Anyone else wondering?

10 points

Matrix is the federated alternative to Signal.

However it would be cool to see Signal implementing their encryption into Matrix and turning Signal into a Matrix provider, becoming a federated messanger.

permalink
report
reply
8 points

I believe Matrix already supports olm which is the same encryption technique used by Signal. The main issue with Signal becoming federated is that in order to make the federation work, a lot of metadata will leak and that could be a cause for concern when using Signal as a private messenger for important things like whistleblowing, etc.

permalink
report
parent
reply
1 point

True

permalink
report
parent
reply
1 point
*

Thank you, I’ll probably keep Signal away from it, but WhatsApp and SMS hoover up my metadata anyway, so nothing to lose there.

permalink
report
reply
2 points

All of the people recommending matrix don’t understand why signal is secure. Matrix offers the same level of end to end encryption as Facebook Messenger, but it’s federated so people who care more about federation than privacy like to misrepresent its safety

permalink
report
reply
1 point

Matrix offers the same level of end to end encryption as Facebook Messenger

Can you please explain that in a bit more detail, for those of us who use these systems but aren’t up on the architecture?

permalink
report
parent
reply
2 points

Facebook Messenger offers optional end to end encryption just like Matrix. Just like Matrix, the server knows who you’re talking to, what groups your in, who else is in those groups, how many messages you sent to which group, who’s messages you react to, etc. But the actual text of the message is technically encrypted so Facebook can’t respond to subpoenas for your messages. I use Facebook Messenger as an example because Facebook is (correctly) generally considered not private or safe.

permalink
report
parent
reply
2 points

I will admit I don’t understand why Signal would be more secure than Matrix. I understood Signal to have E2EE just like Matrix.

permalink
report
parent
reply
1 point
*

That’s fair! If you’re on these type of forums, there are a lot of Signal haters and a lot of Matrix lovers, and sometimes they like to make confusing or just straight up inaccurate statements. The crux of the issue is not about the encryption of the text of messages themselves, which both platforms are capable of doing. Personally, I wish there was something like Signal but without the centralization, but the reality is such a thing doesn’t exist.

Signal (as in the Signal server and by extension the legal entity behind Signal) does not know what groups you’re in, does not know who’s in your contact list, does not know which groups you are sending messages to, doesn’t know which groups exist, and can’t tell the difference between a message, a reaction, a read receipt, a remote delete (“delete for everyone”), an edit… etc. Signal doesn’t have a way to send anything between two parties that the server can see. Signal has received a number of subpoenas which they typically fight, and if/when they lose they over all of the information they have about the subject of the subpoena, which tends to be whether or not they have a Signal account, when they registered the account and when they last used it. You can see these at https://signal.org/bigbrother/

Matrix (as in the Matrix server you’re registered on as well as the servers of whoever you’re talking to, for groups that means everyone in the group, notably this is not necessarily the same as the legal entity behind Matrix, but in practice a LOT of people use matrix.org for their home server so it frequently is) can see basically all of the things I listed above. The text of normal messages is encrypted. The group membership list isn’t encrypted. reactions aren’t encrypted. read receipts aren’t encrypted. Group membership lists are stored in plain text.

permalink
report
parent
reply
0 points
*
Deleted by creator
permalink
report
parent
reply
1 point

“theoretically” being the operative word here. Most people don’t. And if they did, they wouldn’t be able to talk to anyone else without the metadata getting copied to that person’s server. Probably okay if it’s between two information security experts who operate their secure own servers, but in reality most people don’t do that. This could be summarized as: Matrix offers a lot of easy ways to be less secure, Signal does not.

As for WhatsApp, I know they have paid or maybe still do pay Signal for their encryption. I believe Facebook Messenger did or does as well. I’m not sure what the actual implementation looks like and neither is anyone else, because it’s closed source.

permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply

Given everyone’s advice, I’ll look into matrix

permalink
report
reply
12 points

Not a fan of giving my phone number to federate to every server.

Session is like Signal but decentralised (like Tor, not like Fedi) and without the phone no requirement. That sounds better to me.

permalink
report
reply
1 point

Can you link the project you mean? Cant find “session”

permalink
report
parent
reply
1 point
2 points

Appreciate the heads up on session.

permalink
report
parent
reply
3 points

https://www.securemessagingapps.com/

Session doesn’t have perfect forward secrecy. Session also depends on the oxen Blockchain not collapsing.

Session has its uses, just be aware.

permalink
report
parent
reply
5 points

Maybe, but if I want to privately talk to randos from the internet, then using my phone number like with Signal is a no-go from the start. Threema is paid and only partially open source.

Session is fully decentralised and while you can think of crypto whatever, at least it gives people the incentive to run nodes, unlike Tor where the incentives are all over the place, or centralised messengers which are fully reliant on one entity.

permalink
report
parent
reply

Fediverse

!fediverse@lemmy.world

Create post

A community to talk about the Fediverse and all it’s related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

  • Posts must be on topic.
  • Be respectful of others.
  • Cite the sources used for graphs and other statistics.
  • Follow the general Lemmy.world rules.

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy

Community stats

  • 5.2K

    Monthly active users

  • 1.9K

    Posts

  • 65K

    Comments