Messenger Comparisons – Threema, Signal, Telegram and WhatsApp
threema.ch
threema.ch
Signal team did an AMA in last few days [1]
[Few of the Q/A]
Q: Is there any plans to make user ID system, so that we can add friends without knowing the phone numbers?
Ans: Yeah, we're working on it!
Q: Hi, is it possible to backup chat history?
Ans: Thanks, we know this is a big deal and think about it a lot. We're working on ways to do it that would be privacy preserving...
Q: These things would really make the experience for my family and I complete
Support for backups and transfer on Android. Not manual, but automatic like iOS
Support for ChromeOS via Android Tablet support
Support for simple markdown like bold, strike through etc.
Ans: Great list, we're working on all of these!
[1] https://www.reddit.com/r/technology/comments/kt91qk/signal_p...
They did right in stating so soon in the exodus that expected features are planned and coming.
There are lot of low-hanging fruits which are quality of life improvement e.g #1 ask from my non-technical family members: Background wallpaper :)
Another feature: WhatsApp migration
+ Its open source, if they are willing to accept PRs things could accelerate
It seems like you’ve never followed Signal closely (or what happens with feedback and requests). Signal is not one to worry about losing out to other apps. If that had been the case, it would be a lot more feature rich by now than what it is. Signal moves at a glacial pace compared to its competitors.
> Here's a sneak peek at some new Signal features that will start rolling out in a few days: > > • Chat wallpapers! >• About field for your Signal profile > • Animated stickers >• For iOS: Media auto-download settings and full-screen profile photos (to match Android) > > Good morning 🇮🇳! https://t.co/KEAbhMswRI
Edit: In fact, I just had to kill the desktop client because it stopped working and the UI froze while attempting to start a video call.
https://twitter.com/signalapp/status/1348785240819466242?s=1...
Signal is supported by a non-profit foundation https://signalfoundation.org/
According to Telegram's Pavel Durov, "A project of our size needs at least a few hundred million dollars per year to keep going." [0]. Telegram has close to 500 million monthly users, how will Signal pay for their operations when they approach the same numbers, which I assume is the goal? A business model will be needed, Telegram only recently started talking about how to bring in money from other sources than the personal savings of the founder.
Edit: Is it really relevant to compare to SSH? Does SSH have user signups or servers that handle large amounts of real time communication? How many developers does SSH have employed?
On the other hand, I think Signal doesn't store anything once it has been delivered and any backup will have to be made on separate via some DropBox or Drive.
So the cost should be far far less than Telegram
I used for years combo signal+whatsapp, main reason is much better photo quality on signal and I like simpler UI, but I moved my family including parents away from Signal after they started to nag everyone with creating PIN I don't want
and don't get me started un unreliable message delivery if you often switch between wifi and mobile network, whatsapp will deliver messages without any issues, it takes very long time for signal to switch to correct network
so I installed tyo my parents and wife Google messages as backup option with chat feature, but that's not option for me without GMS
looking forward to some IM app with SMS support to replace mine Pulse (which also got into hands of shady company, so it has now blacklisted updates)
also they are talking about those features for years and introducing nonsense instead bringing basics, heck it took them years to be able to send multiple photos at same time, you had to send it one by one until like 2018, I think that speaks volumes about priorities/skills of Signal devs
But the E2E verifications I do find troublesome. I constantly have to re-verify contacts, it's way too much in the way of smooth communication. I wish there was a way to auto-enable (but warn of a key change) them like Whatsapp does. It's not as secure, but you really have to be a crypto geek to constantly compare fingerprints whenever they change or get added. I often log in to different devices (different browsers on machines at home, work, test phones etc). And everything has to be validated. Whatsapp and Signal handle this way way better. This way it just won't make it to the mainstream. I can't expect my contacts to click buttons every time I log into a new browser or clear my cookies.
In the end I just got sick of all these crypto warnings and I ended up switching to something else again. I re-try Matrix every once in a while but it's still not there. Also, for me E2E crypto is not a major thing as I run my own server anyway (which I trust). But some of my friends want it switched on as they also use it on other chat apps.
PS: Not trying to blast Matrix here, but I do find this a problem for adoption. Otherwise I think it's way better than any other chat app.
But the problem was not really for myself.. I know where to click, even though it annoys me. The problem was with the other family members that have to verify every time when I add a new browser to the mix.
And if they don't I don't see all the chats which makes it unreliable.
Also, I don't like the way it exposes that complexity: Why do the other channel users need to know exactly which devices I log into :) They should just know it's me. This is what most other apps do right but Matrix doesn't.
Barely any of my friends use these other apps making all of them pretty useless. Seems like a lot of apps will enjoy really high initial install numbers, but gravity may just pull everyone straight back to WhatsApp.
https://www.securemessagingapps.com/
i recommend Wickr Me. Its free, Privacy friendly and (almost) stable.
Probably confirmation bias so I'll bite. It's not open source, collects some data, it's a for-profit company. Why would I use it?
[1] https://www.militarytimes.com/flashpoints/2020/01/23/deploye... [2]https://www.securemessagingapps.com/ [3]https://news.ycombinator.com/item?id=22129436 [4]https://medium.com/cryptoblog/the-untrusted-server-19aff573c...
See the commits here for example: https://github.com/threema-ch/threema-android/commits/main
It's one commit per version. Contributions go to a private email instead of a public mailing list. All development happens in private and pushed to the public in a version bump with no changelog.
So yeah it has an AGPL License (which is good) and meets the minimum of FOSS requirements, but it gives of the feeling that they're following the letter, but not the spirit of FOSS.
I would definitely not use it or push any friend to use it.
Definitely not "FOSS-first", but it's something.
Its contemporaries are free.
Ergo, it is comparatively expensive.
https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
"You're free to use our source code for whatever you would like but you cannot use our servers" and they also refuse alternative servers or federation.
So basically you cannot create any fork or alternative client or make any change without their agreement.
They are very "Apple-like" in a way, "we known what's good for you, so just agree with us and don't try to go outside of what we want".
They also refuse to be on F-Droid for plainly false arguments. F-Droid offers double security : author signature + reproducible builds yet they keep pretending that you cannot sign apks on F-Droid and force you to download a non-externally verified apk on their website
Signal in itself is great but the people behind are not reassuring at all I think.
There is an still ongoing huge political and criminal scandal: a shady mafia-like figure (Marian Kocner) has (allegedly) ordered the murder of a journalist. The journalist and his girlfriend were shot and during the investigations Kocners phone(s) were found (or more exactly another shady person gave them to the police). Not only were undeleted Threema messages extracted, but also (allegedly) many deleted Threema communications were succesfully extracted and presented in court.
While Kocner was in that particular case exonerated in first instance (it's now in the Highest Court), the messages were leaked to the press and led to the abdication of the then prime minister (Robert Fico), the loss of the then ruling coalition in the next elections, and now because of those decoded messages, many judges, prosecutors, politicians, policemen etc are locked up and investigated - Marian Kocner directly gave them orders through Threema. The former head of police has even hanged himself in the prison a few days ago (because of a different, but connected, scandal). While this is more about the general state of affairs in Slovakia, it's interesting how the compromised security of an app they thought was "fully" secure has impacted the Slovakian political landscape.
Second link: behind paywall
Third link: no mention of Threema
- Paid app for general public (one-time fee)
- Separate "Enterprise" solution (Threema "Work") with paid subscriptions
> It’s not necessary to grant access to the address book in order to use the service.
This section incorrectly marks WhatsApp with an X, stating that it mandates it. The fact is that WhatsApp can very well be used without giving it access to the contacts or address book. This section should have a yes for all the services in the list.
If you don't grant it access, it won't let you associated any name with messages and conversations. Everything shows up with just its raw phone number, and the list of conversations is a list of raw phone numbers with messages, which makes it hard to know who messages are from.
Sometimes it's not a case of not knowing any better. The convenience of reaching almost any of your contacts directly from WA cannot be understated. This is what Signal & co. are up against. Most old folks won't be switching as WA just works for them.
It also doesn't help matters that data plans from ALL telecoms in my country come with FREE WhatsApp bundles.
They didn't really have a choice though, because WhatsApp is now the only way they communicate with a family member, who doesn't have a phone any more.
They both use a Facebook Portal instead.
I think it should be illegal to put users in a position where they are pressured to agree to something without significant effects of agreeing being made clear.
And I think they should be able to return the Portals for a refund when something like this changes on them.
On policy agreements vis-a-vis user privacy, it is a bit of a conundrum that I don't see the normal consumer winning. WhatsApp/Facebook are doing nothing illegal by giving users these new terms. The major problem with such T&C is that the normal user cannot fully understand the contents of them. I will confess to being one of them. Most of them are written effectively to be nothing but legalese scapegoats. With jargons the average Joe cannot comprehend. This I see is the biggest obstacle to every day privacy & user data protection.
Bonus fact: it's not just Facebook knowingly doing this for profit. Many everyday services which we click & agree yes to are doing so. Someone above just pointed out that sometimes they click yes because they know big tech already have their data or will at some point obtain it, why delay the obvious outcome?
Though this shouldn't mean you cannot feed them fake data at any given point/excuse. Privacy battle is not for those who give up easy.
I just assume that all my information is already sold, regardless of the company brand. We lost this war for privacy.
Is that a lack of net neutrality? Does your country have laws about it?
Come to think of it. Facebook zero (0.facebook.com) offering users free access to FB was also a thing almost a decade ago and still is a thing today i.e Facebook usage that doesn't count against your data plan.
I presume this to be a commercial deal between Facebook and the carriers here. Given how popular Facebook, and more so, WhatsApp is here.
XMPP:
* supports three encryption methods (OMEMO, OpenPGP, OTR);
* has a great amount of clients [1];
* and also of servers [2];
* it is federated;
* the protocol [3] and the most established clients and servers are open;
* there are already several online services available to use [4].
And as a bonus, the famous "XMPP's myths & legends" [5].
[1]: https://xmpp.org/software/clients.html
[2]: https://xmpp.org/software/servers.html
On the one hand, it's harder to pronounce than, say, Signal, and it has no inherent meaning like, say, Telegram, but look at Whatsapp...
> Service runs its own server [no]
Telegram uses own servers
> GDPR compliance [no]
There is @GDPRbot, https://telegram.org/faq#q-what-about-gdpr
Is there any official documentation about this? I checked, and could only find a note about their servers in the EU (Netherlands).
They mean it as "the service provider operates and runs all servers, and there are no cloud or hosting services (such as Amazon AWS or Google Cloud) involved"
I'm not sure if it's really an advantage or a weakness.
Telegram runs both own and hosted servers, and also allows volunteers to host relaying proxies to circumvent censorship.
However if they have good e2e encryption this should be a very minor benefit as I'm not trusting the operator anyways.