Encrypted messaging recommendations.
-
[email protected]replied to [email protected] last edited by
If no one's on any kind of private messaging platform, SimpleX is good and fairly easy to use. But I mostly use Signal just because everyone's on it.
Also consider your threat model; Signal is appropriate for just casual personal conversations, but it is centralised and not self-hostable. The servers are run by the Signal org who are based in the US. If the potential of message metadata (which can be used to eg create networks of who's messaging who) getting into the hands of the US state could create significant issues for you, you may want to at least find either a decentralised or self-hostable solution which is not so US-centric. I assume, though, since you're talking to these people on non-private platforms, that these are not super sensitive discussions anyway.
-
[email protected]replied to [email protected] last edited by
Contains proprietary code. I recommend Molly-FOSS instead.
-
[email protected]replied to [email protected] last edited by
People will dislike this:
The most basic one with little barrier to entry is imessage. Theres a good chance your friends and family already have it and with a few setting changes (no sms fallback, set icloud recovery key, probably some stuff I forgot) you’re damn near at parity with signal.
All without dad having to download a new app onto his phone and make a new identity!
Of course you’ll need signal or something for people who don’t use it.
I use that combination and it’s excellent. If you can be on imessage with someone you’re good and everything works, if not you do signal.
There will be people you gotta use sms with. They just won’t be able or willing to do something new. Sometimes there’s an equipment problem, their super old provider version of android can’t get an app you both agree on. Sometimes they’re using a Nokia.
Interacting with sms often may help keep you on your toes about it. I know I’m more careful over text now.
That combination, imessage and signal, also has a benefit of reducing the chances that you’ll broadcast an awareness of and desire for privacy and security to the whole world all the time.
In the us, there’s a 50% chance you just look like a normal person and that’s nothing to sneeze at.
Make sure it meets your needs of course
-
[email protected]replied to [email protected] last edited by
If you're on Android, as well, look into BlueBubbles. It bridges iMessage from a MacOS system to most any device/OS. I've used it for years now with my partner's family with very little issue (all of which were resolved with a restart).
Hard part is getting a MacOS system. I started with a VM, but eventually landed on a ~$100 Mac Mini 2014. Both solutions worked well, but the former is against Apple's TOS and requires spoofing things, so it's ultimately much less reliable than actual hardware.
-
[email protected]replied to [email protected] last edited by
I second xmpp + omemo, and would caution that as far as I can remember matrix leaks significant metadata when syncing between instances/services.
As a personal decision I got away from signal (molly in fact) more than a year ago.
I'm also keep jami working with my family, particularly for things not requiring immediate response. It's a different beast, since it's p2p, but there's no server associated to it, no matter if decentralized or not. It's easy as well, just not as responsive, in particular if looking for immediate responses... I like and keep both, hoping jami improves.
-
[email protected]replied to [email protected] last edited by
That’s awesome! I didn’t know there was an option for android users.
-
[email protected]replied to [email protected] last edited by
little barrier to entry
$1000+
-
[email protected]replied to [email protected] last edited by
I got my mother on XMPP - if you set the person's account up, Conversations is as easy to use as Whatsapp or Signal, but doesn't have the central server dependence.
-
[email protected]replied to [email protected] last edited by
The barrier to entry was intended to refer to others since it’s already installed on over half their phones to start with and most people are gonna be using a messaging program on their phone.
When there’s above a 50% chance the person you’re talking to is already using a particular encrypted messaging program that’s the lowest barrier to entry.
The barrier to entry always refers to other people because the hardest part of establishing private communications has always been convincing other people to actually do it.
If you really wanted to get on imessage for the least amount of cash out of pocket possible, the bluebubble bridge application random letters person mentioned is ~$100 for an old mac, and tbh that’s a high estimate in my experience. People are just giving those things away nowadays.
-
[email protected]replied to [email protected] last edited by
Simplex for anonymity, You can download it, share chat and start talking without registration.
It ate my battery when I installed it. Do you use it on a daily basis? What's your experience with its battery consumption?
-
[email protected]replied to [email protected] last edited by
But most people would be excluded because they don't have an iPhone or even funds to buy one! And would have no real way to participate! Maybe some older secondhand models would go below $300, I don't know, but it would be weird to expect a person to buy a second phone (and an older, more worn-down one at that) just to converse with you. Even $100 is also a pretty high price just to bypass an arbitrary restriction.
There is a reason the most popular messengers are cross-platform. So the aim must be that.
-
[email protected]replied to [email protected] last edited by
Signal is the easiest with true end to end encryption with keys stored on the endpoints only.
-
[email protected]replied to [email protected] last edited by
Sadly, I have no one to use with it, so I don't know about battery usage. I just like, that it doesn't require any external identifiers, unlike Signal.
-
[email protected]replied to [email protected] last edited by
If you’re in america almost sixty percent of phones are ios.
If you’re choosing an encrypted chat and sixty percent of people are already using it then that’s the one you choose. The hardest thing is compliance and you’re almost two thirds of the way there if you just pay a hundred bucks (or scrounge up an old mac) and run the bridge app. Then you use signal for everything else.
I think we’re looking at this from fundamentally different perspectives. I’m not worried about a universal solution because I know I’m not getting to 100% compliance with any solution so I suggested the one that immediately fixes the majority of the problem. Having had to convince people to exchange pgp keys twenty five years ago, I’d pay a hundred bucks to not have to deal with that for two thirds of the people I know.
Think about it this way: if you were starting from scratch would you rather have to convince all your contacts to move their chats with you to signal or matrix or whatever or would you rather have to convince four out of ten to do that?
Obviously you’d pick the easier thing because no matter how committed you may be to not using proprietary software or big corporate apps or fragmented ecosystems you actually have to accomplish the goal of chatting with people using encryption and all the process compliance and wheedling and convincing and tech support for family members is time you could be spending talking about gardening, sharing baby pictures, plotting to overthrow the government or whatever you would normally be doing.
-
[email protected]replied to [email protected] last edited by
Sixty percent still leaves about a half excluded and left without a cheap and conveniwnt way to participate. You think it is fair in any way?
-
[email protected]replied to [email protected] last edited by
As I said, use signal for everything else.
If immediately getting sixty percent of your chats encrypted isn’t worth a hundred bucks to you I don’t know what to say. We’re looking at this from fundamentally different perspectives. I’m trying to meet a goal to solve a problem and you’re trying to find the fair solution.
It’s good to try to find the fair solution.
-
[email protected]replied to [email protected] last edited by
Ah, you mean $100 just for you and then everyone in your family would be able to use it? Still a very steep price but at least you're not forcing anyone epse to pay it. I just thought about messaging not just between family members and you, but between other family members as well.
-
[email protected]replied to [email protected] last edited by
signal or SimpleX.
I'm starting to move away from Matrix, primarily because its metadata is not encrypted. So you might have a message that's encrypted, but the emoji reaction like a thumbs up is not encrypted, and the time it was sent and received is not encrypted, and who it was sent from and to is not encrypted.
Not to mention that in Matrix, private key management for encryption in rooms and stuff like that is quite frankly a pain in the ass. Even I as a cryptocurrency user have trouble making sure that my keys are properly stored without fucking them up.
I would not recommend my friends or family members use it for these reasons.
-
[email protected]replied to [email protected] last edited by
I'm in one room with 1,500 people and it uses about 7% of my battery. Mind you, that is a lot for a messenger. But I can deal with that.
-
[email protected]replied to [email protected] last edited by
I just moved to Signal and have convinced most of my family and many friends to join. It is very secure, non-profit and doesn't share much personal data (the least of the main messaging services) and most of my luddite family has been able to figure it out.