[HN Gopher] My list of favorite secure messaging apps
       ___________________________________________________________________
        
       My list of favorite secure messaging apps
        
       Author : Sami_Lehtinen
       Score  : 63 points
       Date   : 2023-01-12 18:48 UTC (4 hours ago)
        
 (HTM) web link (supernova.tilde.team)
 (TXT) w3m dump (supernova.tilde.team)
        
       | imhoguy wrote:
       | SimpleX looks too good to be true! It even has terminal client
       | https://github.com/simplex-chat/simplex-chat/blob/stable/doc...
        
       | getty wrote:
       | One of the cons for Signal, sending unencrypted SMS messages is
       | being removed soon: https://signal.org/blog/sms-removal-android/
        
         | marssaxman wrote:
         | Bummer. That feature made Signal a really compelling main
         | messenger app.
        
       | dougk16 wrote:
       | Really great list. Thank you. Some of these I wasn't even aware
       | of. I've been using Session for about a year. A year ago it
       | definitely had some missed messages and I was about to ditch it
       | but I held strong and haven't experienced that issue in a while.
       | Been flawless for about half a year. The Oxen/Loki network
       | overall https://oxen.io/ is a really interesting alternative to
       | Monero and Tor. It's interesting how it can be both!
        
       | tjmehta wrote:
       | What about WhatsApp...?
        
         | boring_twenties wrote:
         | What about it? It's not open source, so shouldn't even be
         | considered.
        
           | ask_b123 wrote:
           | There are non-open source apps listed in the OP.
        
       | daneel_w wrote:
       | I've been waiting for Briar to show up for iOS ever since I came
       | across it many years ago.
        
       | fersarr wrote:
       | What about Matrix/Element?
        
         | entrepy123 wrote:
         | Matrix/Element was the best fit when I looked into reasonably
         | private messaging for a small org.
         | 
         | - Matrix has E2EE support, the able to be self-hosted, decent
         | if not perfect clients for all platforms, and an easy to spin
         | up hosted solution through their services company. I think who
         | talks to who could leak, but I think the content is reasonably
         | put into an envelope so to speak. The 2019 security issue seems
         | to have been resolved.
         | 
         | I just wish there was a built-in option for Matrix (Element.io)
         | instances to enforce "only allow E2EE chats". I mean: allowing
         | instances to disable federation prevents some outflows, and
         | E2EE by default is sane, but I want to NOT allow users to
         | accidentally (e.g., in ignorance) click the toggle switch that
         | turns off E2EE for communication chats that they create.
         | 
         | BIGGEST FEEDBACK ON MATRIX/Element: I really think this "only
         | allow E2EE" should be part of the protocol somehow (as an
         | option for instances), and not just a server
         | customization/implementation detail. --> I haven't had the
         | courage to contribute this meek suggestion to "More Instant
         | Messaging Interoperability (MIMI)" [0, 1], but does anyone know
         | if it's being talked about? Does this make sense? It seems sort
         | of obvious to me.
         | 
         | [0] https://mailarchive.ietf.org/arch/browse/mimi/
         | 
         | [1] https://turt2live.github.io/ietf-mimi-matrix-message-
         | format/...
        
       | ishche wrote:
       | Is telegram so bad?
        
       | itake wrote:
       | What do you think of Wickr?
        
         | __derek__ wrote:
         | For personal use, it's not long for this world.[1]
         | 
         | [1]: https://wickr.com/our-focus-on-end-to-end-encrypted-
         | enterpri...
        
       | jckahn wrote:
       | Since it's relevant to the topic, I'd like to share an open
       | source communication tool I started working on last year:
       | https://chitchatter.im/
       | 
       | Chitchatter does ephemeral P2P messaging, audio and video chat,
       | and file sharing in a serverless manner.
        
       | buster wrote:
       | I miss delta chat in that list. :(
        
       | null0pointer wrote:
       | This list was nice to learn about some apps I wasn't yet aware
       | of. One thing the author mentioned as a "con" a couple of times
       | is "No option for automatic deletion of messages". It might be
       | worth noting that no app can provide automatic deletion of
       | messages. Yes there are some apps that have messages disappear
       | after a time but there is nothing stopping those messages from
       | being saved by the other party before that time. If not a data
       | export then a screenshot, and if not a screenshot then a camera
       | pointed at the screen. If the message is to be consumed by a
       | human then it can be recorded.
        
         | snapplebobapple wrote:
         | The purpose of automatic message deletion isn't to protect you
         | from someone actively trying to record your messages, it's to
         | limit both parties liability in the event one or both parties
         | are compromised by a third party after the fact.
        
         | vbarrielle wrote:
         | The threat model that's addressed by deletion of message is the
         | seizing of one's device by a hostile party (eg dictatorship).
         | One cannot be incriminated by messages that have been deleted.
         | 
         | As you pointed out this will not help if your correspondent
         | cannot be trusted.
        
         | twhb wrote:
         | Right, disappearing messages aren't a safeguard against a
         | malicious recipient, they're a blast radius limiter on future
         | device compromise on either end.
        
         | [deleted]
        
       | fenesiistvan wrote:
       | The telecom industry runs around the legacy SIP/WebRTC protocols.
       | What about these? Both of them can be secured (TLS/SRTP/DTLS),
       | but they are usually centralized.
        
         | ale42 wrote:
         | Why legacy? They're still current, and WebRTC is fairly recent.
         | The SS7 mess behind PSTN networks is perhaps more legacy.
        
         | galleywest200 wrote:
         | You could easily spin up some FreePBX server (or similar) and
         | connect SIP devices to talk to each other entirely securely.
         | But calls out to the PSTN are a whole different issue.
        
       | 12311231231 wrote:
       | [dead]
        
       | SkyMarshal wrote:
       | No mention of Tox? https://tox.chat/
        
         | eps wrote:
         | The project is 10 years old, still at 0.2 release, which is now
         | 9 months old, and virtually no activity on the repo. Looks as
         | good as dead.
        
       | snotrockets wrote:
       | Aside from the obvious flaws (Threema isn't secure:
       | https://breakingthe3ma.app/), this is LARPing: the author wants
       | to keep his chats secret, but he doesn't discuss why and from
       | whom. This is amateurish, as your efforts should be defined by
       | the threat model, not the other way around. How much effort is
       | your attacker capable of? How much effort are you willing to
       | spend on opsec, a notoriously hard and inhuman task?
       | 
       | There's a whole difference if you want to keep your affair secret
       | from your wife, your small-time weed dealing from the police,
       | your spy ring from the FBI, coordinating anti-Russian attacks in
       | Ukraine, or a Chinese resident resisting the regime.
        
         | rgrmrts wrote:
         | The author is simply sharing their preferred messaging apps,
         | and they describe the criteria used. Sure it's not an objective
         | in-depth security analysis or a result of professional audits
         | but it's also not claiming to be those things, right?
        
           | __derek__ wrote:
           | The introduction implies some level of security analysis
           | based on the list of "criteria" (e.g., "does not expose
           | personal information" and "does not leak data") and the
           | "testing setup" link.
        
           | generalizations wrote:
           | Understanding the threat model isn't an "in-depth security
           | analysis", though. It's just a matter of understanding _why
           | you care_ about secure apps - who you want to be secure from.
           | If you don 't know that, then these are just toys, and you're
           | just playing.
        
             | detrites wrote:
             | Great! Some of us like play.
        
         | [deleted]
        
       ___________________________________________________________________
       (page generated 2023-01-12 23:02 UTC)