> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...
Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.
I don't trust Signal
81–90 of 473 posts
Re: I don't trust Signal
#82But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…
Edit: Yes, apparently they have a method of doing private contact discovery and, IIUC, even a method for the client to verify that the server is running the source code they expect: https://signal.org/blog/private-contact-discovery/#trust-but...
Re: I don't trust Signal
#83Is there a preference of Telegram over Signal or vice versa?
Telegram doesn't use end-to-end encryption by default and likely never will. Paul Durov has been quite hostile against that feature in the past. So yes, choose Signal over Telegram. I find that instead of trying to convince friends/family to use Signal I just tell them "use Signal as your default SMS app" or install it myself for them. This tactic worked well in the Internet Explorer/Firefox and then Chrome transitio…
I would to those following it that this advice is likely most useful if your family members are on Android devices.
iOS does not allow you to change the default SMS application and if your family member is on iOS, the iMessage platform lock in is nearly impossible to break out of.
Re: I don't trust Signal
#84OWS's staunch refusal to permit anything other than phone numbers as identifiers should tell you everything you need to know about Signal. It is an authenticated, nonrepudiable communications platform using identifiers that are very difficult (possible, yes, but most people will get it wrong) to comprehensively anonymize. The ability to present nonrepudiable communications to a judge is precisely the wet dream of law…
Re: I don't trust Signal
#85TL;DR he doesn’t trust Signal because he doesn’t trust the Android operating system, and something about federation. > No doubt these are non-trivial problems to solve. But I have personally been involved in open source projects which have collectively solved similarly difficult problems a thousand times over with a combined budget on the order of tens of thousands of dollars. Shut up and code then. I’ll personally r…
The author expressly endorses Matrix.
The F-Droid argument is a really empty one. Packages are cryptographically signed? Are you verifying those signatures? In an article about "trust", can you explain how exactly you trust F-Droid packages and not Google Play ones?
What about iOS?
The whole article is extremely vapid and lacks any compelling argument. Signal has introduced state-of-the-art encryption to millions of people in an accessible way.
The author goes on to poke fun at the animated GIF feature of Signal as if it is a waste of time compared to working on an F-Droid distribution, but neglects to address five of the seven points written by Moxie (which he links to) about why they chose not to do that.
Re: I don't trust Signal
#86But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…
I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…
Re: I don't trust Signal
#87> Truly secure systems don’t require trust. This is a chat app so, by definition, security requires trusting at least one other person. Also, I think experience shows that secrets can often be least trusted to those who have some interest in/use for them, with the secret owner often being the least trustworthy of all. So I'd say that if you trust yourself you're already probably trusting one of the weakest links in w…
Re: I don't trust Signal
#88Some version of this post seems to circulate every few months or so. This one is more direct in its accusations of Moxie acting in bad faith. I think this is disingenuous. Moxie has been very clear[0] about the tradeoffs that Signal has made and the reasons for them. It's fine to be dissatisfied with those choices. It's another thing entirely to accuse Moxie of dissimulating. Personally, I'd like to see Signal replac…
Re: I don't trust Signal
#89Re: I don't trust Signal
#90Seriously, why do they use the smartphone in the first place? The smartphone ecosystem, be it Android or iPhone, is not secure. It can not be trusted. Even if we avoid Apple and Google's software distribution platform, Your smartphone still has binary blob kernel module, baseband processor and the OS runs on top of that. People who claims secure and trust on top of smartphone are all liar, idiot or both. Don't use th…