Realistically nothing is ever perfect, but XMPP comes very close. You've got Signal-introduced double-ratchet encryption if forward secrecy is your jam (so it's as "E2E-secure" in practical terms) and you've got a healthy ecosystem of independent client and server implementers, and service providers to choose from.
> Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
(Note that I don't care about cryptocurrencies except for the cryptography behind it)
There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made for (anyone with a copy of the chain can potentially be the recipient of either the money transfer or the encrypted message).
If people were really serious about privacy and secure messaging they'd look into this instead of constantly attacking the concept.
But then of course there are entire armies of shills who have a vested interest in pushing a narrative explaining that services, at best, collecting metadata and, at worst, being backdoored are offering "secure messaging".
I'm only using Telegram and I don't believe for a second it's secure and private (it's got, supposedly, "one on one" E2EE but not for groups). But at least they're not posturing as the most secure and private messenger on earth.
Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company?
As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it.
Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.
Why not? Plenty people already use a dedicated '2FA' phone for Work under BYOD policies when they don't want to install any 'work' software on their 'personal' phone.
Depending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you have to pick your poison. If E2EE is important, you also need to determine how encrypted you want your messages to be (as both XMPP and Matrix carry quite a bit of identifying metadata in its unencrypted headers).
For most people and use cases, either will probably do, but if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal.
> if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal
So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delivery?
I mean, as opposed to using something like XMPP which you can completely use over Tor and never even reveal which server you use/that you use XMPP, from a client running a secure and minimalistic OS and no service-in-the-middle ?
Some would label Signal as a honeypot and it would be difficult to falsify that.
Apple, at least, maintained a historical database of your phone's notifications, that it did not clean up after they expired. That includes all notifications from Signal telling you that person XXX has sent you a message that starts YYYY <facepalm>
Forgot about that and that def was bad, though imo not really on Signal and would have just as much affected any XMPP app, no? To me this definitely didn't "[throw] it all away" as in your messages were still only on your phone and never decrypted on any server or w/e.
Well that's the thing, you just don't know what happens once you let Signal send notifications via Apple/Google - clearly they get them plaintext, and who knows if they're retained and subpoena-able directly from Apple/Google. The leak via notifications DB not being cleaned up is just the shot across the bow. You pay a price for convenience.
Anyway, I'm not OP, and they have a mad setup (XMPP via Tor) which is a flaky solution most people wouldn't go for. In general, if you're not going to such extreme measures of hiding among the crowd of Tor users to mask your metadata, you're better off directly connecting and hiding among the crowd of Signal users, rather than hosting your own instance.
to be clear though notifications do the decryption on device themselves. signal uses apple/play services only to notify the device that there has been a message, none of the contents are delivered over these services. if you cant trust the device to do that then no messaging app could ever be secure enough
De-jure it's against the ToS, but it's not being enforced besides "don't be an asshole, don't abuse the network and be careful with Signal branding". Technically, you can use Whisperfish on SailfishOS, Flare on mobile-linux-of-the-day or even signal-cli as a primary device.
the oceans can adsorb a great deal more heat, but all the ice will melt, while the deap ocean water expands, from it's rather odd temperature ,that keeps it at the highest density possible, about .5% more than if it were just a bit warmer, so more warming will cause very significsnt sea level rise through several different mechanisms related to heat.
Having privacy should be a user choice. I am firmly in the Apple ecosystem and in the EU. Apple could engineer it such that interoperability means giving up privacy. User can choose. Apple could show in the App Store/settings exactly which data is leaked. Apple is using privacy as a tactic.
Very much this! This is about removing (if it at wall will do that) without fixing the root cause. How deep can you put your head in the ground? It reminds of the Matrix where they scorched the skies to remove solar power capabilities as a way to block the enemy.
Climate science consensus is we need to decarbonize and remove. We've gone too far at this point, decarbonizatin alone is no longer sufficient. So we need all the solar-y wind-y nuclear-y stuff AND all this weird removal stuff. And some other weirder stuff too.
Or, use sensible CCS methods like plankton or kelp, charring that, and sending it to the bottom of the ocean instead of resorting to absurd plans like nukes.
reply