Which is your preferred messaging app? I just want some insights about these two.
You may share other messaging apps too.
xmpp + omemo. Signal is centralized, matrix leaks tons of metadata to sync between services…
Signal is a centralized, US-based service which requires your phone number (thus your real identity, IE name and address), has social networking graphs of everyone you talk to, and must forward that information to the US government when asked, as well as (by law) not tell you that they’ve been asked to do so. During the Obama era, 60 NSLs were issued for this private information every single day.
People overlook its privacy concerns for the same reason they do with apple: it has a shiny interface and is easy to use, and makes people very attached to it. Behind all that, is a surveillance network that its creators have explicitly said they do not want it to be able to run in a decentralized, private manner.
It has a long history of privacy offenses below (such as refusing to publish its server’s source code for years, its reliance on other US tech services (amazon, google), US-government funding, and a US-defense-tank friendly administration) which get ignored or shouted down by many of those above. See the article below.
Pretty much any alternative is better, as long as its not hosted in a five-eyes country, and especially if it doesn’t require phone numbers or real identities like signal does.
I personally have been using SimpleX for friends and real life contacts, and Matrix for larger more anonymous group chats.
has social networking graphs of everyone you talk to
Source?
US government funding does not mean it’s immediately bad… The internet, thr flu vaccine, closed captioning, and wheather radar were all funded by the US government. A truly secure messaging encryption is beneficial to the United States, and is evem good enough for the president apparently.
Since their messages are truly secure, it wouldn’t matter where you store them. Just store them in the cheapest places possible. It being centralized makes it far more usable to the average person, making it much more likely for them to use.
Read the linked doc, because it’s clear you didn’t.
I read it. They also have no source or evidence.
Signals database, which we must assume is compromised due to its centralized and US domiciled nature, has a few important pieces of data;
You can’t simply say “we must assume” as evidence. In fact, they implemented “Sealed sender” in 2018 where they are not able to see who the message is being sent to.
They are also legally required to provide all information they have on users for warrants and subpoenas. Any time they do that, they post the (slightly redacted) document they provided to the courts. See the list here: https://signal.org/bigbrother/ This confirms they did not have any metadata on those users. The only info they have is what they openly state (phone number, date of registration, and last time a message was sent).
While there may be other US government requests they are not alllwed to disclose, they were legally required to provide the same information to the courts, and we can see what they provided.
And sure, while the US government funds Signal, you know who else endorses it? Edward fucking Snowden. If anyone knows about secure messaging, it’s the man that physically removes the microphone and camera from his phones before using them.
You can’t simply say “we must assume” as evidence.
Okay yeah you definitely didn’t read it. Large sections in that doc just before that are on phone number identifiers, NSLs, and 5-eyes countries, the US goverment pushing signal in privacy spaces… literally the reasons why signal isn’t trustworthy. Unless you can tell me what an NSL is, then I’ll assume you didn’t read it.
While there may be other US government requests they are not alllwed to disclose, they were legally required to provide the same information to the courts, and we can see what they provided.
Did you ignore the large section on NSLs? These come with a gag order, meaning its illegal for signal to notify their users about them being spied on.
In fact, they implemented “Sealed sender” in 2018 where they are not able to see who the message is being sent to.
This is a “just trust me” from signal, since neither of us have access to their centralized DB, but you also ignored two paragraphs down, where it showed that with message timestamps and recipient information, this would be trivial to find the real sender of a message, regardless of sealed sender. Again, actually open source software can’t say “just trust me” like signal can, we actually have to show code to prove it, and let people run that code in a private manner.
And sure, while the US government funds Signal, you know who else endorses it? Edward fucking Snowden. If anyone knows about secure messaging, it’s the man that physically removes the microphone and camera from his phones before using them.
Elon musk and jack dorsey also endorse signal. An endorsement means nothing, especially for centralized software based in a 5-eyes country.
Large sections in that doc just before that are on phone number identifiers, NSLs, and 5-eyes countries, the US goverment pushing signal in privacy spaces…
Two things:
- Get a burner phone with cash
- This has nothing to do with the claim Signal collects metadata.
If Signal stored a DB of messages sent and received, they would legally have to provide that for a court warrant. The fact they did not provide that to the courts proves they do not store that data.
Did you ignore the large section on NSLs?
No, those are the government requests I mentioned in the quoted section. I just didn’t say “NSL”. Their example with Lavabit was fundamentally different since Lavabit was in control of the TLS keys and was able to decrypt the content, but they refused. Signal is complying without giving anything to the government because they have no way of decrypting the messages, even if they wanted to.
actually open source software can’t say “just trust me” like signal can, we actually have to show code to prove it, and let people run that code in a private manner.
Open Source: Open source is the practice of publishing digital resources publicly alongside their source code or source files, enabling use, study, modification, and redistribution.
Here is there Server source code with GNU AGPLv3 license. I’d say that fits the definition of open source.
I recognize there isn’t a way to confirm they are running the code they published. Even signal has recognized the server source code trust issue:
Of course, what if that’s not the source code that’s actually running? After all, we could surreptitiously modify the service to log users’ contact discovery requests. Even if we have no motive to do that, someone who hacks the Signal service could potentially modify the code so that it logs user contact discovery requests, or (although unlikely given present law) some government agency could show up and require us to change the service so that it logs contact discovery requests. More fundamentally for us, we simply don’t want people to have to trust us.
https://signal.org/blog/private-contact-discovery/
That’s why the set it up to minimize the required trust. The client side code is fundamentally built to make the trust required in Signal to be very minimal. You can build the client app from the source code and confirm everything in it.
An endorsement means nothing, especially for centralized software based in a 5-eyes country.
Edward Snowden is mentioned several times, and quoted, on the 5-Eyes wikipedia as a whistleblower. If the worlds most famous 5-Eyes whistleblower endorses Signal as a way to hide from the 5-Eyes, that’s a pretty damn good endorsement. I recognize that means nothing to you, and that’s fair. I’m more so pointing out the humor.
I will concede that the US government could force Signal to start collecting metadata and we would have no way of knowing. I do think they would fight it, or move to another country, given they have threatened to withdraw services from other countries already. It’s not a great comparison, since the Government was trying to get access to message contents rather than metadata, and Signal would only be stopping service and not change country of operations.
Regardless, Signal is convenient. We all know the balance between security and convenience, and Signal is a good middle ground. It’s a single app users can download, and it’s quick to setup, and they can use the same phone number/contacts they already have. They don’t have to determine a server they want to create their account on, learn what federation is, etc. Signal is a good option, and I would 100% tell people to use Signal over Whatsapp, Telegram, RCS, and especially SMS.
If we wanted to discuss the problems with something like Matrix, it would also be very flawed. You shift the trust to the home server of your choosing not to keep the metadata (It’s not realistic to ask a random person to start their own server). It has a much larger attack surface, between the different clients, servers, bridges, bots, extensions, etc. Even if Matrix itself is relatively secure, it only takes a single integration with a vulnerability to compromise their data. For example, they may bridge Matrix to Slack for specific use case, but if that bridge gets compromised then you could be vulnerable.
Insightful! Thanks. I agree and I’ll give SimpleX a try as others suggested.
I actually prefer XMPP. It’s also less of a hassle to set up than Matrix and the protocol is much more mature. There are still issues, but it’s rather functional for audio and video calls (if you’re using a supported client).
Edit: For clients, I use Cheogram on Android and Profanity (which is a TUI) or DinoX (for calls) on Linux.
Signal. Matrix was made by Israeli spyware company Amdocs and when an employee was asked about it after the split to a UK company they pretended like Amdocs wasn’t caught in multiple global spyware scandals already.
But they say Signal is centralized, and hosted in the US.
So neither is the answer, I guess. We’re cooked.
For easy privacy the answer is Signal. If you want to put in effort then SimpleX or others seem better.
Matrix MIGHT be okay if you self host it, but I definitely wouldn’t trust the main Element hosted server. But the dev team sketches me out too hard so I’d just pick alternatives.
What really helps with such decisions is your use model and threat model. Then a nice matrix that compares them all. Haven’t come across a good updated comparison in a while. Would be good to see a shared link here.
Simplex
Only because nobody answered with this one:
IRC
Decentralized and an open protocol. Client setup to connect is not so straightforward, but it’s a one and done. Very robust.
I’m allergic to centralized communication schemes, though I do use signal to communicate with one person.
I want to research some of the other suggestions that have been brought up, so thank you for the post!
That’s new to me. Thanks!
Lmfao that’s funny, IRC is the oldest of them all.
Delta chat and session (RIP): they dont ask for accounts or ID to chat
Currently me and my friend are using a self-hosted server with Matrix, and Sable as a client.
Sable is the only one with Discord-like functions out of all the clients I’ve tried, all the others falling very short.
Besides that there is Fluxer, which is far more feature complete than any Matrix client. It has some key features holding it back, though, which are no Federation yet, and no E2E encryption yet. But otherwise setting up your own fully functional server is incredibly easily.
I created this to help find active matrix rooms https://activematrixrooms.com/
Cool! Thanks.
I don’t use either, bcz I use simplex in my personal life. It is really quite great!
- If you have a targeted group/peer need then whatever they are using or whatever you all decide right in the beginning - I’d suggest Matrix or some other decentralised alternative, definitely not Signal.
- Matrix had the huge opportunity to be “the messaging app” but they neither became good at corporate usage and definitely ended up sucking at personal usage. They started doing too many things, at once, and while completely ignoring the individual user.
- If you want a wider general acceptance then sadly Matrix is DoA. WhatsApp becomes a huge choice outside USA and China but it has started becoming shittier by the day and looking at who has become WhatsApp’s global head now, I don’t think it’s gonna get any better (check his last “app” or company’s screenshots and come here if you don’t end up vomiting). So Signal or maybe some other similar app. You are limited by societal trends and acceptance here, not the tech or finesse or privacy of an app.
- If you just want privacy and a simpler app, proven (at least so far), then well Signal it is, as much as I hate it for reasons they decided to make it a centralised messaging app and then stuffed crypto in it etc.
- If you have a targeted group/peer need then whatever they are using or whatever you all decide right in the beginning - I’d suggest Matrix or some other decentralised alternative, definitely not Signal.
Matrix is only really enjoyable with unencrypted chats.
I have fairly recently switched phones. Now, a good number of older messenges fail to decrypt. Even when I don’t switch devices, a group chat for a three day long event with a very small group already gave us lots of fun decryption errors. Oh, and I have this other fun group chat where Fluffy Chat constantly reminds me that people whose devices I haven’t verified will be able to read my messenges every time I send something. Also, Matrix has coutless clients with different feature sets and I heard calls are a pain to ßet up.
Signal, on the other hand, just works. Federation and decentralization is obviously nice but a functional product is more importmant. I haven’t had a chance to try XMPP unfortunately.
Don’t you have your encryption key saved somewhere?
I prefer SecureBit Chat . No account, P2P, EE2E, Quantum resistent.
Signal. The app is miles better. I do use matrix too tho for some communities and for keeping an eye for the development









