Why? Because the Dutch national broadcasters keep plugging it as an alternative to Whatsapp.
Aside… Two apps keep getting mentioned as alternatives, Signal and Element/Matrix, but in MHRO both are not viable as replacements.
Signal: still a US app, CIA funded, provides their encryption backbone to Whatsapp, recommended by governments & FBI. Matrix/Element: Developed in Israel, with ties to IDF, preferred by NATO (NI2CE)
IDGAF who funds it or who develops it.
- E2E encrypted
- security review by independent party I trust which says there are no holes or bugs
- open source
Those three things are all that matters.
Just FYI:
If you want to say “both are not”, you can instead use “neither”.
Yes you can, both are correct.
Neither is incorrect really
Other than people you don’t like living in the world here with us, do you have any proof of anything actually nefarious done by signal or matrix?
Signal is funded by the CIA now ? And I thought Element is in the UK?
Signal does seem to have some ties to the CIA
There seems to be a completely different Israeli company called matrix. I can’t find any link between the two.
It’s old and convoluted, something like a precursor to element got funding from Israel or something
Maybe OP means that the Matrix protocol is created by an Israeli company.
Naw
Signal: still a US app, CIA funded
Honestly, this gives me more confidence in it. The CIA is very interested in keeping its people safe, so if they’re using it, its in their interest to ensure it’s secure. If they do put in a backdoor, I happen to be a US citizen so I’m unlikely to be a target since the CIA is all about surveillance on outsiders (FBI is domestic). FBI and Signal rarely agree, but they agree that Signal is great, so I think that’s a pretty strong endorsement.
Add to that Edward Snowden recommends it, and he’s certainly an enemy of both the CIA and the FBI at this point.
If nobody used CIA funded security tools, we wouldn’t have security tools
I happen to be a US citizen so I’m unlikely to be a target since the CIA is all about surveillance on outsiders (FBI is domestic)
All of that’s off the table now with Trump in power. It’s more than likely the CIA will be deployed against domestic targets.
I think that’s unlikely, but even assuming it is, if spooks use a security/privacy tool, it’s probably pretty good.
I guess this means we’re not switching to RCS then?
RCS is not an open standard
Not to mention only available on certain phone brands and certain carriers (where I am, only one of major four).
Nope.
If I can implement my own RCS client, then I’ll consider it.
A lot of VPN servers in Netherlands may have something to do with it…
Let’s hope they’ll be able to continue to use it. It (and all other messengers with proper E2EE) is already on track to be outlawed in Sweden and France, and the new government in Germany will be pro mass-surveillance, too.
Moral of the story? Use
selfhostabledecentralized messaging instead.Milk is getting more expensive. Moral of the story: Buy a cow.
I really wish people would stop being so delusional about the average person’s technological abilities. jUsT TeLL grAn To sPin Up a mATrIx SErvEr… stfu
“Everyone should be hosting a server” was NOT my point, sorry if I got misunderstood. My mother could in no way host an XMPP server on her own - but I could register her an account on mine.
Rather, I meant: a) if you can host it, suggest your friends and family to use your server; b) if you can’t - that is still better: with multiple public servers available, there is no single point of failure, you can choose a server in whatever jurisdiction you want, or even an onion/i2p one.
Sorry for being harsh at the end. I just see this notion too often.
But still, your option b) is not self hosted. Maybe a better word to use would be decentralized then?
That’s just pedantry. ‘Selfhosted’ never meant that every single user has to host it themselves.
It’s not pedantry, it’s using the right terminology.
And yes, self hosted means hosted by yourself. It’s in the name. https://en.wikipedia.org/wiki/Self-hosting_(web_services)
The promise of self hosting is that you own your data which may be better for privacy/security if you know what you are doing. The same doesn’t apply if you have to trust a third party, even if it is a friend/family member who provides you with a service they host. They become a service provider to you.
self hosted means hosted by yourself
A lot of selfhosters share with family. I’m not gonna make my wife spin up her own servers when she can use mine.
Selfhost able. But yeah, “decentralized” would be indeed a more fitting term.
i rather talk to my grand parents over ham radio than giving them a smartphone
true but this is not yet easy enough for normal humans. selfhosting anything is not yet easy enough
My dad just said in the WhatsApp group, why not move to signal. I tried moving friends and family before, but now that there has been anti meta media reports in some news sources. But especially reports on signal in almost every major newspaper and news source.
It seems not only a push because of privacy, but even more a anti big tech(especially us tech) and buy/use eu stuff push.
I don’t mind the push I’m just curious if people stay on signal. Previous time there was a push to signal (during whatsapp technical difficulties and privacy push) people quickly want back to whatsapp.
Now my volunteer work, 1 friend and a family chat already moved to signal. The only thing I did was some explaining that you can just send images and so on. (That it’s not something scary)
What are the major differences between what you can do on Whatsapp vs Signal?
Whatsapp let’s you donate your contact list and social network to meta for them to resell.
Source?
It requires access to your contacts to work on Android. That is, you cannot type in a phone number. That’s an intentional choice.
Oh, that’s yucky. Thanks for the information, we haven’t used it since it got bought by Facebook.
Thank you!
Where you unable to find this without a provided link?
Yes.
it is just a messaging app, legit the exact same. group chats, image and video, previews to links i send, it even has a way higher level of customisability that i haven’t found elsewhere.
I use Telegram, like betamax have I backed the wrong horse?
All kidding aside from the other comments, Telegram is not secure or private. It’s not E2EE by default and getting it enabled is per-chat and convoluted. Frankly, I wouldn’t even trust it with cat pics I send to the bros let alone private messages… not to be fear mongering but do yourself a favor and get off Telegram.
Signal, despite some criticism that it’s “Not private enough etc.”, strikes a balance between usability, privacy and security. It’s also miles better than Telegram on all fronts.
A big issue we have in the privacy community is that it’s easy to have an “all or nothing mindset”. Even small steps in the right direction can be hugely beneficial. So, Signal is great. Use Signal.
I’m sure going all in on a Russian company is just fine. Their Wikipedia entry has nothing at all to indicate any shady behavior.
/s
Oops, I didn’t realise. I’d not fully adopted so will pivot. Ta
Nah we good bro (I have zero objective data to back this up but I want to think it’s true because I’d be too lazy to move)
All kidding aside from the other comments, Telegram is not secure or private. It’s not E2EE by default and getting it enabled is per-chat and convoluted. Frankly, I wouldn’t even trust it with cat pics I send to the bros let alone private messages… not to be fear mongering but do yourself a favor and get off Telegram.
Signal, despite some criticism that it’s “Not private enough etc.”, strikes a balance between usability, privacy and security. It’s also miles better than Telegram on all fronts.
A big issue we have in the privacy community is that it’s easy to have an “all or nothing mindset”. Even small steps in the right direction can be hugely beneficial. So, Signal is great. Use Signal.
Thanks for the detailed reply, will do as only a couple of mates have adopted it anyway and they’re double bagging with WhatsApp anyway
Good luck!
I found that once I plainly and simply explained it to those I want to stay in touch with and stated that this will be the easiest/fastest/only way to reach me, a lot of my connections actually adopted Signal. Once they realized that it’s just “whatsapp but more private and secure” more of their connections started to adopt it etc.
I did notice that for most of my friends they convince themselves that they can’t leave other platforms without loosing their connections, and end up keeping their accounts there in addition to Signal - but I’m living proof that it’s not that hard.
I’m a big proponent of “protocols not platforms” and the above is a great example of why this is the future we need to strive for. FOSS protocols that are immutable, secure and private (as needed).
Hypothetical: If, for example, Signal and Whatsapp were built on the same protocol - you could move to Signal without loosing your contacts/not being reachable etc. Whatsapp would also likely be less shitty because it would’ve been built on a strong protocol too.
It makes alot of sense.
I’m actively trying to limit my reliance on US technology, and while I appreciate Signal is a US organisation I’m going to have to make compromises and adopt a “least bad” mentality
I also have signal but for now most of the criminals I need to communicate with are on TG
Lmao even more reason to move away from TG tbh
Well how would I go about my business then?
I would have rather seen Element but hey, it’s a step in the right direction.
Why? Matrix sucks as an instant messenger app, it’s better as a Slack/Discord alternative.
Only because I’m not aware of other decentralised Signal alternatives. That’s on me.
XMPP
SimpleX is pretty rad.
Indeed, but funded by VC which makes me uneasy about its future.
Huh, I missed that. From the announcement:
Also, funding the work to transition the protocols to non-profit governance model would not have been possible without the donations we received from the users.
Our pledge to our users is that SimpleX protocols are and will remain open, and in public domain, so anybody can build the future implementations of the clients and the servers. We are building SimpleX platform based on the same principles as email and web, but much more private and secure.
If they stay true to that, they’re probably planning on building for-profit apps on top, while keeping the foundation free.
That sounds reasonable to me. Hopefully that happens.
Fair. I’ll still be on watch, since venture capitalists are scum. Hopefully donations will eventually become stable enough for a revenue stream for them.
My concern is that they’d demand not just profit, but growth. But I wonder if they’d be able to go on by charging for commercial use - hosting servers, tech support, etc
Not yet, it lacks a lot of the features Signal has and does not even have a proper ipad ui yet, nor proper profile syncing between devices.
If it ever has these it might be useable by the masses, until then it’ll be only the interest of privacy nerds.
Though really the most important thing is its lack of audits and a transparency report like Signal has. How can we be sure that its encryption/other security is up to standards or they don’t hand over anything to cops/courts without these two things? These are what most messengers fail at, especially open source decentralised ones to be fair.
Yeah, it’s a cool toy, but when I was picking a messenger to sell my SO on, Simplex failed my basic requirements:
- works on phone, desktop and laptop (messages arrive everywhere reliably)
Signal passed, so we went with that.
Simplex is still rad though, and I want to try building something on top of the protocol. I’m working on a P2P Reddit/Lemmy, and Simplex could be rad for DMs or something.
I didn’t personally have problems with reliability (same as for XMPP, Matrix however has broken for me a few times). As for multiple devices - I just use two, with identical names and profile pictures, one on laptop and one on phone.
Yeah, Simplex is reliable. My point is that if I have a conversion with my SO on one device and want to continue on another, I can’t really do that. So messages will come to one or another. When I tried it, they had a CLI tool to get that working, but that’s not going to be acceptable for my SO.
So I went with Signal. It’s easy for my SO to use and has strong privacy protections.
It only sucks because you keep using Element. Its the worst client out there, if you account for “doneness”
And what would be the best? Element is certainly the most popular.
I don’t like it at least because it’s Electron. I had better experiences with Nheko and Cinny.
Cinny is also Electron
What’s better? I’ve only used Element
Cinny
Try fluffychat is more user friendly and with better ui than elements. I used the “every image can be a sticker” feature to move people to matrix.
Isn’t Element based of Matrix? From what I’ve read, Matrix is a bit mid (not exactly mid, but I can’t think of any other word).
It works as it’s supposed to, though the handling of keys (strictly necessary for self-determined end-to-end encrypted chats) can be hard and annoying for people who have no experience. But once you get the hang of device confirmation you can use it seamlessly across multiple devices.
Fluffy Chat is great too!
Fuck signal. No “privacy” focused messenger should need a phone number to register…at that point u basically handing the agencys meta data on a platter
Don’t let perfect be the enemy of good. Getting people off of proprietary stuff is the first step. Whatever else is the next step.
Why are you licensing your comment?
But why do you want to license it at all? It’s normally not licensed. When AI vendors break the law they don’t care about licenses. Fuck, look at meta.
Hmm, did you read the links I posted?
Sure, what meta did is fucked up, but they are being sued. Just because someone ignores the law, does that mean that we should just stop doing something?
Yes, it did not answer my question. Legally you don’t have to do anything to make it so corporations legally can’t use this for AI unless you signed away your rights and if you signed away your rights you can’t change the license back with a notice. So what’s it actually for?
I should probably write a blog post about it. Basically it’s there to possibly get commercial LLMs in trouble for scraping licensed stuff. LLMs have been tricked into revealing their training data and gotten in trouble for that. There are also ongoing lawsuits due to those revelations. Maybe the most notable is the one against
Github’sMicrosoft’s CoPilot for spitting out licensed (GPL and also copyrighted from private repos) code.Whether the lawsuits will be successful or not is yet to be determined (Japan already considers nearly everything fair game for training AIs and machine learning). Whether they will have an impact if they are successful is also unknown. It just costs me a key-stroke (and the occasional response to a friendly question like yours), so I do it 🤷 Once all my hope is lost, I might stop.
From another answer. I highlighted the important part, which explains why the explicit link to the license text instead of it being implicit.
privacy != anonymity
nitpicking
No, that is an important distinction. People have different threat models. For most people, privacy without anonymity may suffice (i.e. I don’t mind that you know it’s me, I just don’t want you to see what I’m sending). For others (i.e. journalists, whistleblowers, more privacy-centric individuals), anonymity may be equally important.
Exactly. And requiring a phone number enables convenience features like:
- account recovery
- find contacts
- be found by other people
Once you have an account, you can disable the phone number and use Hawks usernames instead (can be changed at will) of disable discovery entirely.
It’s a pretty reasonable limitation IMO.
“Account recovery”, yeah but by whom?
“Find contacts”, dont you know who u wana talk with?
“be found by other people” ???
yeah but by whom?
Whoever controls the number. This is fine for 90% of people who hold on to their number, especially since no data is leaked unless you are sent messages after changing your number. But that’s the same for SMS, so it’s not a downgrade from that.
dont you know who u wana talk with?
Yes, but most aren’t on signal yet. When they do join, it’s nice for them to know you’re on it too so your communication can default to that.
You can disable discovery (I do).
Errybody hatin’ your logic but your logic is just that: paranoid and for no shortage of good reason and those are my dice.
Session
GPG
You know that your phone number is never saved anywhere? Signal only uses a cryptographic hash of your phone number.
Jmp.chat is worth being aware of
Also you’re a wackadoo
Yeah lets use the phone number of a middle man to sign up…sure u wont forget to relock the number every week so they dont get the power for account take over since they manage your number.
So no disagreement on the wackadoo part.
Tbh I hope you’re doing something cool with this paranoia. Like I want to see news articles about you secretly fighting evil, not sitting at home playing pirated video games.
I know it’s not the best, but it is great when you want someone to shift from other popular proprietary app like WhatsApp.
Replacing one phone number based system with another may not be a wise choise.
Wise, maybe not. Pragmatic, yes.
Pragmatism got us here. Maybe its time for people to start giving fucks, or like just dont communicate with me.