188
submitted 6 months ago by Star@sopuli.xyz to c/privacy@lemmy.ml
you are viewing a single comment's thread
view the rest of the comments
[-] dessalines@lemmy.ml 16 points 6 months ago

I don't get it at all. There are plenty of platforms like matrix, xmpp, simplex that don't require phone numbers tied to your identity. Signal has somehow managed to convince people that it's a private platform, despite it being a US hosted service that requires phone numbers.

[-] drwho@beehaw.org 8 points 6 months ago

It's a Google hosted service, which is arguably worse because they may as well be a nation-state unto themselves.

[-] EngineerGaming@feddit.nl 6 points 6 months ago

Wasn't Amazon involved here as well? It is another "nation-state".

[-] drwho@beehaw.org 3 points 6 months ago

I do not think so, no. However, Amazon is certainly big enough to be un-humorously compared to nation-states as well.

[-] EngineerGaming@feddit.nl 4 points 6 months ago

I remembered it as being AWS. Checked their blog, and the article about their spending mentions renting space in AWS and Azure too, indeed.

[-] refalo@programming.dev 2 points 6 months ago

And the largest homeserver, matrix.org, is MITM'd by Crimeflare.

[-] msage@programming.dev 2 points 6 months ago

Fuck matrix.org, just selfhost.

[-] refalo@programming.dev 2 points 6 months ago

Any homeserver that federates (even indirectly) with matrix.org will still have practically all the same data shared with it, just not your password.

[-] msage@programming.dev 1 points 6 months ago
[-] refalo@programming.dev 1 points 6 months ago

The password used to login to the homeserver

[-] drwho@beehaw.org 2 points 6 months ago

Doable, but a huge pain in the ass because of conflicts in the protocol. I spent about a year trying to suss them out and come up with a fix but never figured it out.

[-] refalo@programming.dev 3 points 6 months ago* (last edited 6 months ago)

Who have they convinced that it is private? I think it has more to do with the overall purpose of the platform. Signal is not made for large group chatting with strangers like Matrix.

[-] msage@programming.dev 1 points 6 months ago

I use Matrix for my personal 1 on 1 chats with family and friends, so dunno

[-] to55@discuss.tchncs.de 1 points 6 months ago

Say the US government, in a worst-case scenario in which it constantly monitors all traffic that goes through Signal’s data centers, can ‘only' see phone numbers, IP addresses and timestamps, right? Or am I forgetting something here?

[-] dessalines@lemmy.ml 7 points 6 months ago* (last edited 6 months ago)

Metadata and social graphs are more important than message content, esp since not many people have the time to read through individual messages to build meaning.

Signal stores phone numbers (meaning your identity, and home address), and message timestamps: who texted who and when, and who's in chats with who else. More than enough to build social graphs and connections, and also figure out where people are through their IP addresses.

[-] to55@discuss.tchncs.de 2 points 6 months ago

Right. So arguably better than WhatsApp, where each users’ contact books, profile photos, bios, and each group chat name, picture and description is not E2E. But to call it ‘private’ is not logical, looking at the alternatives, of which some are much more private.

[-] marcie@lemmy.ml 1 points 6 months ago

Do you happen to know what metadata matrix stores? I assume matrix.org specifically stores email and username, right

[-] dessalines@lemmy.ml 1 points 6 months ago

Yes, but I don't think user metadata outside of your apub url, name, icon, display name, leaves your homeserver. Email or passwords don't leave iirc.

[-] brayd@discuss.tchncs.de 1 points 6 months ago

Signal can't see who is texting who. They can't see which groups you are part of. Those information are end to end encrypted, same as your chats itself, your profile picture, your stories, etc.

Signal doesn't store message timestamps either.

What Signal itself knows of you is your phone number, the timestamp of your registration, the timestamp of your last connection to the server. That's it.

Yes metadata is critical but Signal handles metadata very well. Indeed, even though I'm a fan of Matrix, better than Matrix. Matrix is a metadata nightmare due to it's centralized structure and the way the protocol works.

[-] dessalines@lemmy.ml 4 points 6 months ago

Signal can't see who is texting who. They can't see which groups you are part of. Those information are end to end encrypted, same as your chats itself, your profile picture, your stories, etc.

This is completely false. They can absolutely see who is texting who, in fact they need it to be able to route messages. They have message timestamps, and phone numbers stored in their database.

Question, why do you "trust" signal? You can't see what code their centralized server is running, unlike matrix which you can self-host and build from source. You don't have to "trust" matrix, you can verify it for yourself.

[-] brayd@discuss.tchncs.de 0 points 6 months ago

Signals server is open source. You can run a server. You just can't connect to the main net because each server is it's own thing so it doesn't make sense besides for development purposes.

Please don't spread misinformation.

[-] dessalines@lemmy.ml 0 points 6 months ago

They went over a year without publishing their server updates. And how do you know signal is running the code they say they are? Do you trust them?

[-] brayd@discuss.tchncs.de 0 points 6 months ago

The good thing here is that you don't need to trust the server in order to have a secure communication since your clients decrypt and encrypt and not the server.

Yes they can optimize with things like this but that doesn't make it insecure. It's still the most secure solution that the average person can use.

Threema doesn't even have the server open sourced at all, are for profit and their encryption has been compromised.

Session is shady.

Matrix is a metadata nightmare due to it's federated aspects.

SimpleX is the only thing that is secure, anonymous and good in this regards but it has some small details left that prevents people from switching. I.e. simple things like the fact that you can't see an overview of your images and videos sent in a chat without scrolling up all those messages. It seems trivial but for the average user stuff like that is important since they know it and use it every day in other messengers.

this post was submitted on 13 May 2024
188 points (96.1% liked)

Privacy

32120 readers
286 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS