They are contributing to IETF MLS for end-to-end encrypted group messaging: https://datatracker.ietf.org/wg/mls/about/
They are contributing to IETF MLS for end-to-end encrypted group messaging: https://datatracker.ietf.org/wg/mls/about/
Not needing a phone number is nice, but last I checked Wire does little when it comes to metadata, while Signal is more or less the state of the art in that regard.
The phone number requirement itself is supposed to be eventually dropped in Signal (although I'll admit it's taking quite some time, and with the spam issues it might take some more).
Features are available and work everywhere (unlike Signal which has a dumbed-down desktop client and no web client at all), it does everything you generally need and the search is actually superb (better than Telegram even, since tg only does word matching and Wire can do symbol and arbitrary string matching and is also very fast) although limited to one chat so you need to know which chat contains what you're looking for. Meanwhile Element (Matrix) goes "can't search encrypted chats"... useless if you want to communicate something non-ephemeral, you'd need to switch to pgp-encrypted email and all its problems or another chat service.
Compared to all the alternatives, Wire with all its faults is the best encrypted messenger. I would recommend it to everyone aside from the network effect: Signal clearly has more users (while being worse on features and privacy). Because it's useless to be alone on a messenger and because it's still a step forwards from the status quo, most of the time I end up recommending subpar solutions.
That used to be true, but now the desktop client has almost all the feature of the mobile clients. Which feature do you miss there?
> Signal clearly has more users (while being worse on privacy)
I assume you're talking about the phone number requirement? This is fair criticism, but what about the rest? Signal leaks way less metadata than Wire, which is more similar to WhatsApp in that regard.
See also this comment: https://news.ycombinator.com/item?id=14069674
Some things might have changed, but it's not clear to which extent.
Since centralized services are currently also the convenient ones and neither Wire nor Signal show any sign of wanting to use a decentralized protocol, those that can't be bothered to use inconvenient services have to trust that their centralized service is ethical about what they do with your data.
The privacy differences are very minimal by comparison when they're all missing one basic feature or other like message editing (Signal), a desktop client (Threema[2]), cross-chat searching (Wire), searching a chat at all (Element), any usable encryption (Telegram), etc. If you're going to use an end-to-end encrypted messenger where the server can't read any contents, the privacy differences are just not that large when you trust them all equally. The only thing that you can objectively compare is what the client sends, since that's something they can minimize and you can actually check.
[1] "clients derive a 96-bit delivery token from their profile key and register it with the service. The service requires clients to prove knowledge of the delivery token for a user in order to transmit “sealed sender” messages to that user". It's a bit opaque so in regular English: my Signal client sends something like deliveryKey = H(profileKey, currentTime) to Signal, where my profileKey is something only my contacts and I know. Great, so my contacts only specify the deliveryKey and not who's sending, so you send anonymously! But wait, those contacts connect to Signal with an IP address and are doing other things like updating their profile or registering their delivery keys for their account from that same IP address. 1+1=2 and you know who is sending messages to whom.
[2] They have it, but your phone plays Chinese Whispers with your computer and every time your laptop or phone reconnects to wifi/mobile data you need to open the app on your phone and navigate two menus to re-enable it.
With Matrix you still end up trusting the server sysadmin (both in terms of ethics and technical abilities), it's not like it solves the problem for mass communication where at least one user has to agree on a 3rd-party instance.
> those contacts connect to Signal with an IP address and are doing other things like updating their profile or registering their delivery keys for their account from that same IP address.
Correct me if I'm wrong, but I think that happens within SGX. This in itself is its own can of worms, but assuming it's secure, I don't think you can do this association IP / account that easily. At least it seems so easy to work around that I would expect it to be like this (given that they already use SGX for other things). Now of course SGX is not secure, but it still makes the attacks more expensive and complex than they would be otherwise. If you have access to a Wire server, it would take you minutes to get all the group memberships of one user. If you have access to a Signal server, you'd need to log connections over some time, and do some statistical analysis to extract useful information. Not impossible, but far more costly and less reliable.
In terms of privacy Wire might be better with respect to the phone number requirement, but otherwise Signal has an edge.
The IP address is also something you can solve independently (VPN / Tor), so it makes sense not to solve it within Signal. But it would be nice to have some integration with Tor eventually.
It likely doesn't really add much security. Anyone capable of running processes on the chip hosting the SGX enclave can probably run a side-channel attack to recover the necessary keys. I was very disappointed that Signal took that approach.
I do think there's some improvements that can be made, such as a better visibly into how to sign up without a phone number (I think this is still the default on the phone app) and a more visible download option on their website (the free version is buried under "Resources" -> "Downloads". You can make backups, but there's no easy method to do a plain text export. I get the feeling sometimes messages get "Stuck", and there's been issues in the past with notifications not being sent or push notifications not getting through certain Android sleep states. Sometimes I'll edit a message just to "resend" it such that it's delivered.
Overall though, It's still my secure messanger of choice by far. Glad to see it discussed here.
The company keeps a list of all the users you contact until you delete your account.
Source: https://archive.fo/ARZe4#im
But due to the usability constraints of truly decentralized systems, I think most users are better off with federation.
E.g. it states: "A collection of decentralized computers systems are components of a larger computer network, held together by local stations of equal importance and capability. These systems are capable of running independently of each other." This is true for Matrix with Homeservers being the decentralized computers and the network of the same being the larger computer network.
If you are going to pick a tiny part of the page, you might find that it's not sufficient. In the sense of your chosen quote, Twitter is decentralized, since it runs on multiple computers organized in a network. Those are capable of running independently of each other, to a degree, if Twitter Inc did their High Availability work correctly.
It is not decentralized from a user's perspective though, since the software they use on their devices cannot run independently of the remote systems of twitter.com.
I don't know where that leaves us, but then again I don't know what you were trying to argue either.
Yeah, and I agree there are different types of decentralization: e.g. physical, authority, ... or combinations
Each incarnation with different goals
But it would be nice if the sender could be notified that the message was never delivered.
It's not obvious, but if status never changes from "Sent", then it wasn't "Delivered".
For those who like to leave your message unread on the server for up to a year, then go with signal or telegram.
As I've observed for a long time: UX is more powerful than anything else except maybe cost, and even then one driver for user preference for "free" apps is not having to dig out a card... so cost is also UX.
Bitcoin isn't... neither is cash in hand. Neither is a drop. Someone knows.
A discussion of 'anonymity' in this context is one of increasing the difficulty of discovery, not thinking that the discovery is impossible. If a major world government is after you, good luck with "anonymous"
It could be done truly anonymously when up against the full weight and might of US, Western, Israeli etc intelligence budgets and methods?
I should still note that it isn't a magic bullet, and that things you do in connection to the monero blockchain can obviously still give the authorities an idea of what you are doing.
Etc etc. My point is that anonymous is an ideal, not a absolutist reality.
There's not many kinds of payments which aren't fairly easy to do anonymously.
These guys must be making insane amounts of money, would love to build a competitor.
In any case, doesn't this only link your personal data to the ownership of a Threema app usage license and not to the content (user ID) inside the app?
It's definitely different to entering your phone number into the app.
You can just get a gift card and pay in cash for it.
It's a bit hard to find, looks like they've given up trying to compete for non-business users, but the client has a registration form open to everyone.
I think they'll keep supporting this because inviting those 'guest' accounts into rooms of business users is a big feature. We regularly collaborate with people via Wire (customers or freelancers, who can just use their personal Wire accounts) because it's the easiest way to collaborate without forfeiting encryption or features.
Not a pro move in my opinion.