Encrypted messengers: Riot, not Signal, is the future
titus-stahl.de
Encrypted messengers: Riot, not Signal, is the future
1–10 of 178 posts
Re: Encrypted messengers: Riot, not Signal, is the future
#2[1] https://matrix.org/blog/2016/11/21/matrixs-olm-end-to-end-en...
Re: Encrypted messengers: Riot, not Signal, is the future
#3Re: Encrypted messengers: Riot, not Signal, is the future
#4Re: Encrypted messengers: Riot, not Signal, is the future
#5Is this correct? I've never bothered looking it up, but Signal was connecting me with people in my phone's address-book.
Re: Encrypted messengers: Riot, not Signal, is the future
#6I have the impression that Signal by now has such a great brand name that mere technical objections won't affect its growth for a very long time.
Re: Encrypted messengers: Riot, not Signal, is the future
#7I have the impression that Signal by now has such a great brand name that mere technical objections won't affect its growth for a very long time.
I wonder if the name of Riot will be a hindrance for widespread adoption. Most people don't like riots.
Re: Encrypted messengers: Riot, not Signal, is the future
#8Are there any plans to do a security audit on Riot? The useful report by NCC [1] looks at libolm (which implements the end-to-end encryption) but of course that's only part of the whole product. [1] https://matrix.org/blog/2016/11/21/matrixs-olm-end-to-end-en...
Re: Encrypted messengers: Riot, not Signal, is the future
#9I think something worth keeping in mind is that almost everyone who works in secure messaging agrees on one thing: that electronic mail is not the future of secure communication.
There's no fundamental reason why that should be the case. The store-and-forward model used by SMTP could be made to work for asynchronous secure group messaging. You can get forward and future security with it. It can interoperate with existing email addresses. All of that can be made to work.
But it is the case. Email won't be a secure group communication system. The reason for that is that email is federated and thus permanently mired in the lowest common denominator of mainstream email clients.
I think reasonable people can disagree about whether it's tractable to create a federated secure group messaging system with what we know right now. But I do not think it's reasonable to suggest that the concern (federation = lowest common denominator security) is invalid. And that's what this piece does.
Re: Encrypted messengers: Riot, not Signal, is the future
#10EDIT: Thank you for the responses! It pretty much confirms what I thought; Apple _could_ access your communication (either through keylogging at the OS level or backdooring Signal) but this solution is better than everyone use plain text communication. I personally would not trust Apple with my life if I needed that level of protection but maybe that's not the main use case for Signal.