Signal and Matrix are open source and full-featured.
Signal and Matrix are open source and full-featured.
The people who can judge if Facebook are to be trusted should be in the millions by now though...
Actually, no that's not sufficient evidence. That's only sufficient evidence for those interactions between the auditors and whatsapp's servers, it doesn't say anything about your interaction with whatsapp's servers. And that's the heart of the problem: using code shipped to a browser for e2e encryption is a flawed model, it would be trivial to target you with a version that has broken e2e encryption but subtle enough that you would never notice.
I said same things to most of my closer people and in the end they tell me “well they have all our data anyway”.
And all they have to do is just download an application.
I understand these aren't huge obstacles, but I am generally reluctant to add additional communication channels for these reasons - they aren't trivialities to everyone.
Messengers usually don’t have forwarding or a sensible polling interface. It would be nice to have all-in-one app even with limited functionality, since I’m mostly using text and images. Or use one of real full-featured messengers with gateways to others.
However I also think more people are on WhatsApp than those two (and possibly more) combined and people want to just use it probably for that reason.
I saw some of my contacts sign up to Signal firstly after the privacy fiasco then again in smaller quantity after the major outage. I deleted WhatsApp a while ago but I decided to re-install it again recently or basically risk losing contact with some old friends. In fairness I did try and convert people to Signal; I managed to convince a couple - so not all was lost.
Can you highlight your collective pet peeves ?
It should also be noted that we are not privacy-critical, just like these “numb people” I believe, who choose over little details rather than a big picture. Our background at the time was whatsapp, telegram and viber.
Another very small thing, but it irks me slightly - the chat bubbles are rounded too much.
Those are some of the few companies that are large enough to oppose governments.
> Signal and Matrix are open source
The main advantage of which is to enable audits like this, which WhatsApp is doing.
Of course you can't actually build WhatsApp from the audited source or pin it to the audited version... but you can't do that with Signal either. Not to mention that you're stuck with closed-source Google Play Services (or closed-source iOS) anyway.
They're more likely to cooperate with governments because they have so much to lose. All the big guys are caving in to China for example because they don't want to lose that sweet 1+ billion consumer market. Yes even Google. Check maps.google.cn and see the border around the South China Sea.
And also their interests are much more aligned with the governments, being entities similar in size and controlled by huge shareholder interest groups.
Oh and finally most of them don't even pretend to oppose government interests. Even Apple.
The best thing about Matrix is that both the software and the network is open and decentralised. This is why I prefer it over Signal (which even frowns on third party clients)
Signal may be open source at times, but that alone is not a reliable factor for the platform/company to be considered as trustworthy.
Agreed - I've moved ~80 of my friends from Messenger to the free Matrix server, and I host my own server. It's a wonderful experience.
This absolutely untrue. Signals source has NEVER been closed source. The Signal server source code(which isn't special and doesn't change that often) just had no public commits. The Signal client source code(what matters and makes Signal secure) was frequently updated.
> Signal may be open source at times,
Again, Signal has always been open source.
So it was opensource... you just couldn't see the source running on the servers? Yeah, makes sense. Right.
The client source code is the only thing that's really relevant in an e2e encryption model, anyway. Regardless, 100% of the production versions of the Signal server software have been published under free software licenses, so I'm not sure what you're arguing.
But I think what they're trying to say is because signal prevents any user from being able to use the signal app with servers they the user control. You're stuck with trusting the people running the servers because they say they won't do anything wrong. The whole reason you say the client is what matters is because it's something the user doesn't need to trust somebody else won't do something wrong. if I can build my own client and validate myself The security doesn't depend on blindly trusting somebody else because they say it's safe to do so.
A well designed encrypted protocol doesn't depend on blind trust in some service. The main signal app requires blind trust in the servers they control.
Now with signal and other E2EE messengers, you can just get the metadata graph, maybe. Not using the standard set of servers makes you stand out in a different way metadata wise, and more vulnerable, because you don't have as much labor available to secure your personal network, which is what your hinting at. It's partly why tor is a public network, because they want more noise in metadata analysis, and why you want to use VPN providers, so it's not just "you" that is aggregating your traffic.
The 3rd era will do both in a usable way, but usable ones don't really exist yet. All you have is research messengers.
One step at a time. Perfect is the enemy of good, or something better.
Phrased differently; Other messengers don't protect privacy so it's acceptable for this one claiming security to break privacy too.
> Now with signal and other E2EE messengers, you can just get the metadata graph, maybe. Not using the standard set of servers makes you stand out in a different way metadata wise, and more vulnerable, because you don't have as much labor available to secure your personal network, which is what your hinting at.
No, that's not what I'm hinting at. I'm complaining signal pretends it's primary focus is privacy any security, but fails at some of the most basic designs! If someone is targeting me specifically they can own my server, and I'm screwed. But using my server; if they own Signal, they don't get me for free. The inverse is correct as well, if they're targeting me, and they own me. They might not put forth the effort to own Signal. And if your opposition includes people who can server a sealed warrant, hacking into signal might not even be needed.
> It's partly why tor is a public network, because they want more noise in metadata analysis, and why you want to use VPN providers, so it's not just "you" that is aggregating your traffic.
What?
> The 3rd era will do both in a usable way, but usable ones don't really exist yet. All you have is research messengers.
> One step at a time. Perfect is the enemy of good, or something better.
No, that's not true about security. No security is better than half-assed security. Especially if you don't know it's half-assed.