adbenitez

joined 4 years ago
MODERATOR OF
[–] adbenitez@lemmy.ml 2 points 6 days ago (3 children)

It is a us based non profit that doesn’t store any information about you

still it runs in AWS, Microsoft, etc servers, and as any centralized service policy and interests can change at any time in the future, which would be pretty bad when you have several countries fully depending on them, just look the current situation with whatsapp, you can not be resilient/sovereign like that

has been independently audited like four times.

could you provide source pointing to the security audits?

[–] adbenitez@lemmy.ml 2 points 6 days ago

take a look at ArcaneChat https://arcanechat.me/

[–] adbenitez@lemmy.ml 1 points 1 week ago* (last edited 1 week ago)

I don’t trust this one bit.

you don't need to trust, you can self-host your own server and read/modify the code, unlike in a centralized server where you don't even know what is actually running on the server, which is well know from the past to not match the actual released code for the case of Signal

They don’t mention anywhere what they use for encryping your chats

all this is documented inside the app in the offline help/FAQ that comes with it, the app is targeted to end users that don't know or care about such topics so it is avoided to talk too much about encryption up-front

Their code is not documented at all.

ArcaneChat is a fork of DeltaChat client, DeltaChat has been audited several times, you could also use the official Delta Chat client: https://delta.chat/

[–] adbenitez@lemmy.ml 1 points 1 week ago (2 children)

because it is a centralized service from US company, registration requires phone numbers so it is easy to know from what country you are, the server is running in Amazon Web Services, etc, while ArcaneChat can be used with your own infrastructure, for total technological sovereignty

[–] adbenitez@lemmy.ml 2 points 1 week ago

for iOS and desktop you can use Delta Chat which is fully compatible with ArcaneChat

[–] adbenitez@lemmy.ml 12 points 1 week ago (8 children)

As alternative to WhatsApp, there is also ArcaneChat that is more user-friendly for normies: https://arcanechat.me/

[–] adbenitez@lemmy.ml 1 points 1 week ago* (last edited 1 week ago) (1 children)

Maybe I'm confused, do the DeltaChat and ArcaneChat clients only work with DeltaChat/ArcaneChat servers?

The "ArcaneChat/DeltaChat servers" are just normal email servers with some default configurations and tweaks for privacy/security and speed

Edit: forgot to mention I can see the sender & recipient addresses (Signal uses sealed sender to minimize this metadata leak)

Signal needs to "seal sender" to be able to send messages anonymously since their service is not anonymous and you login with your phone number, in ArcaneChat it is like you are "sealed sender" from the very beginning, you don't register with phone number or any private data, you log in anonymously always, currently you have an static anonymous identity, and have to manually change it over time if you are the most paranoid person in town, but in the future the app might implement anonymous identity rotation

I can also see what time the message was sent this is the kind of metadata Meta collects through Whatsapp even though they also encrypt message content.

Nothing that the server doesn't know, the server knows the time at which you try to send a message because well you are asking it to do so at that time. But I agree this is a problem with stored messages if the server gets audited at a later point, by default with a single device messages are deleted immediately and otherwise after 20 days so still it is limited what they could get, but this can be improved, the header doesn't need to have a real date could be whatever fixed date while the real date is protected in the encrypted part, this needs to be done 👍

It doesn't seem - although maybe it now does - that DeltaChat nor ArcaneChat support key ratcheting, so if someone's intercepting messages they can decrypt all future + past messages.

This is a pretty theoretical situation, first the attacker needs to get control of your chatmail provider/server and start collecting your messages, secondly you need to happen to be using disappearing messages since otherwise when they get access to your phone to get the key they can as well just get all your messages that are available already decrypted in the app, since you need the messages to be ephemeral, in that case you can as well create a temporary profile, ex. For some protest or activism and delete it after the operation is finished, and you get the same results of "forward secrecy" without sacrificing the usability of the app, ex. In ArcaneChat it is possible to have your account in as many devices as you want all well synchronized and every device is totally independent, if your phone dies you can keep using it in other devices or add it back to a new phone without losing a single message

[–] adbenitez@lemmy.ml 1 points 1 week ago* (last edited 1 week ago)

Hey, how do you know she is named Nancy!? And that she smokes a bit too much! 😱

[–] adbenitez@lemmy.ml 3 points 1 week ago* (last edited 1 week ago) (1 children)

I didn't want to advice/promote DeltaChat/ArcaneChat, they are not the only possible way of using email securely, just came here with the meme as a way of leaving out a rant because I have seen a lot of people talking like that and it is by now an urban legend people just repeat like parrots and pointing to articles that basically are misleading. Had a recent discussion about that in the Privacy Guides forum and just came here with the meme to shake the frustration away ;-)

[–] adbenitez@lemmy.ml 3 points 1 week ago (3 children)

it is all about the sassy retro style and base64 MIME body

more seriously: Signal is centralized and based on phone numbers, and as said by Signal themselves: "Privacy is Priceless, but Signal is Expensive" https://signal.org/blog/signal-is-expensive/ while email infra is WAY more economic and decentralized

SimpleX maybe but I it is not powerful/flexible nor as solid/mature as email server infra

[–] adbenitez@lemmy.ml 5 points 1 week ago

When you send ANY message (it doesn't matter if it is just text, image or other attachment) it is end-to-end encrypted and on the server it all looks the same, encrypted blobs, it is only visible in your devices.

If you have a single device the encrypted blobs are deleted immediately after downloading them, if tyou have more than one device, the blobs are stored up to 20 days in the server to give you the chance to sync your devices, if you use "disappearing messages" option or manually select and delete messages or use the "clear chat" option, then you have more fine control when it is removed.

About your friend being offline, the same rules apply, they will be able to download the images and other messages you send to them as soon as they come back online within 20 days :)

Of course, if you host your own server you can tweak it to your needs if the defaults of arcanechat.me don't suit you

 

I created a Lemmy community for ArcaneChat users (ArcaneChat is a Delta Chat client)

https://lemmy.ml/c/ArcaneChat

 

ArcaneChat 1.54.0 is already available in Google Play and should be available in f-droid in the upcoming days, for other download options check https://arcanechat.me/

Changelog:

  • enhanced "Saved Messages" feature, now when forwarding a message to "Saved Messages" chat, it retains the sender information and a button to jump to the original message
  • Saved messages are marked by a bookmark sign
  • improve explanation when blocking a contact
  • improve wording in empty "apps" and "files" tabs in chat media screen
  • UI improvement: keep avatars aligned to message bubble when message has reactions
  • fix problems when opening attachments in external apps
  • fix a bug with some big images appearing as blank/transparent
  • some other small bug fixes
  • update translations
 

ArcaneChat an alternative Delta Chat client for Android is now available in Google Play store! 🎉

also, the official ArcaneChat website is live now! check out https://arcanechat.me/

announcement in social media: https://mastodon.social/@adbenitez/113923300365112674

20
submitted 1 month ago* (last edited 1 month ago) by adbenitez@lemmy.ml to c/delta_chat@lemmy.zip
 
 

ArcaneChat (previously known as DeltaLab) an alternative Delta Chat client for Android is now available in official F-Droid store! If you already have it you can securely continue to upgrade it now from F-Droid (or IzzyOnDroid) thanks to Reproducible Builds which ensures the apk matches the source code and not me nor F-Droid is manipulating the binary 🎉

announcement in Mastodon: https://mastodon.social/@adbenitez/113165018833290408

view more: ‹ prev next ›