Signal is a walled garden. They refuse to allow federation and even prohibit any modified client to use their servers. It's the least open "open source" model, and once (if) they gain significant market share they can easily close down the app and lock-in the users. Please use and spread federated alternatives. Donate and contribute.
What alternative would you recommend?
Looking back at how Signal works
241–250 of 301 posts
Re: Looking back at how Signal works
#242I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…
Riot and almost all of the other clients I tried all phone home to some kind of metadata/identity or push server that is run by some private company I’ve never heard of (which isn’t part of Matrix/Riot). Check out its network traffic sometime.
For Push, whatever app you use needs to have a push server that talks through to Apple/Google if you use their push. For Riot, that server is run by the New Vector (vector.im), the outfit which makes Riot.
The network traffic should make this very clear.
Re: Looking back at how Signal works
#243Earlier quoted context omitted.
The way you use encryption matters as much as the quality of the crypto used. In Telegrams case, usage is all wrong and not even better than e.g. WhatsApp. Opt-in E2EE is worse than having it be default, and server side encryption with server side keys is bordering on the pointless.
Thank you for reflecting with an opinion. I also believe that opt-in E2EE is worse than having it by default. We have precedent for E2EE chats by default and syncing those E2EE messages across devices using the latest RiotX for Matrix. I'd love to see Telegram adopt that strategy. I use Telegram because it delights its users. When I have tried to bring friends and family to first Riot, then Signal, the experience I e…
Re: Looking back at how Signal works
#244Earlier quoted context omitted.
> Meanwhile, yes, Matrix took years to add encryption, but it works much better than Signal, even with quite a few small bugs. I'm not sure which Matrix client you use, but clients like Riot don't even let you opt out of sending read receipts unless you edit `/etc/riot/config.json` to enable experiments and then go into the settings to disable read receipts. Problems like this (and issues like this [0]) give me the i…
I'm a massive Matrix fan and have high hopes for it but in experiments we've done with activist and journalist partners we've found the Riot.im client often gets a bit complicated for people to use. I think the main issue people have is related to keys. As I techie I love the options but I find many don't like having all the options. Signal of course is a lot easier as it hides many of those issues in the UI/UX.
Re: Looking back at how Signal works
#245Earlier quoted context omitted.
I knew Signal was against federation but I hadn’t realized they had pretty much banned third party clients. That would otherwise have been a really easy win for people that actually care about the system integration, performance, and architecture of desktop clients enough to shun electron “clients.”
The Signal team has always been open about the reason why they reject third-party clients: they claim that XMPP adoption was hindered by the inability of a user’s software to know if the software on the other end supports the same feature set. XMPP had grown into a large set of features that some clients supported and others did not. If Signal introduces a new feature, it knows that all users’ devices will support th…
Re: Looking back at how Signal works
#246Earlier quoted context omitted.
I'm a massive Matrix fan and have high hopes for it but in experiments we've done with activist and journalist partners we've found the Riot.im client often gets a bit complicated for people to use. I think the main issue people have is related to keys. As I techie I love the options but I find many don't like having all the options. Signal of course is a lot easier as it hides many of those issues in the UI/UX.
Out of curiousity, did you ever try keybase? It always struck me that usability as well as security were their primary focus. And I think they did the whole key management / chain of trust thing really well. Hopefully none of that changes now that they've been acquired by zoom.
Keybase claims that it is, but it's a lie that nobody verified: https://security.stackexchange.com/questions/222055/how-can-...
Re: Looking back at how Signal works
#247Earlier quoted context omitted.
> I'm thinking of switching to Matrix solely because the desktop client is pretty bad. Oooooh, I've got some bad news for you.
What is it? Riot works beautifully.
Re: Looking back at how Signal works
#248Earlier quoted context omitted.
The legal entities can move to other jurisdictions, sure, but it doesn't matter because app distribution still occurs primarily through USA-based Google Play and USA-based Apple App Store—both of which can easily geofence apps as they please (or as they're required). This is one of the reasons I've started to appreciate Matrix a lot more lately. https://matrix.org/blog/2020/01/02/on-privacy-versus-freedom
The real solution is switching to open source mobile operating systems.
Re: Looking back at how Signal works
#249Is it worth trying to move my friends from WhatsApp to Signal? As I understand it, they're both e2e encrypted. I'm also trying to move my chats from SMS and Gchat to something encrypted, but am torn between WhatsApp and Signal. The former has more of a buy-in with my contacts already. I realize WhatsApp is owned by Facebook, but isn't the whole point of e2e encryption that you don't have to trust the intermediate inf…
Even if you turn it on and you're not afraid of the server swapping the key when you send a message (which is fair enough), do all your contacts also have it turned on? And would they tell you immediately and out of band (otherwise the attacker can suppress or change the message) that they saw your key change?
But an even bigger reason I don't have whatsapp is because of Facebook. Metadata has already been mentioned by others so I won't repeat that.
Re: Looking back at how Signal works
#250Earlier quoted context omitted.
I, for one, have a bigger problem with it forcing the use of phone numbers as a sign-in method. They're an arbitrary identifier from a legacy system that there's not really a point in continuing to extend, because if your device is capable of anything more advanced than SMS it's also capable of... well, this. Also KaiOS and the like are making chat feasible even on feature phones. Don't get me wrong, RCS will be a fi…
"even on feature phones"? It was perfectly possible at least back in the early 2000's. Where I'm from, we've gone through a lot of different IMs over the years, including XMPP (which I was a big fan of, but started to despise because it had such terrible support for mobile clients). Many J2ME clients had pretty advanced features like group chats and file transfers.