I can't see Jitsi there
Messenger systems compared by security, privacy, compatibility, and features
101–110 of 242 posts
Re: Messenger systems compared by security, privacy, compatibility, and features
#102This is neat but it has plenty of flaws. I wish the definitions were spelled out. It says Signal isn't "anonymous", which I assume means "uses a phone number to find peers". And it has the usual feature matrix problem: sure XMPP "does E2E". But what does that mean? It supports S/MIME. Do you want S/MIME? (You don't.) It supports OTR, TS and SCIMP too: but you need to be an expert in messaging schemes to understand ho…
> It supports S/MIME. Do you want S/MIME? (You don't.) Could you provide your source? I've never seen S/MIME used in XMPP. Client certificates for authentication sure but not for E2E security. > It supports OTR, TS and SCIMP too: but you need to be an expert in messaging schemes to understand how those are different. OTR is being rolled back from clients in favor of OMEMO for good reasons: https://conversations.im/om…
I am aware that OTR is being rolled back. My point is that extensibility is at odds with practical security and privacy for the vast majority of users. The people who need it the most do not understand the difference between OMEMO and OTR, but I can tell them to go install WhatsApp or Signal, give them a rough idea of why you want one or the other, and everything will be copacetic.
Re: Messenger systems compared by security, privacy, compatibility, and features
#103Earlier quoted context omitted.
Fair enough, but this is kind of inherent for anything based on open standards. Was your email encrypted? It depends on whether the sending and receiving mailserver support TLS. Is your website visit perfect-forward-secret? Depends on whether your browser and the webserver support modern cipher suites. Is your DNS request encrypted? Only if your OS and your DNS server support DNSSEC or DoH. These are valid challenges…
How do I know my XMPP client is actually doing what it says? Are you saying the provenance for my XMPP client is fundamentally better than that of the WhatsApp app?
Other than that, sure, you have no guarantees, yet it's still desirable for such critical security components to be free, or at least "open source".
Re: Messenger systems compared by security, privacy, compatibility, and features
#104What is the data source for all of these? I'm particularly curious about a number of the "claimed" entries.
+1 It seems like someone just created a spreadsheet with no description of what methodology was used to test the assertions.
Re: Messenger systems compared by security, privacy, compatibility, and features
#105Earlier quoted context omitted.
How do I know my XMPP client is actually doing what it says? Are you saying the provenance for my XMPP client is fundamentally better than that of the WhatsApp app?
OMEMO and its implementation in Conversations has been security audited by an independent entity. Other than that, sure, you have no guarantees, yet it's still desirable for such critical security components to be free, or at least "open source".
Why the scare quotes?
What about software's source code being available makes it more desirable for your non-technical users who will never modify their software?
Re: Messenger systems compared by security, privacy, compatibility, and features
#106This is neat but it has plenty of flaws. I wish the definitions were spelled out. It says Signal isn't "anonymous", which I assume means "uses a phone number to find peers". And it has the usual feature matrix problem: sure XMPP "does E2E". But what does that mean? It supports S/MIME. Do you want S/MIME? (You don't.) It supports OTR, TS and SCIMP too: but you need to be an expert in messaging schemes to understand ho…
Re: Messenger systems compared by security, privacy, compatibility, and features
#107Earlier quoted context omitted.
How do I know my XMPP client is actually doing what it says? Are you saying the provenance for my XMPP client is fundamentally better than that of the WhatsApp app?
OMEMO and its implementation in Conversations has been security audited by an independent entity. Other than that, sure, you have no guarantees, yet it's still desirable for such critical security components to be free, or at least "open source".
EDIT: I previously said "turns off E2E", which I didn't say in my original referred-to post, and that's more misleading than "hamstrings", which is how the actual attack works.
Re: Messenger systems compared by security, privacy, compatibility, and features
#108Earlier quoted context omitted.
OMEMO and its implementation in Conversations has been security audited by an independent entity. Other than that, sure, you have no guarantees, yet it's still desirable for such critical security components to be free, or at least "open source".
That's all fine but not responsive to my point. GP post said "but what if whatsapp silently hamstrings e2e overnight" -- my point is: what if my XMPP client/server does? EDIT: I previously said "turns off E2E", which I didn't say in my original referred-to post, and that's more misleading than "hamstrings", which is how the actual attack works.
Re: Messenger systems compared by security, privacy, compatibility, and features
#109This is neat but it has plenty of flaws. I wish the definitions were spelled out. It says Signal isn't "anonymous", which I assume means "uses a phone number to find peers". And it has the usual feature matrix problem: sure XMPP "does E2E". But what does that mean? It supports S/MIME. Do you want S/MIME? (You don't.) It supports OTR, TS and SCIMP too: but you need to be an expert in messaging schemes to understand ho…
> Use WhatsApp to talk to normal people. Use Signal for nerds. This has been my go-to advice for a while now too! The key driving point is that amazing crypto is 100% useless if the person you're talking to doesn't use it, or uses it incorrectly. The only sticking point with the above advice is the nerds who think they understand crypto but don't and insist on you using some crazy app :/
Maybe try listening to those nerds and try out some open alternatives with security that is possible to verify.
You might be surprised to find both tools are pretty low on the list in respect to security and privacy compared to tools with smaller marketing budgets.
Re: Messenger systems compared by security, privacy, compatibility, and features
#110I can't see Jitsi there
also, what about 'blockchain messaging' apps like Dust, Echo etc. ?
Blockchain, as usual, purports to solve a problem nobody had. Dust doesn't try to address the simplest, best-understood problems we have for reputation systems on chained blocks.