Post B4pR2UeyXoDJ67SQZE by OnkelBobbyWhite@mastodon.social
(DIR) More posts by OnkelBobbyWhite@mastodon.social
(DIR) Post #B4pMcE23LNbGBKTF9U by delta@chaos.social
0 likes, 0 repeats
After three intense months of work from more than a dozen contributors, #deltachat 2.48 releases are rolling. Maybe the most feature-packed releases ever? - "zero metadata" messaging- native Audio/Video calls on Android and iOS, as well as UbuntuTouch- Group and Channel descriptions- A new background audio player- Revamped Download-on-Demandand, last but not least, the long-awaited next-generation of messaging resiliency through "multi-path" routing .... https://delta.chat/en/2026-03-31-zero
(DIR) Post #B4pNlmDRicVUlFuymW by Lucseleventje@toot.community
0 likes, 0 repeats
@delta Wow! š
(DIR) Post #B4pNqiiCAqvJLEerC4 by goetz@freiburg.social
0 likes, 0 repeats
@delta Ups, and what if i already enabled (and added) additional relays with 2.43 and I want to upgrade to 2.48 (where the rel-notes state "Ensure all your devices are upgraded to version 2.48 or later before enabling this feature.")
(DIR) Post #B4pO1l83Wm1w1W1ASu by delta@chaos.social
0 likes, 0 repeats
@goetz this should work fine but it's better to upgrade still. Some details are better co-ordinated. But nothing bad or irreversible should happen if you use 2.43 and 2.48 side by side.
(DIR) Post #B4pO6QWrXqala8qYkq by zaire@fedi.absturztau.be
0 likes, 0 repeats
@delta havent you always been advertising āzero metadataā. now its zero-er? hmh
(DIR) Post #B4pO6QiYqLwwAQJtzM by delta@chaos.social
0 likes, 0 repeats
@zaire we minimized metadata in prior steps, but only this release goes all the way. Maybe read the post for more context.
(DIR) Post #B4pPqtTWM8nQdE0Li4 by severin@hci.social
0 likes, 0 repeats
@delta looks like an impressive release! Audio/video calls based on WebRTC 𤩠Congrats to the devs! imho, the last remaing hurdle for much greater reach for deltachat is contact discovery. Any plans/ideas about that?
(DIR) Post #B4pQ6AHCAicz5EWNTU by Onlykievv@bonito.cafe
0 likes, 0 repeats
@delta a job well done, I was waiting for the support for audio and video calls, thank you very much to the developers.
(DIR) Post #B4pQ9RSuihcXGMZ6QK by delta@chaos.social
0 likes, 0 repeats
@severin thanks! Unfortunately, it is not likely the apps will offer contact discovery themselves. It would bring #deltachat closer to being a social media app, and invite spam and abuse which we are not prepared to handle due to the decentralized nature of our efforts. We do not know, mediate or see any interactions between users, an providing central discovery would break that privacy property.
(DIR) Post #B4pQhSkCTJZx4hsBfc by jaseg@chaos.social
0 likes, 0 repeats
@delta please correct me if iām wrong. from your post it sound like what you call āzero metadataā isnāt metadata resistant in the sense that it doesnāt leak timing patterns to relay/mta or network adversaries, right?
(DIR) Post #B4pR2UeyXoDJ67SQZE by OnkelBobbyWhite@mastodon.social
0 likes, 0 repeats
@delta @severin When I recommend a Delta/Arcane, it's always one of the arguments why this is better than Whatsapp and Signal, and underlines the data protection is written big.
(DIR) Post #B4pRVj6xtRGGJeUMlM by delta@chaos.social
0 likes, 0 repeats
@goetz You can "hide" all relays but one for now, this way all your contacts will send only to one relay and not trigger the bug in 2.43. This is actually done automatically during upgrade, by default all relays except the primary one are hidden right after upgrade, so you don't need to do anything.
(DIR) Post #B4pRXsBr6pCR3KneLo by delta@chaos.social
0 likes, 0 repeats
@jaseg yes, it's about message header metadata, and the fact that no cryptographic identities are visible on the transport layer, making it hard for hostile servers to track anything when users change relays. This blog post is not a security whitepaper, which we admittedly still need to update and produce.
(DIR) Post #B4pS7evFupPcKR6E3E by jaseg@chaos.social
0 likes, 0 repeats
@delta thanks for the clarification. speaking from my network security background, the whole timing leakage is what iād call metadata and what your āzero metadataā thing is protecting (AFAIU timestamps and cryptographic identities) in a cryptographic protocol iād consider straight up data, not metadata.thinking about an average user of a secure comms tool, iād expect they would be surprised to learn that something that is āzero metadataā still leaks timing and through correlation identities.
(DIR) Post #B4pTiT2r8dSC9zlnOq by delta@chaos.social
0 likes, 0 repeats
@jaseg in the very first sentence we try to clarify the scope, i.e. "With the latest 2.48+ releases, a chat message reveals close to zero metadata to servers." The key phrase here is "to servers", and we then detail all the data that was made invisible to the server. If you want to discuss this further, it's maybe better done in a support forum post.
(DIR) Post #B4pURMFrEOSo8EFyXg by vintprox@techhub.social
0 likes, 0 repeats
@delta I swear I saw an incorrect diagram some hour ago, where Alice and Bob only use two of their relays, and while writing my own post I was like: "HUUUUH?". And now it's corrected.
(DIR) Post #B4pfdhcKjMP9MCrHm4 by blueluma@mastodon.social
0 likes, 0 repeats
@delta does DeltaChat use or intend to use a double ratchet encryption algorithm ?
(DIR) Post #B4qIzFc1QhRn5HykKW by jaseg@chaos.social
0 likes, 0 repeats
@delta but it reveals timing, which everyone but you considers metadata, to servers
(DIR) Post #B4qTLVgRMBKQqCIXcO by kbruen@procial.tchncs.de
0 likes, 0 repeats
@delta@chaos.social @zaire@fedi.absturztau.be It doesn't really go "all the way" though. Just because the email address is random, it doesn't make it unbreakable: it's still a unique and persistent identifier.
(DIR) Post #B4qTLWCLRYqiR9E1Lc by zaire@fedi.absturztau.be
0 likes, 0 repeats
@kbruen @delta that. the persistent email addresses have always been a concern of mine. they can be recorded, they can be tracked, whatās up with that
(DIR) Post #B4qTLWVUIOA5OWBJBY by zaire@fedi.absturztau.be
0 likes, 0 repeats
@kbruen @delta part of me feels like delta is so commited to staying āthe email messengerā because of some sunk cost fallacy. dont get me wrong, it works, but theres so much extra working around flaws that wouldntve existed with a proper IM protocol that has to be done
(DIR) Post #B4qTLWmVH7lyFI8thw by kbruen@procial.tchncs.de
0 likes, 0 repeats
@zaire@fedi.absturztau.be @delta@chaos.social No. Using email as a backbone is one of the big selling points. Otherwise, there's dozens of apps out there. Using the email infrastructure brings advantages no other protocol can bring, such as censorship resistance.That's not the issue here. For example, the blog post mentions multiple relays, but only one seems to be used for sending, which feels like that meme of a miner giving up right before reaching diamonds. If Delta Chat would send each message from a random relay, the problem would pretty much be solved. Alas, I have a love-hate relationship with Delta Chat, and I often find the choices of the devs puzzling.
(DIR) Post #B4qTLX8TxPLzLSQRxw by delta@chaos.social
0 likes, 0 repeats
@kbruen @zaire we are proceeding step-wise and aim to provide stable user experiences across versions. In the last section of the blog post https://delta.chat/en/2026-03-31-zero#maximizing-availability-and-resilience-through-multi-path-delivery we already sketch a path forward that includes switching sending relays. But we need to move and change an implementation, and cant just work on the idea level alone.
(DIR) Post #B4qVLJDRuX5E57lm7s by chiefbongo@mastodon.social
0 likes, 0 repeats
@deltaIs telephony e2ee? You only mention peer-to-peer and no mention of e2ee. Well done, you guys are really advancing at a rapid pace!And please no contact-discovery!
(DIR) Post #B4qW3BxwECRkKyRJDc by delta@chaos.social
0 likes, 0 repeats
@chiefbongo yes, calls are end-to-end encrypted. Sorry for not making this more explicit. We also still have work to do to update docs and get everything stabilized š
(DIR) Post #B4qWB5w6Wu83xBLlOC by delta@chaos.social
0 likes, 0 repeats
@chiefbongo and no worries, contact discovery is more or less a no-go area, even though it is lightly discussed sometimes, but certainly not via a centralized server, let alone one that we would run.
(DIR) Post #B4qWa6AYnefvus2C7E by dexternemrod@troet.cafe
0 likes, 0 repeats
@delta@kbruen @zaire I like the step-by-step approach.As soon as address-randomization is reached, the next complaint is that only the same n-adresses are in the pool. So the next request is to let DC create its own addresses. Get me right: This would be an awesome feature, I just use this to demonstrate that this is the nature of iterative approaches and ongoing improvements.
(DIR) Post #B4qZGEAhdarwo1JkKu by kbruen@procial.tchncs.de
0 likes, 0 repeats
@dexternemrod@troet.cafe @delta@chaos.social @zaire@fedi.absturztau.be I'm not complaining about iterative development, I'm complaining about the blog post being titled "Zero metadata, ...", the Fedi post having the bullet point "- "zero metadata" messaging", the reply saying "this release goes all the way". Those are all incorrect, and the blog post text saying "close to zero metadata" sours the great achievement by introducing the shady vibe that asterisks and tiny texts in advertising gives.The achievement of having removed so much metadata is great on its own, and I think misrepresenting it cheapens it and leaves a bad taste.
(DIR) Post #B4qZGEXOHF17wNvrhQ by delta@chaos.social
0 likes, 0 repeats
@kbruen @dexternemrod @zaire in hindsight, maybe "zero metadata messages" would have been the more proper framing. Apart from the maybe too catchy tag the text goes into quite some details what "zero metadata" messages are about. We highlight in the "Telegram" section that while we are discussing about nitty gritty details of cryptographic terminology, they lure >1 billion users into thinking Telegram is secure ....
(DIR) Post #B4qhDW0ZfFFEtDnVfk by pancake@infosec.exchange
0 likes, 0 repeats
@delta i've lost all my accounts and settings after updating in macos. it's fine because i had second device in a phone to transfer that back. but yeah that was scary
(DIR) Post #B4qqadWulRuoSv1Zey by adam_jurkiewicz@linux.social
0 likes, 0 repeats
@delta great!
(DIR) Post #B4swiNMFlNTSfP1zCy by seismic_elm@puntarella.party
0 likes, 0 repeats
@deltaAwesome changelog! What is the usual timing between github release and fdroid packaging? I've checked and it's still 2.47 there (waiting the fdroid release to nudge my contacts to upgrade).
(DIR) Post #B4syTR51qFYfm8yiA4 by delta@chaos.social
0 likes, 0 repeats
@seismic_elm 2.48 appears to be available now on the f-droid app on android?
(DIR) Post #B4tMQydf0sFdt2XNk8 by seismic_elm@puntarella.party
0 likes, 0 repeats
@deltaYeah something weird happened. I updated the app but fdroid was showing me that the update was to 2.47. Apparently it was 2.48. Oh well, fdroid mysteries. Now it shows that 2.48 is installed :blobcoffee:
(DIR) Post #B4u7v0u9qdZzRq4uyO by Pug@masto.ai
0 likes, 0 repeats
@delta - How about that F-Droid release?
(DIR) Post #B4uaVcGRDneWSQk2Hg by delta@chaos.social
0 likes, 0 repeats
@Pug f-droid offers 2.48.0 since yesterday. maybe the index inside the f-droid app needs a refresh if you do not see the update
(DIR) Post #B6ILj50irfmrexuFu4 by hidikem@piaille.fr
0 likes, 0 repeats
@delta There is two thing i still find annoying, it's the fact we still cannot hide the "menu" toolbar on desktop version (linux).And a quite "difficult" documentation for hosting a relay, i hosted many service over the years, but the documentation of delta relay made me scratch my head, and where i had to reread multiple time the doc (it touch of smtp etc so it's "logic" but having an easier documentation would be welcome for this purpose š