didn’t even know tab groups were coming. interested to try them out!
didn’t even know tab groups were coming. interested to try them out!
to add even more to what’s already been said, even if Signal’s infrastructure was compromised and they could see messages traveling through their servers, each one is encrypted, the keys are rotated with every message (cracking one, which is nearly impossible, doesn’t give you access to previous or future messages), and thanks to Sealed Sender, only the recipient knows who a message came from. There are many other layers that they’ve engineered to ensure they can’t know anything about you, like private contact discovery, using secure enclaves, remote attestation, etc.
MLS only deals with encryption and key management, which is great but that’s been a “solved” problem since TextSecure (now Signal) introduced the TextSecure Protocol (now the Signal Protocol) in 2013.
What I’m aware is missing with RCS / MLS compared to Signal (someone with more recent knowledge please correct me):
RCS still leaks metadata like a sieve. Encryption, considering the platforms that exist today (Signal and SimpleX), should not be the minimum requirement. Plain-text messaging should not even be possible in modern secure messaging platforms. The platform should be open source and be engineered to mitigate the collection of metadata - like Signal and SimpleX.
Signal is a publicly available app that provides encrypted communications, but it can be hacked.
This is misleading statement that will only confuse people who want to use a secure messenger.
To clear things up with anyone who’s not technically inclined: Anything can be theoretically hacked. Signal has not been hacked and has no history of being compromised.
The Signal “hacks” that linked people’s Signal client to devices that aren’t theirs were sophisticated phishing/spoofing attacks. The equivalent of getting someone to click a malicious link via email because it looked like the real thing.
A reminder that you still need to do your due diligence even when using a secure service. Technology alone cannot completely protect you.
I love hearing good news 🥰
asked this somewhere else, but does anyone know how it compares to Cryptpad which is also developed in France, open source, self hostable, collaborative, and end-to-end encrypted?
anyone know how this compares to Cryptpad? I think it’s developed out of France, also open source, self-host-able, collaborative and end-to-end encrypted!
It’s not a Signal feature so its likely an app that has the permission to “display over other apps”. Search your Android settings for “display over other apps” and see what apps have this permission. On my phone only Phone, Google, and Google Play Protect Services are allowed. Disable anything else and test. If its not any other app, its probably the keyboard, since keyboards have permission to overlay input fields (I think).
There’s at least two of us who use stories! I use it the same way, its a quick way to share what’s going on without directly pinging people who may not be interested.
H.265 is patent encumbered. Blame the 2 or 3(?) patent pool holders (for-profit corporations, unlike non-profit -and-slowly-losing-market-share Mozilla) for not making it free to use for everyone.
This is why AV1 is preferred, it saves bandwidth and there’s no threat of being sued into oblivion.
But then you’re indirectly giving the enemy (Google) power by increasing their browser market share, which in turn lets them dictate the future of the web.
The “ArcaneChat/DeltaChat servers” are just normal email servers with some default configurations and tweaks for privacy/security and speed
I know what the servers do. My question is direct, because it would answer an important detail that has been left unanswered. Can the chat clients work with any email provider or only Delta/Arcane configured email servers? Because if they work with any email provider, people are going to shoot themselves in the foot by allowing insecure servers. If its the latter, then at least the clients enforce some safeguards.
this needs to be done 👍
And until its done, its leaking metadata.
This is a pretty theoretical situation […]
A lot of security is based on theoretical attack vectors. This is why security is hard, you have to invest time and effort to secure areas that could be exploited at some point in the future, not just what we know today. It’s why Signal and Apple have developed and enabled quantum-resistant encryption in their messaging platforms (Source).
first the attacker needs to get control of your chatmail provider/server and start collecting your messages,
Considering people get hacked left and right all the time and the constant barrage of breaches, not the highest bar set.
Tesla facilities face wave of attacks as Elon Musk delves into politics
I love good news!
XMPP is more comparable to Signal, yes.
XMPP allows unencrypted messages and leaks metadata - Signal does neither.
Signal does need (yes, need) a phone number, and most people only have one so that is identifiable info.
Signal is basically a privacy enhanced text/SMS/phone replacement. I can give my phone to someone in person and they can immediately start “texting” me on Signal - this is a feature (as well as a con to some people).
This puts it at mostly the same level as some competitors, including WhatsApp which is often advised against.
People advise against Whatsapp because while it uses Signal to encrypt message contents, they take no effort to minimize the collection of metadata - Signal’s been compelled by court to present all data it has on its users various times and the only info they have is the day/time you signed up for their services and the last day (not time) one of your clients pinged their servers - Source: https://signal.org/bigbrother/
I have yet to find any other free service that collects this little information and works just as well as a normal non-encrypted messenger. Even Signals sticker packs are end-to-end encrypted - Source: https://signal.org/blog/make-privacy-stick/
Maybe I’m confused, do the DeltaChat and ArcaneChat clients only work with DeltaChat/ArcaneChat servers?
Edit: forgot to mention I can see the sender & recipient addresses (Signal uses sealed sender to minimize this metadata leak). I can also see what time the message was sent, this is the kind of metadata Meta collects through Whatsapp even though they also encrypt message content. It doesn’t seem - although maybe it now does - that DeltaChat nor ArcaneChat support key ratcheting, so if someone’s intercepting messages they can decrypt all future + past messages. Lastly it doesn’t seem either support any kind of protection against attacks from quantum computers. Currently Signal, SimpleX and iMessage are the only clients that do protect you from these kind of attacks.
Also “Minimal metadata” says “no” while there is no personal data at all required to use ArcaneChat, accounts are fully anonymous hence what metadata and from whom?
Unfortunately email wasn never built for privacy. As DeltaChat and ArcaneChat both run on top of email, they suffer from many of the same privacy issues that have existed since the inception of email, over 50 years ago.
Stephanie Lovins is a piece of shit racist
Just a reminder for anyone not in the know:
While Bluesky is better than Xitter right now, don’t forget that it’s still a centralized service that has censored - and will continue to censor - content they disagree with. Bluesky Relay servers costs so much to run that it’s only financially feasible for big corporations to run them. This forces centralization, although technically can be decentralized, and puts it’s end users onto the same path of enshittification that Xitter and other social networks have gone through.
Mastodon, while imperfect, is actually decentralized (including DM’s - all Bluesky DMs are centralized amd can be viewed by its admins) and cannot suffer this type of censorship.
it’s only gotten better. now you can run it in your browser and play local files
https://webamp.org/