Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Privacy
  3. Signal is not the place for top secret communications, but it might be the right choice for you – a cybersecurity expert on what to look for in a secure messaging app

Signal is not the place for top secret communications, but it might be the right choice for you – a cybersecurity expert on what to look for in a secure messaging app

Scheduled Pinned Locked Moved Privacy
privacy
103 Posts 56 Posters 494 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • 9 [email protected]

    Actually RCS has encryption in the new spec now, and we could see encrypted RCS messages implemented on iOS and Android within a year.

    But even so, use Signal.

    supernova1051@sh.itjust.worksS This user is from outside of this forum
    supernova1051@sh.itjust.worksS This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #7

    RCS still leaks metadata like a sieve. Encryption, considering the platforms that exist today (Signal and SimpleX), should not be the minimum requirement. Plain-text messaging should not even be possible in modern secure messaging platforms. The platform should be open source and be engineered to mitigate the collection of metadata - like Signal and SimpleX.

    9 1 Reply Last reply
    0
    • merde@sh.itjust.worksM [email protected]

      because "they" don't trust the people they "represent" and they want to avoid federal archives

      they must know something about WhatsApp that we don't

      zorsith@lemmy.blahaj.zoneZ This user is from outside of this forum
      zorsith@lemmy.blahaj.zoneZ This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #8

      There's nothing to know; facebook is facebook, and nobody trusts facebook for data security. Whatsapp is not, nor will it ever be, true end to end encryption, when facebook owns the locks and keys.

      R 1 Reply Last reply
      0
      • 9 [email protected]

        Actually RCS has encryption in the new spec now, and we could see encrypted RCS messages implemented on iOS and Android within a year.

        But even so, use Signal.

        B This user is from outside of this forum
        B This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #9

        I think they mean that it'll take time for everyone to get it. My carrier still doesn't even have RCS at all.

        1 Reply Last reply
        0
        • florencia@lemmy.blahaj.zoneF [email protected]
          This post did not contain any content.
          E This user is from outside of this forum
          E This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #10

          Signal is the place for top secret communications, but not for government business (at least not when using a public instance - they could fork the project to keep decryptable records on gov servers where the official gov instance would run).

          florencia@lemmy.blahaj.zoneF S socsa@piefed.socialS 3 Replies Last reply
          0
          • U [email protected]

            EVERYONE SHOULD DOWNLOAD SIGNAL for PHONE-NUMBER-based communication, tho. Proper RCS is not here yet (and won't be in a long while), so let's try to mobilize people to Signal.

            DeltaChat is cooler for non-phone based communications, IMO, and decentralization makes it way sexier and worth this tradeoff.

            A This user is from outside of this forum
            A This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #11

            Isn't DeltaChat just PGP encrypted email? Could be wrong

            1 Reply Last reply
            0
            • florencia@lemmy.blahaj.zoneF [email protected]
              This post did not contain any content.
              C This user is from outside of this forum
              C This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #12

              I can't imagine any messenger is private if you invite random people into a group chat 🤦‍♂️

              satyrsack@feddit.orgS povoq@slrpnk.netP 2 Replies Last reply
              0
              • bushvin@lemmy.worldB [email protected]

                Considering the US government now owns Meta and thus WhatsApp, it’s an interesting case… why did they use signal?

                G This user is from outside of this forum
                G This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #13

                Disappearing messages

                1 Reply Last reply
                0
                • bushvin@lemmy.worldB [email protected]

                  Considering the US government now owns Meta and thus WhatsApp, it’s an interesting case… why did they use signal?

                  K This user is from outside of this forum
                  K This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #14

                  If there is backdoor for them, then there is a backdoor for everybody who knows where to look.

                  1 Reply Last reply
                  0
                  • supernova1051@sh.itjust.worksS [email protected]

                    RCS still leaks metadata like a sieve. Encryption, considering the platforms that exist today (Signal and SimpleX), should not be the minimum requirement. Plain-text messaging should not even be possible in modern secure messaging platforms. The platform should be open source and be engineered to mitigate the collection of metadata - like Signal and SimpleX.

                    9 This user is from outside of this forum
                    9 This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #15

                    Seeing as RCS with encryption based on the MLS standard hasnt been deployed yet, can you show exactly what metadata is leaking?

                    povoq@slrpnk.netP supernova1051@sh.itjust.worksS 2 Replies Last reply
                    0
                    • S [email protected]

                      I use signal myself but I also use simple X. I can't use delta chat because I use proton for my email and therefore can't use delta.

                      satyrsack@feddit.orgS This user is from outside of this forum
                      satyrsack@feddit.orgS This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #16

                      Delta Chat is not associated with your email account, as far as I can tell. Am I wrong?

                      S 1 Reply Last reply
                      0
                      • C [email protected]

                        I can't imagine any messenger is private if you invite random people into a group chat 🤦‍♂️

                        satyrsack@feddit.orgS This user is from outside of this forum
                        satyrsack@feddit.orgS This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #17

                        Layer 8 security issue

                        R 1 Reply Last reply
                        0
                        • satyrsack@feddit.orgS [email protected]

                          Delta Chat is not associated with your email account, as far as I can tell. Am I wrong?

                          S This user is from outside of this forum
                          S This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #18

                          https://delta.chat/en/

                          ⚡️ Sign up to secure fast chatmail servers or use classic e-mail servers

                          satyrsack@feddit.orgS 1 Reply Last reply
                          0
                          • bushvin@lemmy.worldB [email protected]

                            Considering the US government now owns Meta and thus WhatsApp, it’s an interesting case… why did they use signal?

                            J This user is from outside of this forum
                            J This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #19

                            The government does not "own" Meta. Words have meanings.

                            hominine@lemmy.worldH X 2 Replies Last reply
                            0
                            • E [email protected]

                              Signal is the place for top secret communications, but not for government business (at least not when using a public instance - they could fork the project to keep decryptable records on gov servers where the official gov instance would run).

                              florencia@lemmy.blahaj.zoneF This user is from outside of this forum
                              florencia@lemmy.blahaj.zoneF This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #20

                              at least not when using a public instance - they could fork the project to keep decryptable records on gov servers where the official gov instance would run

                              All the people in the chat were high enough that the government for free provided them with secure rooms in their homes so everything would be done through government hardware and encryption programs.

                              E R 2 Replies Last reply
                              0
                              • S [email protected]

                                https://delta.chat/en/

                                ⚡️ Sign up to secure fast chatmail servers or use classic e-mail servers

                                satyrsack@feddit.orgS This user is from outside of this forum
                                satyrsack@feddit.orgS This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #21

                                You don't have to use a "classic email server", or even link your account to your current email address at all. The default onboarding procedure actually creates a new anonymous account for you on the default chatmail server. Reading through the site, I can't actually even tell why someone would want to use their preexisting email address.

                                S 1 Reply Last reply
                                0
                                • satyrsack@feddit.orgS [email protected]

                                  You don't have to use a "classic email server", or even link your account to your current email address at all. The default onboarding procedure actually creates a new anonymous account for you on the default chatmail server. Reading through the site, I can't actually even tell why someone would want to use their preexisting email address.

                                  S This user is from outside of this forum
                                  S This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #22

                                  Ah, okay. I think I heard about it at an earlier point where it was only using your current email.

                                  1 Reply Last reply
                                  0
                                  • J [email protected]

                                    The government does not "own" Meta. Words have meanings.

                                    hominine@lemmy.worldH This user is from outside of this forum
                                    hominine@lemmy.worldH This user is from outside of this forum
                                    [email protected]
                                    wrote on last edited by
                                    #23

                                    Not for ideologues unfortunately.

                                    1 Reply Last reply
                                    0
                                    • florencia@lemmy.blahaj.zoneF [email protected]

                                      at least not when using a public instance - they could fork the project to keep decryptable records on gov servers where the official gov instance would run

                                      All the people in the chat were high enough that the government for free provided them with secure rooms in their homes so everything would be done through government hardware and encryption programs.

                                      E This user is from outside of this forum
                                      E This user is from outside of this forum
                                      [email protected]
                                      wrote on last edited by
                                      #24

                                      Yes, ofc, using Signal was intentional to not keep any records/evidence.

                                      1 Reply Last reply
                                      0
                                      • florencia@lemmy.blahaj.zoneF [email protected]
                                        This post did not contain any content.
                                        W This user is from outside of this forum
                                        W This user is from outside of this forum
                                        [email protected]
                                        wrote on last edited by
                                        #25

                                        Signal is great, that's why I'm suspicious that this recent story is to not only target journalism, but also secure app communication. I wouldn't be surprised if it's used as an excuse to remove signal from the app stores.

                                        Hopefully I'm just being too paranoid.

                                        S breadguy@kbin.earthB N 3 Replies Last reply
                                        0
                                        • florencia@lemmy.blahaj.zoneF [email protected]
                                          This post did not contain any content.
                                          hiddenlayer555@lemmy.mlH This user is from outside of this forum
                                          hiddenlayer555@lemmy.mlH This user is from outside of this forum
                                          [email protected]
                                          wrote on last edited by
                                          #26

                                          How's signal compared to Element?

                                          Also, is there a secure way to directly send messages to someone else's phone without the message having to be stored on a central server? As in they're only stored on the recipient device. Even if the server has no way of decrypting messages by default, just having the encrypted messages stored there is a liability because your encryption keys can easily get leaked by malware running on your device, phishing, etc.

                                          R 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups