this post was submitted on 07 Feb 2025
227 points (98.3% liked)

Technology

61850 readers
2666 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

I currently use Telegram for my friends and family, but have reluctantly come to the conclusion that the UK Government is either reaching agreement for backdoors with messaging services, or is trying its hardest to.

I'm also on Element/Matrix. Before I try to get my contacts to join me on there, should I be aware of any privacy issues or is that a good place to head?

you are viewing a single comment's thread
view the rest of the comments
[–] mox@lemmy.sdf.org 7 points 16 hours ago* (last edited 6 hours ago) (2 children)

Signal is easier to use, more private, and faster.

Unfortunately, it is also effectively tied to Google services due its app distribution and push notification channels on Android (which most people on Signal use), and as a centralised service, it is vulnerable to shutdown or network-level metadata monitoring by anyone with sufficient access/influence at Signal or their data center provider (such as a government who doesn't like encrypted messaging).

~(Edit:~ ~rephrased~ ~for~ ~clarity)~

[–] jws_shadotak@sh.itjust.works 12 points 15 hours ago (1 children)

You can use Molly, a fork of Signal for android. It offers an alternative for push notifications.

[–] mac@lemm.ee 3 points 15 hours ago

Yep, I run my own mollysocket + ntfy server.

Essentially, molly socket functions as another device, when it recieves a notif, it pings your specified unified push server, which then queues up a notification for the ntfy app on your device.

You don't need to run your own unified push server, and can just use one of the main ones, but I figured I might as well.

I personally have them hosted on fly.io for free via the legacy hobby plan.

Now all I need to do is get more of my friends to message me on it 🤣

[–] Ulrich@feddit.org 7 points 15 hours ago* (last edited 8 hours ago) (1 children)

it's also effectively tied to Google services due to the app distribution

It's been recently added to FDroid.

and push notification channels

You can use NTFY with Molly (which has been on FDroid for some time).

network-level metadata monitoring by anyone with sufficient access/influence at Signal or their data center provider (such as a government who doesn't like encrypted messaging).

This one is just a straight-up lie. Everything on the server is encrypted and no one has the keys except the participants.

[–] mox@lemmy.sdf.org 2 points 6 hours ago* (last edited 5 hours ago) (2 children)

It’s been recently added to FDroid.

No, it has not. A third party published it in an f-droid compatible repository. That might be convenient for someone who happens to trust that third party and manually add it to their F-Droid client, but it is not at all like it being added it to F-Droid.

You can use NTFY with Molly (which has been on FDroid for some time).

This does not refute what I wrote. Unless you only communicate with people who get their Signal app from some non-Google source and they all rig up alternative push notification channels, or every one of them uses Signal exclusively on iOS, your conversations are still tied to Google. Perhaps you have so few contacts that you could achieve that, but most people are not in that position.

network-level metadata monitoring by anyone with sufficient access/influence at Signal or their data center provider (such as a government who doesn’t like encrypted messaging).

This one is just a straight-up lie. Everything on the server is encrypted and no one has the keys except the participants.

Encryption doesn't hide network traffic. Signal's centralised design means there is a single point where that traffic can be monitored and traced to reveal which endpoints are talking to each other, and where, and when.

What I wrote is not a lie, which you would know if you actually understood these issues. Please stop making baseless accusations. You are wrong, and you are being very rude.

If you're interested in correcting your ignorance, I suggest starting with this paper, which touches on some of the issues:

https://www.ndss-symposium.org/ndss-paper/improving-signals-sealed-sender/

If the paper is too much for you, the linked video does a pretty good job of explaining.

[–] EngineerGaming@feddit.nl 2 points 1 hour ago

I would be more concerned about how phone-oriented it is. A phone's default OS is such spyware that I am not sure just what is safe from from being uploaded. And even if the person wants a more private alternative, most phones have locked bootloaders. On the other hand, Linux would run on damn near anything... But using Signal on it without a smartphone is very annoying. No way my mom would understand an Android VM or a command-line client, because the desktop client isn't feature-full and doesn't even allow registration.