Live data from Hacker News

Messenger systems compared by security, privacy, compatibility, and features

docs.google.com

41–50 of 242 posts

Re: Messenger systems compared by security, privacy, compatibility, and features

#41
post #25

There still isn't a popular messaging and voice call platform that supports private end-to-end encryption by default. How terrible is this? I mean it would be so trivial to establish a secure and private communications standard. Europe and North America has a population of almost a billion people combined. If 500 millions of those live in first-world conditions and only 1% cares about privacy, with $1/year worth of g…

WhatsApp does but the author of this sheet has chosen to list it as "claimed", despite other also-unverified clients like Telegram getting a "true" for their (non-default) e2e support.

FWIW I believe Riot/Matrix are planning e2e by default as soon as their implementation stabilises. Theirs is more complex/powerful than WhatsApp's though since they have multidevice support (which WhatsApp lacks). They've avoided making it default sofar due to bad UX and the possibility of losing access to conversations across devices, but it's improving rapidly.

Re: Messenger systems compared by security, privacy, compatibility, and features

#42
Well, that is a protocol comparison. A client comparison would be much closer to the real world user experience. Don't get me wrong, I am a huge fan (and daily user) of XMPP, but the best protocol will not be of any use if the clients are too complicated or buggy to use.

So yes, XMPP supports audio and video calls but finding two different clients which work on the first try together can be a challenge. Sometimes I wish there would be some compatibility XEP which defines a common set of supported XEPs including a test suite to run it against.

Re: Messenger systems compared by security, privacy, compatibility, and features

#43

Earlier quoted context omitted.

Doesn't WhatsApp do that? ( https://faq.whatsapp.com/en/android/28030015/ )

If I recall correctly Facebook has plans to end E2E encryption in order to serve personalized ads.

Maybe, but at least currently it does support E2E.

Re: Messenger systems compared by security, privacy, compatibility, and features

#44

I would like to use Riot/Matrix but its UI (at least on Android) is terrible. I can't convince non-technical friends & family to switch. Part of the problem is the inability to assign nicknames to contacts, so you have to remember everyone's Matrix ID.

For me, the problem is how incredibly slow Riot is (and every other client I've tried has almost unusable bad UI, sometimes in combination with being slow). IMO: Text chat with a few emojis and images here and there should not ever be among the things that slows your computer to a crawl. EDIT: I'm speaking of the UI, not the network connection; the latter is sometimes slow too, but that's understandable

It's very likely that what was slow there was not riot, but the server. The Matrix.org homeserver is notoriously overloaded.

Re: Messenger systems compared by security, privacy, compatibility, and features

#45
This is neat but it has plenty of flaws.

I wish the definitions were spelled out. It says Signal isn't "anonymous", which I assume means "uses a phone number to find peers". And it has the usual feature matrix problem: sure XMPP "does E2E". But what does that mean? It supports S/MIME. Do you want S/MIME? (You don't.) It supports OTR, TS and SCIMP too: but you need to be an expert in messaging schemes to understand how those are different. None of them implement double ratchets. None of them implement even close to the privacy features Signal has implemented. But on this diagram it is clearly better because there is more green and less red.

Another example: "open server" and "on-premise" says nothing about whether or not you really want to run one of those instances. It just says that hypothetically one could.

In terms of errors: the linked "E2E audit" for Telegram did not audit E2E at all, and in fact only cites sources saying that it's probably fucked. Wire has a real audit that isn't listed. WhatsApp uses Signal, just with fewer of the.

Use WhatsApp to talk to normal people. Use Signal for nerds, and... probably Matrix for group collab? Or maybe stop caring about secure messages for group collab so much :-)

Re: Messenger systems compared by security, privacy, compatibility, and features

#46

I would like to use Riot/Matrix but its UI (at least on Android) is terrible. I can't convince non-technical friends & family to switch. Part of the problem is the inability to assign nicknames to contacts, so you have to remember everyone's Matrix ID.

I won't argue any of your UI opinions other than to say that riot - which is only one of the many possible clients [1] over the matrix protocol - is still in early days, and is getting better with each version. That being said, as far as having to remember everyone's matrix id, I'm sure users had similar complaints back when email addresses were still novel. I'm sure conceptual address books will be a thing in future matrix clients - both riot as well as others. Failing that, you can always submit a feature request! [2]

[1] https://matrix.org/docs/projects/clients-matrix [2] https://github.com/vector-im/riot-web

Re: Messenger systems compared by security, privacy, compatibility, and features

#48
post #25

There still isn't a popular messaging and voice call platform that supports private end-to-end encryption by default. How terrible is this? I mean it would be so trivial to establish a secure and private communications standard. Europe and North America has a population of almost a billion people combined. If 500 millions of those live in first-world conditions and only 1% cares about privacy, with $1/year worth of g…

Someone will correct me if I'm won't but I believe Apple Messages are end to end encrypted by default. I'm not sure if FaceTime audio/video is encrypted.

Re: Messenger systems compared by security, privacy, compatibility, and features

#49

Well, that is a protocol comparison. A client comparison would be much closer to the real world user experience. Don't get me wrong, I am a huge fan (and daily user) of XMPP, but the best protocol will not be of any use if the clients are too complicated or buggy to use. So yes, XMPP supports audio and video calls but finding two different clients which work on the first try together can be a challenge. Sometimes I w…

Sounds like you may want to consider writing the spec for such a XEP?

Re: Messenger systems compared by security, privacy, compatibility, and features

#50
post #25

There still isn't a popular messaging and voice call platform that supports private end-to-end encryption by default. How terrible is this? I mean it would be so trivial to establish a secure and private communications standard. Europe and North America has a population of almost a billion people combined. If 500 millions of those live in first-world conditions and only 1% cares about privacy, with $1/year worth of g…

What do you mean by “private” so as not to have WhatsApp and iMessage fit this description ? Because as far as I understand, they do. Especially the telephone lines bit; iMessage and WhatsApp offer more privacy than telephone lines did, already at the operator level, but definitely at the tapping level.

Anonymous account creation? Open source? Audited?

Post reply on HN