Hacker News new | ask | show | jobs
by dncornholio 1297 days ago
So that basically means don't use any messenger.
2 comments

There are options. Matrix, Session, Threema, Wire...
Wire? Didn't they get bought out by some shady company a few years back?
I used to work at Wire. As far as I know there was no shady buyout, just new investors who were less lax about wanting Wire to actually make money. So they started reorienting at big corporate clients.

The technology itself wasn't changed and Wire was still involved in exciting things like MLS (https://datatracker.ietf.org/doc/draft-ietf-mls-protocol/) when all this was happening (~4 years ago).

No, most. Like Signal for example. Even without security you can't migrate between android and iphone or have multiple devices with the same account. But they have crypto amd stories now lol.
All the hating on Signal but for me it's the best and fits my threat model. I live in the UK and by all accounts I'm pretty unremarkable - I want privacy but not overly worried about anonymity, I also wanted something that I could persuade family and friends to use.

Signal works perfectly in my use case, my friends and family happily switched over to it where when I tried to help my parents set up Matrix it was super verbose and required them to remember long passwords, etc. (of course they shoul dbe using a password manager, but one step at a time!).

Signal is great until your family member's phone breaks, and you have to explain to them that their messages are gone forever. Allow us to choose to enable backups, Signal!
PLease no. If someone compromises one of the contacts in a large chat group's google password or whatnot, they now have the entire message and media history from me to the chat group? This is exactly why iMessage is so useless for security - one compromise on one person's apple ID and all their groups have all their messages compromised going forward.
That works the same for signal as well, if a person's phone is compromised they have all their chat. What are you talking about? Even signal folks repeatedly have iterated they don't protect messages when a device is compromised.
Disappearing messages are what you want here.

I expect it would be easier to compromise a group member's phone than someone's Google account.

I have backups enabled actually. Sure, it's a pain to manage compared to WhatsApp, as you have to manually download it off your phone, but Signal has an option for automatic daily backups.

They are encrypted with a key you have to note down somewhere though, so if you don't prepare for it the messages are, in fact, gone forever.

Your backups are useless if you want to use a different platform they support. You have to use android or iphone for life. And you can't use them on desktop without a mobile app and you can't have multiple sessions and you have to use your phone number. Right... very private.
Manual backups are no backup.
I've restored Signal backups before. It was trivial and fast.
Signal has made the choice that their users will not be people like you or your family. No automatic backups or recovery or migration capability. They also dropped sms support. They are better than telegram for sure. I recommend using an apple device and imessage for the average person who just wants private communication and isn't concerned about targeted nation state attacks and the like. On android, session might be ok but I wouldn't know, for security I don't see what signal has that they don't and you don't need google play services to use them but i have no idea if they are even unfriendlier than signal. There are other apps that use the underlying crypyo signal uses, so it really is a feature comparison.

I regret getting friends and family to use signal.

*after giving them your phone number and everyone you want to message and the entire social graph from anybody with your number stored in their device's contacts list

F, for Failure