[HN Gopher] My list of favorite secure messaging apps
___________________________________________________________________
My list of favorite secure messaging apps
Author : Sami_Lehtinen
Score : 63 points
Date : 2023-01-12 18:48 UTC (4 hours ago)
(HTM) web link (supernova.tilde.team)
(TXT) w3m dump (supernova.tilde.team)
| imhoguy wrote:
| SimpleX looks too good to be true! It even has terminal client
| https://github.com/simplex-chat/simplex-chat/blob/stable/doc...
| getty wrote:
| One of the cons for Signal, sending unencrypted SMS messages is
| being removed soon: https://signal.org/blog/sms-removal-android/
| marssaxman wrote:
| Bummer. That feature made Signal a really compelling main
| messenger app.
| dougk16 wrote:
| Really great list. Thank you. Some of these I wasn't even aware
| of. I've been using Session for about a year. A year ago it
| definitely had some missed messages and I was about to ditch it
| but I held strong and haven't experienced that issue in a while.
| Been flawless for about half a year. The Oxen/Loki network
| overall https://oxen.io/ is a really interesting alternative to
| Monero and Tor. It's interesting how it can be both!
| tjmehta wrote:
| What about WhatsApp...?
| boring_twenties wrote:
| What about it? It's not open source, so shouldn't even be
| considered.
| ask_b123 wrote:
| There are non-open source apps listed in the OP.
| daneel_w wrote:
| I've been waiting for Briar to show up for iOS ever since I came
| across it many years ago.
| fersarr wrote:
| What about Matrix/Element?
| entrepy123 wrote:
| Matrix/Element was the best fit when I looked into reasonably
| private messaging for a small org.
|
| - Matrix has E2EE support, the able to be self-hosted, decent
| if not perfect clients for all platforms, and an easy to spin
| up hosted solution through their services company. I think who
| talks to who could leak, but I think the content is reasonably
| put into an envelope so to speak. The 2019 security issue seems
| to have been resolved.
|
| I just wish there was a built-in option for Matrix (Element.io)
| instances to enforce "only allow E2EE chats". I mean: allowing
| instances to disable federation prevents some outflows, and
| E2EE by default is sane, but I want to NOT allow users to
| accidentally (e.g., in ignorance) click the toggle switch that
| turns off E2EE for communication chats that they create.
|
| BIGGEST FEEDBACK ON MATRIX/Element: I really think this "only
| allow E2EE" should be part of the protocol somehow (as an
| option for instances), and not just a server
| customization/implementation detail. --> I haven't had the
| courage to contribute this meek suggestion to "More Instant
| Messaging Interoperability (MIMI)" [0, 1], but does anyone know
| if it's being talked about? Does this make sense? It seems sort
| of obvious to me.
|
| [0] https://mailarchive.ietf.org/arch/browse/mimi/
|
| [1] https://turt2live.github.io/ietf-mimi-matrix-message-
| format/...
| ishche wrote:
| Is telegram so bad?
| itake wrote:
| What do you think of Wickr?
| __derek__ wrote:
| For personal use, it's not long for this world.[1]
|
| [1]: https://wickr.com/our-focus-on-end-to-end-encrypted-
| enterpri...
| jckahn wrote:
| Since it's relevant to the topic, I'd like to share an open
| source communication tool I started working on last year:
| https://chitchatter.im/
|
| Chitchatter does ephemeral P2P messaging, audio and video chat,
| and file sharing in a serverless manner.
| buster wrote:
| I miss delta chat in that list. :(
| null0pointer wrote:
| This list was nice to learn about some apps I wasn't yet aware
| of. One thing the author mentioned as a "con" a couple of times
| is "No option for automatic deletion of messages". It might be
| worth noting that no app can provide automatic deletion of
| messages. Yes there are some apps that have messages disappear
| after a time but there is nothing stopping those messages from
| being saved by the other party before that time. If not a data
| export then a screenshot, and if not a screenshot then a camera
| pointed at the screen. If the message is to be consumed by a
| human then it can be recorded.
| snapplebobapple wrote:
| The purpose of automatic message deletion isn't to protect you
| from someone actively trying to record your messages, it's to
| limit both parties liability in the event one or both parties
| are compromised by a third party after the fact.
| vbarrielle wrote:
| The threat model that's addressed by deletion of message is the
| seizing of one's device by a hostile party (eg dictatorship).
| One cannot be incriminated by messages that have been deleted.
|
| As you pointed out this will not help if your correspondent
| cannot be trusted.
| twhb wrote:
| Right, disappearing messages aren't a safeguard against a
| malicious recipient, they're a blast radius limiter on future
| device compromise on either end.
| [deleted]
| fenesiistvan wrote:
| The telecom industry runs around the legacy SIP/WebRTC protocols.
| What about these? Both of them can be secured (TLS/SRTP/DTLS),
| but they are usually centralized.
| ale42 wrote:
| Why legacy? They're still current, and WebRTC is fairly recent.
| The SS7 mess behind PSTN networks is perhaps more legacy.
| galleywest200 wrote:
| You could easily spin up some FreePBX server (or similar) and
| connect SIP devices to talk to each other entirely securely.
| But calls out to the PSTN are a whole different issue.
| 12311231231 wrote:
| [dead]
| SkyMarshal wrote:
| No mention of Tox? https://tox.chat/
| eps wrote:
| The project is 10 years old, still at 0.2 release, which is now
| 9 months old, and virtually no activity on the repo. Looks as
| good as dead.
| snotrockets wrote:
| Aside from the obvious flaws (Threema isn't secure:
| https://breakingthe3ma.app/), this is LARPing: the author wants
| to keep his chats secret, but he doesn't discuss why and from
| whom. This is amateurish, as your efforts should be defined by
| the threat model, not the other way around. How much effort is
| your attacker capable of? How much effort are you willing to
| spend on opsec, a notoriously hard and inhuman task?
|
| There's a whole difference if you want to keep your affair secret
| from your wife, your small-time weed dealing from the police,
| your spy ring from the FBI, coordinating anti-Russian attacks in
| Ukraine, or a Chinese resident resisting the regime.
| rgrmrts wrote:
| The author is simply sharing their preferred messaging apps,
| and they describe the criteria used. Sure it's not an objective
| in-depth security analysis or a result of professional audits
| but it's also not claiming to be those things, right?
| __derek__ wrote:
| The introduction implies some level of security analysis
| based on the list of "criteria" (e.g., "does not expose
| personal information" and "does not leak data") and the
| "testing setup" link.
| generalizations wrote:
| Understanding the threat model isn't an "in-depth security
| analysis", though. It's just a matter of understanding _why
| you care_ about secure apps - who you want to be secure from.
| If you don 't know that, then these are just toys, and you're
| just playing.
| detrites wrote:
| Great! Some of us like play.
| [deleted]
___________________________________________________________________
(page generated 2023-01-12 23:02 UTC)