WhatsApp goes down for users globally
theguardian.com
theguardian.com
Also, being based in the UAE doesn't inspire confidence on the privacy and security front... Nor the fact they promised to release yearly transparency reports and then never did so... Or the fact Der Spiegel claims they have evidence of Telegram handing over user chats to authorities despite the fact telegrams FAQ claims they have never done so...
> Also, being based in the UAE doesn't inspire confidence on the privacy and security front...
Well the 5 eyes do not inspire confidence either, and that's where whatsapp is based.
And Apple has plans to automatically inform law enforcement from device scans. At least telegram client is open source so that is unlikely to happen on the client side directly.
You also lose talking to more than 1 person at the same time.
Also AFAIK Telegram has access to the plain text data from stickers so when they are downloaded by a person on a secret chat, everybody with server access can also figure a bit of the context of the conversation.
And everyone from all companies to which Telegram will sell the data once they figure that there is a good money to be made from it.
If they have the plain text data they can do whatever they want with it.
It uses a homebrew encryption scheme and does not have E2E encryption (yes, you can enable E2E for individual chats, but nobody uses it because it breaks most features).
Not to mention the weird corporate structure, lack of transparency, failed crypto token launch, dishonest marketing...
Please stop with that. At some point every encryption scheme was "homebrew" (or rather, new). MTProto 1.0 had flaws, which were addressed in 2.0. The latter has been independently formally verified to be secure[0].
> Telegram is the least secure.
Against who? What is your threat model? Such absolutist blanket statements are useless by design.
> of all the major messengers
Which are Messenger, Whatsapp, and SMS/RCS around here. Signal shows up from time to time, and Matrix doesn't even register above statistical noise so I won't count them as "major" (Signal, being, in a stroke of optimism, at best a challenger)
Of these, SMS/RCS is a total clusterfuck, and the remainder is owned by Meta. Yes, Meta is high on my list of adversaries, and given their track record should probably be for anyone out there caring about their privacy. No, WhatsApp's E2E is not to be trusted[1][2].
So is Telegram the least secure of major messengers? definitely not.
Is Telegram perfect security, certainly not either, because that doesn't exist[6], but their E2E is solid, even without E2E, extra steps are taken to thwart certain adversaries[3][4], they have reproducible builds for their client binary builds[5], and as can be observed so far their actions are veering on the complete opposite side of Meta's.
Is Telegram an opportunity to convince non-{privacy,security}-minded random joes and janes to jump out of a bunch of terrible chat platform for a better (or less worse if you want) chat platform? I'd say probably. I mean, it really really looks like they're trying hard to get the job done.
[0]: https://github.com/miculan/telegram-mtproto2-verification
[1]: https://twitter.com/Shiftreduce/status/1347546599384346624
[2]: Meta controls the Es in this "E2E", and I won't trust that, ever.
[3]: https://telegram.org/faq#q-do-you-process-data-requests
[4]: https://security.stackexchange.com/questions/238562/how-does...
For example, if you travel internationally with a different SIM card, iMessage doesn’t allow your main phone number to be used for iMessage any more.
Another terrible “feature” is that to have a complete history of your chats, you need to back up to iCloud. Even for plaintext messages. And uploading photos will quickly blow through your iCloud storage.
Telegram, on the other hand, maintains your complete searchable message history including media for free, and when your phone number changes, it just asks “hey did your phone number change?” You press no, and the experience is completely identical.
Whereas when your phone number goes away on iMessage, you’ll have to fiddle around with settings to get something else working, your contacts will be fucked, and people will have issues sending you messages, etc.
In telegram, the model is that my messages are associated with me. In iMessage, the model is that my messages are associated with my device and SIM card. I think the latter model is boneheaded for a personal messaging app. Which means that iMessage is fundamentally problematic.
Sorry for my iMessage rant, but I do love telegram :)
Indeed, it is. I did not mention it because it's Apple ecosystem only, leaving a lot of people out. It appears to do many things very right, some lacking, and a few "wrong".
AIUI, with Messages backups in iCloud disabled, each device has its own key. Each message sent gets E2E encrypted with the key to each destination device and sent once for each device. So if the recipient has three devices, that's three encryptions and three messages sent. (That's how I recall someone describing it back in the day, I'm not sure today and I can't find the source of that anymore)
> Another terrible “feature” is that to have a complete history of your chats, you need to back up to iCloud.
The above means that a newly added device doesn't get access to the message history. This actually implements perfect forward secrecy! An attacker who manages to convince someone in some way to add a new device would a) be name to decrypt any old message intercepted and b) only be able to see new messages.
In that setup the only thing really lacking is being able to jointly check a contact (sender or recipient) key via a secondary channel and maybe TOFU it and displaying a warning when a contact key is added, changed, or revoked. You do get a warning for new devices added to your account but it could also apply to already added devices who unexpectedly get a new key.
Enabling backups in iCloud breaks perfect forward secrecy somewhat since the goal is being able to obtain the whole history, so an attacker managing to enroll a new device would presumably get the history. That said I also hear that this iCloud backup isn't zero-trust encrypted (technically it could be, think borg backup) but I'm really not sure about that.
> And uploading photos will quickly blow through your iCloud storage.
Not just that, it seems to do an absolutely terrible job at clearing the local cache, eating space like crazy and with no easy option to clear it: the settings app storage section is hopeless in that regard, Telegram's way of handling that manually plus the automated ones are muuuch more clear.
> For example, if you travel internationally with a different SIM card, iMessage doesn’t allow your main phone number to be used for iMessage any more.
I did not witness that when swapping SIM cards with new numbers: Messages popped up a dialog or something asking "keep using +XXXXXX" || "use +YYYYYY". I seem to recall I could even have both numbers for some time (IIRC there was a 2 week - or was it one month? - delay before a number is forcefully dropped out if you don't pop the SIM with that number back in). It was annoying the hell out of me as it was a short-lived number that was temporarily assigned while my real number was transferred between operators. My mistake though for tapping the wrong answer, but admittedly something there could use some improvement.
That was with local numbers though, the international story might be different? I would not expect that though as it would be truly an awful experience for international travelers that swap SIMs on non-multiSIM (eSIM+tray) iPhones.
And finally there's trust... it's completely closed and very hard to audit, but then again Apple owns the OS and hardware, so one could audit the app all they want, they have a much more potent vector for exfiltration.
[0] https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...
That said, WhatsApp using the E2E Signal protocol is immaterial if they exfilter the locally stored private keys out to their servers, which is what the redaction of that line in the whitepaper we both linked (you directly, me via that Twitter link highlighting the diff) alludes to:
> At no time does the WhatsApp server has access to any of the client's private key.
Unless one checks every update of the client's code and the matching published reproducible binary output one can't be sure that keys (or any other data for that matter, since it has full access to anything decrypted) are not exfiltrated.
Now, that line deletion could be a subtle canary because law enforcement/state actor, or that could be Meta being nefarious following the cofounders departure, or anything in between. Either way I find it a worrisome signal that this specific line has been removed.
They don't do that.
Biggest issue with WA is the backup mechanism. You can encrypt it with a passphrase nowadays but AFAIK that's off by default, rendering E2E moot if either party backs it up to their Google Drive.
Seems legit, I see no reason whatsoever not to trust them completely at their word. No company has ever lied to anyone before after all.
factual statement is made by said company
doesn't elaborate
gigachad.jpg
No. Most people can't do that (because not everyone is a software developer).
Good luck trying to convince the general population that “the UX is bad but theoretically anyone can improve it” is better than what you get out of the box with other messengers.
Just do the change yourself. Help those people close to you to install Element alongside whatever they are using now. Even if just because they are using to talk with you, it's better than nothing.
You don't get to migrate things that are on huge network effects in one go. But we can help the growth of one network organically until it reaches critical mass.
I am not asking them to delete the other app, I am not asking them to join a religion. I am just asking them (and helping if necessary) to install an app and set up an account on my server.
I don't use either so I don't really care. I just don't expect a consumer service with subpar UI to win market share solely on technical merits.
That makes sense for unfunded projects because most developers are not good designers, and designers don't have a culture of contributing to open source, but for a project that pays (some of) its developers, it's their choice how much to pay developers vs designers vs managers, and they are responsible for the way in which they allocate their limited resources.
I recently had to move my open source project's chat from Gitter to Discord, not because we like Discord or "don't care about open source" but because everyone is so damn tired of Gitter's terrible UX that it became the overriding concern.
Matrix bought Gitter two years ago, and I kept waiting, hoping that they would improve it, but they did literally nothing to it except connect it to Matrix within a couple months – and even that doesn't work well, with Matrix users still unable to respond in threads.
I assume there is a good reason for that. I'm not here to judge, only to point out that this "good reason", whether it's lack of funding or priorities or whatever – won't change anytime soon, so I won't be holding my breath anymore.
We spelt out the good reason in the original blog post: https://matrix.org/blog/2020/09/30/welcoming-gitter-to-matri...
> However: in the medium/long term, it’s simply not going to be efficient for the combined Element/Gitter team to split our efforts maintaining two high-profile Matrix clients. Our plan is instead to merge Gitter’s features into Element (or next generations of Element) itself and then - if and only if Element has achieved parity with Gitter based on the above list - we expect to upgrade the deployment on gitter.im to a Gitter-customised version of Element. The inevitable side-effect is that we’ll be adding new features to Element rather than Gitter going forwards.
We’re almost at the point of being able to switch Gitter over to being a branded Element.
Apparently, that has not been a priority in many years.
Matrix/Element is so far behind usability/features that it's really only used by people that favor decentralization/openess at the expense of actual users.
Telegram is great for other no privacy related stuff as bots, channels and groups.
We're keeping one alive with friends, not because we need it, but because we can and it's easy to do so.
We can argue matrix has not the most fancyful clients right now, and it might not be a perfect solution for everybody, however there are many clients to choose from, you can write one easily with many support libraries, it's easy to script, you can have full control.
This is what we should push for. I've recommended signal to a lot of friends, and I currently feel stupid for doing so: It was a hurdle to convince them, and what I achieved was to move some to another privately run network with arbitrary rules and mandated software controlled by a single entity which is now starting to do random crap.
(But also: I don't have the resources to run a separate instance for myself, let alone for my friends.)
Hint: the correct answer to this is not "Well there's your problem you're expecting to run it on Digital oc-" no, this attitude helps nobody. Like Picard said, make it so.
Meanwhile you also have the option to get a client with multi-account support. Again, not all clients have this, but this is again something that no other messenger does, or will ever allow purely for market reasons.
[1]: https://techcrunch.com/2021/09/26/signal-the-encrypted-messa...
The fact that these systems are centralized in management does not mean that they need to have any SPOFs.
Also, the Apple App Store and iOS activation servers are the biggest SPOFs of all. Without them, even with a brand new working device, you can't activate it or install apps to communicate.
While true, Signal hasn't done this as far as I know. Until they do, their infrastructure is just as centralized as WhatsApps.
They are owned/managed by the company that popularized "move fast and break things" (though to be clear I do not think that they intentionally take this approach with WA or IG or the FB advertising infrastructure).
If one engineering mistake can take it down, it's not decentralized. Or an action, not necessarily a mistake. It's at least somewhat centralized. An individual can be asked to take it down. In a correctly decentralized service, that can't happen.
There's no way for you to avoid SPOFs for notifications on Apple devices, because APNS is designed so that the only way you can wake up an app to talk to an API is via notifications sent from the developer of that app.
This means that if the APNS servers go down (unlikely), or that the vector.im notification relay servers go down, nobody using Element on iOS gets any notifications.
It also means that vector.im sees all of the notification events (who got notified when), though I don't believe they see the notification content. The notifications (I speculate) are simply app wakeup events that make the app then contact the homeserver to see what it has new.
(Of course, it did so roughly as we finally qualified for the nonprofit Slack plan, so it was a bit too late to have a real advantage - but it's an option now where it wasn't before.)
So let's say I were using Matrix for the hackerspace. With spaces, I can invite a new member to the space and they can join whatever associated rooms they want on their own.
Without spaces, I'd be stuck either inviting people individually to every room, or making every room completely public, neither of which are particularly palatable.
Copied from last "This week in Matrix":
- Another big thing in Synapse 1.69 is experimental support for faster remote room joins!
- The new WYSIWYG (What You See Is What You Get) composer is available in Labs soon; It’s in active development and we’ll be adding more functionality soon.
- Notifications research is near conclusion; We trawled hundreds of GitHub issues, discussions, looked at competitors and interviewed some users. We’re really excited to bring improvements to your experience.
- Threads is making great progress and we’re hoping you’ll start seeing these improvements in the next few weeks! Keep your eyes open for updates.
No, this is not a question, this is an answer. At this point, XMPP is not a solution, but a basis for an actual coherent solution to be built on, but it does not exist yet (or anymore).
Matrix is also only a partial answer, because in practice you will direct users to matrix.org, and that makes matrix.org not a single point of failure, but still a huge point of failure and matrix will be down for most people if matrix.org goes down.
I would be happy with it but my contact list quite empty.
I'm not outright rejecting XMPP. I would like it very much to just use XMPP, but something needs to happen. It needs to be easy to use, friction-less, have all the fancy features and probably more to sell than Signal, Telegram, WhatsApp, Facebook Messenger and Matrix at the same time, which is no small feat.
Core XMPP does not cut it. People expect more from a chat solution and won't adopt it as-is.
XMPP has had decentralization for a very long time, but almost no users (if speaking about actual, decentralized, chat; it's used in many other things). It had both decentralization and users for a short time with Google chat, and user with no decentralization with Google chat and Facebook chat for a longer time, but both things are dead now.
The network effect is the biggest issue to overcome for a chat system, not the actual tech, and XMPP has not solved it. Unfortunately, if you ask me.
Element/Matrix, in contrast, have the features and a beginning of adoption. it now needs polish, smoothing the rough edges, and adoption. And also adoption. And even more adoption. Including from people/entities providing homeservers. I tried to make people adopt it. I failed. Signal, however, has been a success so far. Element/Matrix is great and a success in my company, however.
I can't claim it has exact feature parity with Signal/Telegram/WhatsApp, but it has all the important stuff and is good enough for my family to use daily. It also has some advantages, such as not requiring a phone number (which e.g. means that my children can use it on the old "living room tablet").
Snikket counters the "empty contact list" problem and the network effects by focusing on small groups like this, automatically including everyone else in the same group(s) in your contact list. It helps a lot.
The ultimate goal is that we get enough such small groups operating on open networks, eventually the members of those groups will find they can communicate with each other. It's better approach than isolated individuals using XMPP/whatever with empty contact lists just because they believe in it.
Is there a desktop app for Snikket?
Having been down the venture capital route in the past and not particularly enjoyed it, I'm trying to work on Snikket as close to full-time as possible while self-limiting to funding that's compatible with the open nature of the project and the ecosystem it's a part of. Currently grants, sponsorships and donations are helping immensely with that.
There is no desktop app yet, but it's firmly on the roadmap. For now I tend to point people towards Dino or Gajim for Windows and Linux, or Beagle for MacOS. None are a perfect match for the project right now, but power users can generally deal with it, and all of them are under active development and constantly improving.
Without a internet standard for IM we cannot hope for advanced features like usable federation, encrypted messaging or A/V calls between platforms. We probably should not be promoting platforms which are not standards compliant.
Don't you need XEPs to do any messaging in the first place?
Naysayers keep arguing that the jungle of XEPs make it too hard to implement and use and that's what halting the adoption of XMPP, but that's like saying no one is doing any web innovation because the specs are too big. The reality is that only a big name with continuous marketing work and advocacy is missing from XMPP, and is the one reason Matrix got where it is today.
Honestly, we just need a drop dead simple chat client/server that can be self hosted and may be eventually extended via wireguard/tailscale networks and MagicDNS.
WhatsApp nailed distribution, Signal does privacy well, Telegram is simple and scalable. What is Matrix? None of the above. I'm sorry, that might come across as harsh but I see a lot of wishful posts here that kind of throw users in that direction without real insight and knowledge into it. We don't want DIY that's endlessly complex and hard to maintain. The reason centralised apps work is because there's no setup, so really you're fighting frictionless experiences. Want to make self hosting a better experience, make it frictionless.
I wish they'd focused on building a messenger first, rather than trying to be a Slack/Teams/Discord. That said, it's taken a while but the Element client is dramatically better now. It still doesn't have the polish of other messengers, but I'm rooting for them to dial that in.
Another problem is that a focus on federation limits your appeal to people who like to self-host things.
XMPP, again and again. But that's not a solution, because the problem is absolutely not technical.
I've run the original jabberd server for an organizations internal chat server along with all the open source bells and whistles that go with it. Let me tell you I didn't once see the value of that except to save money and for privacy. But it was an organisation. If we want open federated communication the standout thing has to be the ease of use, the quality of experience and to actually highlight it's benefits. Right now I don't see that.
I know at least one project aiming to fill the same gap for organizations though (again, using XMPP), but pre-release currently: https://prose.org/
I'm a firm believer in essentially what you said: The protocol doesn't matter, it's all about the products and what they can do and how easy they are to deploy and use.
It' s not necessarily a better user experience but it provides a far better user independence, and that definitely counts.
I'd rather recommend Briar [1] which is really end to end encrypted, and works even offline via bluetooth or Wi-Fi LAN.
shrug
Everyone I message with is via iMessage or Signal nowadays and I only have WhatsApp because I am part of a few sports clubs which have a WhatsApp group but we don't chat enough for me to notice a downtime like today.
Makes me happy to see how I've actually managed to rid myself of WhatsApp for the most part.
In some countries WhatsApp is used by almost everyone. I wonder how much all those free users cost Meta each year. Just as a side thought :)
iMessage intentionally preserves a backdoor in its crypto so that the FBI can read approximately every iMessage sent/received without a warrant, should they so desire.
For the normal person this matters less of course, intelligence services are not interested in your nudes.
> intelligence services are not interested in your nudes
There is actually plenty of evidence they are[1].
[1]: https://www.theverge.com/2014/7/17/5912287/edward-snowden-sa...
If I recall correctly Snowden said the opposite. The guys he was around regularly shared nudes etc of people they were spying ins
Would be great if you provide a source for that.
Might not be the best "source", but there's clear evidence of it being done in the past.
The backdoor in their end to end encryption preserved intentionally by Apple to enable surveillance is what allows them to be read - by Apple.
There really is no technical reason to use Whatsapp anymore
IP networks have much more reach than the PSTN these days. It's not 1995.
I don't see how I could be in a situation where sending a message to a +50 group is critical.
Open source, doesn't require a phone number, and a big strength is that it's decentralized, which makes it much less vulnerable to outages like this.
"Session utilises the decentralised Oxen Service Node Network to store and route messages. This means that unlike P2P messaging applications you can message Session users when they are offline. This network consists of community operated nodes which are stationed all over the world. Service nodes are organised into collections of small co-operative groups called swarms.
Swarms offer additional redundancy and message delivery guarantees even if some service nodes become unreachable. By using this network, Session doesn’t have a central point of failure, and Session’s creators have no capacity to collect or store personal information about people using the app"
Btw, the whole idea of "no phone numbers" makes it really hard to spread. It basically means you can't send a message to anyone in your address book that already has Session installed, unless you get his Session username by other means.
Also, by doing that and letting the account existence be publicly known, anyone with their phone number will know that they have an account on that service and lets you try to contact them. That can range from privacy violation to life-in-danger situations.
We give too much information away. Companies have shown that they are incapable of keeping the information private anyway. We get big scandals, the interwebs kick up a big stink, brows are furrowed, and then we go back to doing what we did before with nobody learning anything.
If I gave my phone number to someone, I made an implicit social contract with that person or organization that they may contact me using that phone number. I don't see it as a big stretch if they use that number to send me a message or call me using WhatsApp, Signal or any other messenger where I registered using that same number. It's for the same purpose of communication, after all.
If I don't want to be contacted, I just don't share that number.
And it's not like people don't know that messengers or social networks can collect contact metadata about messages and calls. It's what traditional landline and mobile providers have been doing for ages.
I don't really care if they sell my phone number, it's already out there, I don't consider it private data anymore.
It’s basically an email client disguised as a messenger.
I haven't dug too deep either but it doesn't sound much more centralized than the tor network for example.
[1] https://docs.oxen.io/products-built-on-oxen/session/network-...
> Oxen blockchain and the $OXEN privacy token
EDIT: Support answered with generic mail on what to do if problems registering device... eh, whatever.
Though for my closest friends and family we still have Signal as backup.
Sounds like a nice way to test new notification settings before putting them into production. Now go and apply them ;)