7 ms·
> Use Signal. Or Wire, or WhatsApp, or some other Signal-protocol-based secure messenger. That's a "great" idea considering the recent legal developments in th
by jhgb 9mo ago
> Use Signal. Or Wire, or WhatsApp, or some other Signal-protocol-based secure messenger.
That's a "great" idea considering the recent legal developments in the EU, which OpenPGP, as bad as it is, doesn't suffer from. It would be great if the author updated his advice into something more future-proof.
- akerl_ 9mo agoThere's no future-proof suggestion that's immune to the government declaring it a crime. If you want a suggestion for secure messaging, it's Signal/WhatsApp. If you want to LARP at security with a handful of other folks, GPG is a fine way to do that.
- jhgb 9mo agoNobody decided that it's a crime, and it's unlikely to happen. Question is, what do you do with mandatory snooping of centralized proprietary services that renders them functionally useless aside from "just live with it". I was hoping for actual advice rather than a snarky non-response, yet here we are.
- akerl_ 9mo agoI gave you the answer that exists: I'm not aware of any existing or likely-to-exist secure messaging solution that would be a viable recommendation. The available open-source options come nowhere close to the messaging security that Signal/Whatsapp provide. So you're left with either "find a way to access Signal after they pull out of whatever region has criminalized them operating with a backdoor on comms" or "pick any option that doesn't actually have strong messaging security".
- johnisgood 9mo ago> messaging security > WhatsApp Eh? There are alternatives, try Ricochet (Refresh) or Cwtch.
- akerl_ 9mo agoI stand by what I said.
- johnisgood 9mo agoI mean... why?
- closewith 9mo agoNot the GP, but most of us want to communicate with other people, which means SMS or WhatsApp. No point have perfect one-time-pad encryption and no one to share pads with.
- Fnoord 9mo ago> Nobody decided that it's a crime, and it's unlikely to happen. Which jurisdiction are you on about? [1] Pick your poison. For example, UK has a law forcing suspects to cooperate. This law has been used to convict suspects who weren't cooperating. NL does not, but police can use force to have a suspect unlock a device using finger or face. [1] https://en.wikipedia.org/wiki/Key_disclosure_law https://en.wikipedia.org/wiki/Key_disclosure_law
- closewith 9mo agoYou're asking for a technical solution to a political problem. The answer is not to live with it, but become politically active to try to support your principles. No software can save you from an authoritarian government - you can let that fantasy die.
- signed-log 9mo agoMost countries will throw you in jail for years if you refuse to give the password to encrypted devices they want. [1] And that's even if you are innocent on the underlying charge or search. Encryption in this political climate, is a pick your poison. - Either you go to jail for years but you know your gov and other actors has no access to your data. - or you store on remote/proprietary apps, stay free, but your gov or other actors may or may not have access to it. [1]: https://en.wikipedia.org/wiki/Key_disclosure_law https://en.wikipedia.org/wiki/Key_disclosure_law
- anonym29 9mo agoCould you please link the source code for the WhatsApp client, so that we can see the cryptographic keys aren't being stored and later uploaded to Meta's servers, completely defeating the entire point of Signal's E2EE implementation and ratchet protocol?
- akerl_ 9mo agoThis may shock you, but plenty of cutting-edge application security analysis doesn't start with source code. There are many reasons, but one of them is that for the overwhelming majority of humans on the planet, their apps aren't being compiled from source on their device. So since you have to account for the fact that the app in the App Store may not be what's in some git repo, you may as well just start with the compiled/distributed app.
- anonym29 9mo agoWhether or not other people build from source code has zero relevance to a discussion about the trustworthiness of security promises coming from former PRISM data providers about the closed-source software they distribute. Source availability isn't theater, even when most people never read it, let alone build from it. The existence of surreptitious backdoors and dynamic analysis isn't a knock against source availability. Signal and WhatsApp do not belong in the same sentence together. One's open source software developed and distributed by a nonprofit foundation with a lengthy history of preserving and advancing accessible, trustworthy, verifiable encrypted calling and messaging going back to TextSecure and RedPhone, the other's a piece of proprietary software developed and distributed by a for-profit corporation whose entire business model is bulk harvesting of user data, with a lengthy history of misleading and manipulating their own users and distributing user data (including message contents) to shady data brokers and intelligence agencies. To imply these two offer even a semblance of equivalent privacy expectations is misguided, to put it generously.
- tptacek 9mo agoThese are words, but I don't understand how they respond to the preceding comment, which observes that binary legibility is an operational requirement for real security given that almost nobody uses reproducible builds. In reality, people meaningfully depend on work done at the binary level to ensure lack of backdoors, not on work done at the source level. The preceding comment is saying that source security is insufficient, not that transparency is irrelevant.
- goldsteinq 9mo ago> If you want a suggestion for secure messaging, it's Signal/WhatsApp. If you want to LARP at security with a handful of other folks, GPG is a fine way to do that. I want secure messaging, not encrypted SMS. I want my messages to sync properly between arbitrary number of devices. I want my messaging history to not be lost when I lose a device. I want not losing my messaging history to not be a paid feature. I want to not depend on a shady crypto company to send a message.
- some_furry 9mo ago> I want secure messaging, not encrypted SMS. I send long messages via Signal, typed on a desktop computer, all the time. (In fact, I almost exclusively use Signal through my desktop app.) You don't have to use it like "encrypted SMS"! You're free. > I want my messages to sync properly between arbitrary number of devices. I want my messaging history to not be lost when I lose a device. OK. https://signal.org/blog/a-synchronized-start-for-linked-devices/ https://signal.org/blog/a-synchronized-start-for-linked-devi... > I want not losing my messaging history to not be a paid feature. I genuinely don't understand what you mean here. From https://signal.org/blog/introducing-secure-backups/ https://signal.org/blog/introducing-secure-backups/ "If you do decide to opt in to secure backups, you’ll be able to securely back up all of your text messages and the last 45 days’ worth of media for free." If you have a metric fuckton of messages, that does cost money, sure, but as they say: "If you want to back up your media history beyond 45 days, as well as your message history, we also offer a paid subscription plan for US$1.99 per month." "This is the first time we’ve offered a paid feature. The reason we’re doing this is simple: media requires a lot of storage, and storing and transferring large amounts of data is expensive. As a nonprofit that refuses to collect or sell your data, Signal needs to cover those costs differently than other tech organizations that offer similar products but support themselves by selling ads and monetizing data." If you want Signal to host the encrypted storage, that costs money. If you don't want to pay Signal money, they provide 45 days of backup for free. If you want to self-host your own backups (at your own cost), that's easy to do. https://imgur.com/a/EIfaIee https://imgur.com/a/EIfaIee You can literally set up SyncThing to stream your on-device backups to your NAS, cloud storage, or whatever. > I want to not depend on a shady crypto company to send a message. Shady crypto company? Are you referring to MobileCoin? That feature isn't in the pipeline for sending messages. I checked! https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/ https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...
- deleted 9mo ago[deleted]