Is no one going to talk about how much more complex matrix is than signal?
On Privacy versus Freedom
61–70 of 209 posts
Re: On Privacy versus Freedom
#62I saw Moxie Marlinspike's talk when it was posted on CCC's official channel [1] and was disgusted by it. The talk has been now censored and video was made private. It was one of the most defeatist talks I've ever come across when it comes to messaging and privacy. His message was basically that anything you do is pointless and that his and WhatsApp/Facebook's way is the right one. I've used Signal on few occasions in…
Centralized services should be avoided for a multitude of reason, the primary one is being dependent on some company that offers you the service and can and probably will shut down one day, with the result of loosing all the things you had on that service.
Look at the past, how many centralized services closed down and we lost all our data? Instead decentralized services are still up and running: email, usenet, IRC, even if unfortunately a bit forgotten these day (with the exception of email, even if most of people uses GMail anyway so it's in fact centralized...)
Re: On Privacy versus Freedom
#63I won't touch signal because I care about user freedom more than privacy. (Both are important) No 3rd party clients, mandatory updates, mandatory google play services, and mobile only are all deal breakers.
Google Play Services obviously aren't required to run Signal on iOS.
Re: On Privacy versus Freedom
#64Earlier quoted context omitted.
Wire seemed like a decent alternative where you're not required a number, I think only an email. Also you can delete your account.
I read on a privacy-oriented website that Wire was purchased by an American company not trusted for its record on privacy (or perhaps it was that since the company is American, their data can be read by the US govt.). I can't find it now though. There isn't anything mentioning it on the website of `www.privacytools.io`: https://www.privacytools.io/software/real-time-communication...
Re: On Privacy versus Freedom
#65I think the timing makes Moxie's point very well without him saying a thing. All these years later Matrix only has... The ambition to some day try to offer the core privacy features Signal already delivered back then. Some of the most basic stuff is, you believe, almost kinda sorta done. This is, to be clear, much better than just sitting back insisting you were right but not lifting a finger. But for an actual user…
And you know another thing? Email works great to me, and it's decentralized. I have my email server, with my domain, so I don't depend on anyone to provide me a service. I have full control of my data that is on my server. I can even send encrypted emails with GnuPG without any problem, and it's as secure as Signal, if not better. I can use whatever client I want, a fancy application, a web interface, or as I do a small CLI program since I don't use graphical user interfaces.
Sure, having a chat protocol that is decentralized like email would be great! I wish that Matrix will evolve in something usable in the following years, we need that. I need a chat application where I can have a client that I can use in my terminal, and Signal doesn't do that (Telegram does, for example, since the API is more open, and it's what I use second to email).
Re: On Privacy versus Freedom
#66I saw Moxie Marlinspike's talk when it was posted on CCC's official channel [1] and was disgusted by it. The talk has been now censored and video was made private. It was one of the most defeatist talks I've ever come across when it comes to messaging and privacy. His message was basically that anything you do is pointless and that his and WhatsApp/Facebook's way is the right one. I've used Signal on few occasions in…
Wire seemed like a decent alternative where you're not required a number, I think only an email. Also you can delete your account.
Re: On Privacy versus Freedom
#67I saw Moxie Marlinspike's talk when it was posted on CCC's official channel [1] and was disgusted by it. The talk has been now censored and video was made private. It was one of the most defeatist talks I've ever come across when it comes to messaging and privacy. His message was basically that anything you do is pointless and that his and WhatsApp/Facebook's way is the right one. I've used Signal on few occasions in…
The talk wasn't "censored"; the conference made a mistake by recording and posting it in the first place.
Re: On Privacy versus Freedom
#68Earlier quoted context omitted.
Here's his reasoning: https://twitter.com/moxie/status/1211443530335281153
> I just prefer to present something as part of a conversation that's happening in a place, rather than a webinar that I'm broadcasting forever to the world. To me it sounds an awful lot like not wanting to be scrutinized or held accountable for what he says. I also find this rather disappointing as it excludes anyone who is unable, for whatever reason, to be at his talks from hearing what he has to say. Given how in…
Re: On Privacy versus Freedom
#69Earlier quoted context omitted.
Wire seemed like a decent alternative where you're not required a number, I think only an email. Also you can delete your account.
It's fine, but you should know that pretty much everything Moxie and Signal talk about contrast sharply with Wire. For instance: last I checked, Wire stores your entire social graph on their servers in a database --- effectively forever, Wire stores a plaintext log of everyone you've communicated with.
This is similar guarantees that a lot of other chat and VPN companies offer. Personally I would consider any information given out to a company non-secret, especially to those operating outside my jurisdiction.
Re: On Privacy versus Freedom
#70Earlier quoted context omitted.
It's fine, but you should know that pretty much everything Moxie and Signal talk about contrast sharply with Wire. For instance: last I checked, Wire stores your entire social graph on their servers in a database --- effectively forever, Wire stores a plaintext log of everyone you've communicated with.
To be fair, since there is no remote attestation possible for the Signal servers, and you realistically can't run one yourself, you only have their word that they don't store any of that information. This is similar guarantees that a lot of other chat and VPN companies offer. Personally I would consider any information given out to a company non-secret, especially to those operating outside my jurisdiction.
So the logic you're using here is essentially: "since we have to take Signal's word for some part of this, we might as well use services that promise the exact opposite". I don't find that argument persuasive, but you do you.