this post was submitted on 14 May 2024
108 points (82.5% liked)

Privacy

31893 readers
581 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 19 points 5 months ago

Blaming the Americans is a signature "Russia has fucked with this company" trademark.

[–] [email protected] 0 points 5 months ago

I wonder if it's legit or just another attempt at manipulating markets

[–] [email protected] 34 points 5 months ago (1 children)

If one is to compare apple to apples, imho the decision to choose between Signal, Whatsapp and Telegram and other "messengers" is obvious and clear.

Signal is fully open source! You can run it on-premises, if you know your business!

Why are we not talking about it?

I hope my comment will not be discarded/removed as not being in sync with the narative... 😉

[–] [email protected] 8 points 5 months ago (1 children)

Signal is fully open source! You can run it on-premises, if you know your business!

Why are we not talking about it?

Unless something has drastically changed recently, the official Signal service won't interoperate with anyone else's instance. That makes its source code practically useless for general-purpose messaging, which might explain why few are talking about it.

[–] [email protected] 3 points 5 months ago* (last edited 5 months ago) (2 children)

My point is that you have all the open source software components needed to run secure communications, on your own premises, for your own users/community in case you are not trusting Signal's infrastructure.

If you know any other similar alternative with strong encryption open source protocols please let me know! I love learning new things everyday!

Cheers!

[–] [email protected] 2 points 5 months ago
[–] [email protected] 4 points 5 months ago* (last edited 5 months ago) (1 children)

on your own premises, for your own users/community in case you are not trusting Signal’s infrastructure.

Yes, that's an example of data (and infrastructure) sovereignty. It's good for self-contained groups, but is not general-purpose messaging, since it doesn't allow communication with anyone outside your group.

If you know any other similar alternative with strong encryption open source protocols please let me know! I love learning new things everyday!

Matrix can do this. It also has support for communicating across different server instances worldwide (both public and private), and actively supports interoperability with other messaging networks, both in the short term through bridges and in the long term through the IETF's More Instant Messaging Interoperability (MIMI) working group.

XMPP can do on-premise encrypted messaging, too. Technically, it can also support global encrypted messaging with fairly modern features, with the help of carefully selected extensions and server software and clients, although this quickly becomes impractical for general-purpose messaging, mainly because of availability and usability: Managed free servers with the right components are in short supply and often don't last for long, and the general public doesn't have the tech skills to do it themselves. (Availability was not a problem when Google and Facebook supported it, but that support ended years ago.) It's still useful for relatively small groups, though, if you have a skilled admin to maintain the servers and help the users.

[–] [email protected] 2 points 5 months ago

Thank you very much for the info!

[–] [email protected] 10 points 5 months ago* (last edited 5 months ago) (1 children)

I'm always amazed how people come out of the woodwork to defend Signal any time any criticism of it comes up. It's become a sacred cow that cannot be questioned. Whatever you may think of Telegram should bear zero weight on your views of Signal.

The reality is that developers of Signal have close ties to US security agencies. It's a centralized app hosted in US and subject to US laws. It's been forcing people to use their phone numbers to register, and this creates a graph of real world contacts people have. This alone is terrible from security/privacy perspective. It doesn't have reproducible builds on iOS, which means you have no guarantee regarding what you're actually running. These are just a handful of things that are publicly known.

And then we know stuff like this happens. NSA suggested using specific numbers for encryption that it knew how to factor quickly. The algorithm itself was secure, but the specific configuration of how the algorithm was implemented allowed for the exploit https://thehackernews.com/2015/10/nsa-crack-encryption.html

These kinds of backdoors are very difficult to audit for because if you don't know what to look for then you won't have any reason to suspect a particular configuration to be malicious. Given the relationship between people working on Signal and US government, this is a real concern.

The same kind of scrutiny people apply to Telegram and other messaging apps should absolutely be applied to Signal as well.

[–] [email protected] 7 points 5 months ago

I’d just like to add that you can use a temporary phone number service to sign up to Signal as you only need a phone number to register, not to actually use Signal.

[–] [email protected] -2 points 5 months ago (1 children)

Idk how secure telegram is but cmon signal is shady AF . They won't let fdroid have it cause they want to sign their own keys or some shit but there is a speculation its because they can roll out custom apk to targets which governments want which is just not possible if it is hosted by someone like fdroid . Even telegram allows that and they even allow third party apps which signal won't .

SimpleX and briar is the best option if your actually worried about privacy .

This comment is copy pasted from another thread where I had the same opinion

load more comments
view more: next ›