I've heard that claim so many times, yet very few startups hold their promise to open the source code. Especially for something branded as a secure messenger, how to give it any credibility without being able to inspect/audit the source?
> you can stop using Android or Apple phone i think
I use deblobbed android without google services -> replicant.us
> you can find "Loki Messenger" (old name of Session ) with two "spyware" inside too
I pointed it out in another comment so i'm aware. However these trackers have been removed in the meantime, and Session is actually free software which you can build from source.
> i trust the very skilled person
Good to see they've got a competent cryptographer, however competent cryptographers does not necessarily make a successful and secure decentralized messenger. See also Wire who had serious crypto and promises to open source everything, but to my knowledge the server side was never released, and Wire more or less failed as yet-another encrypted centralized messenger like Signal. Or GNU/Net who also has some solid research and practical applications [0], yet didn't grow so much over the years.
> Session is just another textsecure implementation
In fact not. It's certainly a TextSecure fork, but the only TextSecure implementation left is silence.im, whose maintainer is an employee of La Quadrature du Net from what i understand. But being SMS-based, silence.im leaks a lot of metadata (unique identifiers + timestamps).
And contrary to other TextSecure forks (like Signal), Session does not rely on a centralized infrastructure or sketchy "secure enclaves". Like i said i'm very critical of relying on a blockchain at all, but i have to admit Session looks (from a quick look) like a serious project.