Anyone who hasn't tried it really ought to.
To the haters talking about PGP: giving your entire social graph to Meta or even Signal is considerably worse.
Anyone who hasn't tried it really ought to.
To the haters talking about PGP: giving your entire social graph to Meta or even Signal is considerably worse.
(Delta Chat markedly does leak your social graph, because it's email and email has no way to protect sender metadata from each user's email provider. That means full social graph recovery is one low-effort subpoena away in your attacker's municipality of choice.)
Their contact discovery uses SGX, which has a long list of vulnerabilities [1], and is even deprecated by Intel.
With access to the server, my guess is that getting someone's social graph is not entirely impossible.
[1]: https://en.wikipedia.org/wiki/Software_Guard_Extensions#List...
The OpenPGP crypto can never be "outdated" because it is constantly being updated.
There's no PGP equivalent of TLSv1.3. The last time people tried that it created a huge drama.
> The OpenPGP crypto can never be "outdated" because it is constantly being updated.
Yet it hasn't been, it's not there in the implementations, it's not there in the defaults.
> I’ve tested Delta Chat with my own mail server, which uses Postfix and has everything configured for public e-mail, like DKIM signing, spamd, IP blocklist checks and so on, and each message took about 2 seconds from one device to another. Using a public server it sure feels below 300ms, so there is room for improvement when self-hosting a dedicated chatserver.
https://www.kassner.com.br/en/2025/05/08/delta-chat-encrypte...
In my test, both clients were ~80ms away from the IMAP server, but the server was delivering to itself. I’m also not sure if the port 587 has an idle/keepalive mechanism, or if it has to go around the entire TLS handshake at each message.
I don’t think 2 seconds is bad, most of my contacts will take at least triple that to read and type in an answer, so not a big deal.
> giving your entire social graph to Meta or even Signal
1) Signal does not have your social graph2) you are not required to give the app access to your contacts
Stop spreading this misinformation, it is only making it harder to get people onto secure messaging systems. You need two people using secure systems to communicate and the result of all this horseshit is a bunch of armchair experts who haven't bothered to look into the actual security of the app making strong confident statements. Just stop.
Even if it had half the issues people pretend it does let's be honest, my grandma can use signal. That's a fuck ton better than most of the alternatives out there. Frankly, that's what 99% of people need, the app that everyone can use. Not the app that some techie says is trivial...
Side note) Comparing Signal to WhatsApp is wildly disingenuous.
Side side note) there's a 30 yo pgp hack. If you reply to a gpg email with "could not decrypt" you'll get back the email in clear text. (Joke is older than the average HN user)