this post was submitted on 07 Feb 2025
284 points (98.6% liked)

Technology

61850 readers
2490 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

I currently use Telegram for my friends and family, but have reluctantly come to the conclusion that the UK Government is either reaching agreement for backdoors with messaging services, or is trying its hardest to.

I'm also on Element/Matrix. Before I try to get my contacts to join me on there, should I be aware of any privacy issues or is that a good place to head?

you are viewing a single comment's thread
view the rest of the comments
[–] cmhe@lemmy.world 4 points 3 hours ago (2 children)

But you should also be aware that Signal does not federate, so the company can be bought. They have control over all accounts and the servers, without easy way to migrate away again. So it might just be another trap.

Try to use federated services (like matrix), they are more robust against hostile take overs.

[–] Andromxda@lemmy.dbzer0.com 6 points 3 hours ago (1 children)

so the company can be bought

The company (Signal Messenger LLC) is fully owned by Signal Foundation, a 501(c)3 non profit organization.

Try to use federated services

I generally like this idea, and I also use federated services for things like social media, that's why we're having a discussion here on Lemmy. But it introduces some issues with private messaging, like lack of reliability, which sucks if you want to use Matrix as your primary messenger, as well as metadata leaks. Federation is not always the answer, and in my opinion definitely not when it comes private and secure messaging.

they are more robust against hostile take overs

Probably around 80-90% of Matrix users are on the matrix.org homeserver, so it's absolutely not as decentralized and resilient as you think it is.

[–] cmhe@lemmy.world 1 points 3 hours ago

The company (Signal Messenger LLC) is fully owned by Signal Foundation, a 501(c)3 non profit organization.

OpenAI is also non-profit. Not really an argument.

Probably around 80-90% of Matrix users are on the matrix.org homeserver, so it's absolutely not as decentralized and resilient as you think it is.

Well, the goal is that moving to your own server, will not mean that you will loose access to all your contacts. Which makes moving instances much simpler. If Matrix gets a hostile take-over, your don't really need to reach a critical mass for an alternative server.

[–] JOMusic@lemmy.ml 5 points 3 hours ago* (last edited 3 hours ago) (1 children)

At least (to my knowledge) the Signal messages are decrypted on the client end, so buying the company doesn't give them automatic access to messages.

Having said that, I'm sure a hostile new owner could update the app to decrypt and then send the messages as plaintext to the servers if they wanted..

[–] cmhe@lemmy.world 2 points 3 hours ago (1 children)

Well, you can still insert client side decryption into the app.

But it isn't really about the messages, it is about the control of the servers and the accounts. You cannot easily move away from their servers, because you will lose your contacts. This gives the people controlling the servers power over you. A sort of vendor lockin.

[–] Andromxda@lemmy.dbzer0.com 1 points 2 hours ago (1 children)

Well, you can still insert client side decryption into the app.

That's why all clients are fully open-source. You can also use a fork like Molly.

[–] cmhe@lemmy.world 2 points 2 hours ago* (last edited 2 hours ago)

AFAIK, Signal does not want anyone to use alternative clients, has that changed?

As far as I know moxie, signals lead dev, considers only the use of the officially build and distributed client authorized to use their servers.

So if they ever manage to detect someone using their services with an alternative client, they might delete your account.

https://techcrunch.com/2016/11/07/signal-app-maker-rebuts-criticism-of-dev-direction-by-calling-for-more-community-help/