of 2010 uses Facebook. Class of 2020 uses Tiktok or idk snapchat.
And this issue isn't just about your class, it also includes any peer group of any kind. For me as a 20s something, the choice is quite binary.
Nowadays you can't even participate in free software communities without using proprietary services. Many free software projects have discords instead of community run matrix or IRC instances.
Hey, I might be old, but I still live nowadays too!
I've had the joy of trying to explain to my elderly dad why his text message history is lost because he chose Signal as the default sms system, didn't make a backup, didn't sync that backup to the cloud or manually copy it to the new phone, and didn't write down the very long decryption code.
The usability issues for non-tech people have been getting less and less in the past years which is keeping my hopes up.
If people won’t go to the trouble of using an alternate way of getting in touch with you then they’re not really your friends.
If people won’t go to the trouble of using your preferred method of getting in touch with you then you don't have enough social clout.
Then there are also many organizations/companies that use Whatsapp to set appointments, for chat support, etc.
In many EU countries Whatsapp is pretty much replaced SMS. Only a small minority of folks have Signal or Telegram. iMessage is probably the only other thing that shows as a blip on the radar, but only a portion of the population has iDevices.
I agree that this is a bad situation, but WhatsApp became popular when it was still independent and their profit model was charging 1 Euro per year (which was much cheaper than SMS). Now abandoning Whatsapp is difficult due to network effects.
Make it happen.
Be the change you want to see.
Telegram's backend is closed-source.
Someone that needs a special set of phones to be able to communicate securely and not be reliant on a publicly run server? Here's a non pointless use case.
I'll let imagine who might run something like that.
Don't get me wrong, I love Riot (or whatever it's called these days) but it's just not user-friendly for your average Joe...
We've actually witnessed that people _are_ willing to pay for streaming services like Spotify and Netflix after a long time of illegal torrents. How can we spread this sentiment towards services like email and chat too?
I remember vaguely getting convinced by a friend, "you just payed [200,300,idk]€ for that new phone, can't pay one euro for this one app?"
We can't, because those two things are in direct opposition. Piracy was less convenient and offered fewer features that people wanted, so they moved to platforms that were more convenient. The current giants (Gmail, Facebook, WhatsApp...) are more convenient than their alternatives (generic email, Mastodon, Signal...) and so the pressure is not to move, but in fact to stay.
In general, the pressure is always decentralised->centralised, which is exactly what torrents->Netflix was. Even if we had infinite funds to offer people distributed services for free forever, we would still need to make them more convenient than their current centralised ones - if on top of not being more convenient, we also want to charge them, I see no reason why the average person would ever want to switch.
Maybe there's some space for a freemium model (IIRC one of the questions asked during the Facebook hearing was whether they could add a paid ad-free option) but so far that hasn't happened.
I guess Matrix is doing this, but unfortunately, the way history has played out, centralized IM had first mover advantage by a huge margin and that's what people are used to now - that a messenger is an application on your phone that you can only use to contact other users of that same application.
And unlike Signal, you can host your own server (Synapse) instance and be truely independent with the ability to join the federated network.
EDIT: To the people downvoting this: I said the same thing a long time ago about whatsapp before Facebook bought them.
However I'd also promote federation-first services like Matrix. Only issue with Matrix is the e2e being so clumsy IMO
Even moving from Fb to Telegram is an improvement in almost all respects and it's sure as hell a lot easier to do than going straight to Matrix/Riot/whatever it is these days. Don't be a purist and let people have their compromises, lest you end up like the "GNU/" part in front of "Linux".
(Edit: this is rather a negative comment but its out of frustration -- I want to use it!)
That page also states "Advanced users with special needs can download the Signal APK directly. Most users should not do this under normal circumstances." which IMO is a very good point. Downloading random APKs from the internet is rarely a good idea...
0. https://github.com/signalapp/Signal-Android/issues/9044#issu...
Ever heard the first rule of encryption? "Never roll your own crypto". Well they broke the rule and they won't let anyone check if the crypto is secure or not.
Not to mention encryption is off by default and your plaintext messages are stored on their servers...
https://telegram.org/privacy#3-3-your-messages https://telegram.org/privacy#4-1-storing-data
They have the encryption key, so the difference is not huge.
It tries to have feature-parity to WhatsApp; looks the same, works the same. All this while researching innovations on cryptography that doesn't compromise user experience too much.
In my experience, doing exactly what WhatsApp does (but safer) makes it an easy sell to people around me.
Other than that it's definitely a great alternative.
In other words, Telegram doesn't even deserve to be in the same conversation. Even if it had the best encryption out there (however you define that), that wouldn't mean anything when it's not used in like 98% of the cases (percentage pulled out of my ass).
It's like comparing Signal to Facebook's Messenger, and I'd still say Messenger over Telegram because at least it uses Signal's protocol under the hood (I believe the feature is called hidden conversations) instead of inventing its own thing and ignoring the expert opinions.
Granted I've never used WhatsApp, but I've been using Signal for like 5 years now on my phone and on my laptop with absolutely no issues.
WhatsApp is a total joke, it loses media (IIRC this includes audio messages as well) people send you after a very short time even when you use it on a single device, so talking about multi-device usage is completely out of the overton window.
(for any sensible definition of multi-device)
Meanwhile, the Telegram desktop client is at feature-parity with the phone app with both running entirely independently on as many devices as you want.
I would also state that it is unfair to compare an app that doesn't have to worry about your privacy and solving real engineering problems vs basically making a web app that can easily sync your data because it's all stored on someone else's computer.
If that's the level of privacy you're setting you may as well use email for communicating. It's federated, it's easy to use, and everybody has one.
All that said, I do agree the Signal desktop app needs some work, but they'll get there eventually, and in the meantime I don't have to wonder if any of my data will be leaked to anyone outside of my intended recipient.
Funny you say that because Signal is the one with a crappy Electron app which is definitely a deal breaker for me. I mean I lose E2E with Telegram but gain really well designed and featureful platform apps that are native and non-gimped desktop apps (and a functional linux client. Signal's Ubuntu client just crashed for me).
[1] https://threema.ch/en/blog/posts/md-architectural-overview-i...
In practice it works by each device having their own encryption key and then those devices are bound together with a cross signing key, so your peer can robustly identify all your devices at once (and the list of devices can change as long as they are bound by the cross signing key). Certainly the server is able to correlate device ids (and thus keys) and IPs.
The way threema does it sounds a bit how room encryption works in Matrix amond multiple clients.
So I personally don't even know if I'll keep fighting for my privacy and stuff or if I'm going to give up now. I don't want to, but I honestly don't imagine how on Feb08 I will be telling people who aren't my close friends or co-workers, but communication with whom is really valuable to me, that I refuse to join any WhatsApp group chats anymore, so they will have to notify me about anything important (important to me, in he first place!) personally via SMS, Telegram, email, whatever. Especially now, when people are forced to communicate remotely and stuff gets cancelled/renewed/delayed because of another round of idiotic government regulations, so if I'll fall out of these communities, I'm pretty much left in the vacuum and won't know about anything that happens.