Hi, I wanna know what is the most secure and best messaging app/platform… Need an app that is crossplatform and has a very good numbers of features and security. (And it has to be FLOSS) I thought about XMPP clients, Signal, Session, IRC clients… Propose and explain me your choice

  • yogsototh@programming.dev
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    27 days ago

    matrix with element as client.

    If you really care about privacy you can hist a matrix server without much resources needed.

  • Lung@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    28 days ago

    It’s basically just Signal if you want ease of use + good security. Not totally 100% since it is funded almost exclusively by the US govt, and I can’t be sure if the encryption is not backdoored, but it’s the best bet we got. IRC: not secure, XMPP / Matrix maybe ok but hard to use for most, Telegram wouldn’t really trust though in theory has e2e, Whatsapp and Google world stuff even less faith. Honestly none of it is super great, but Signal has the best balance imo. There’s also some crypto based messaging stuff that’s used on darknets but that’s the clunkiest

    I think the only fully guaranteed method is having a pre shared one time pad encryption key between two parties & then send the encrypted text however you want (ex post on a far corner of a mostly dead online forum or Reddit). That doesn’t have any fancy algos that may be bugged, or private/public key stuff

    • RayJW@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      11
      ·
      28 days ago

      I think we can be pretty damn sure that the encryption is not backdoored since the Signal Protocol is the gold standard in encryption nowadays and thousands if not more highly skilled cryptographers without tied to the US govt looked at it thoroughly. Also Snowden calls Signal the best messenger on the grounds on him using it daily and still being alive so that’s also a pretty good sign.

      Also, do you have a source about them being mainly funded by the US govt? In their blog they talked about mainly being funded by small donors and a few initial loans from people who care about privacy.

      • Lung@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        2
        ·
        28 days ago

        Ok, my bad, it’s not mostly funded now (though funding isn’t totally clear for all of its history) but we do know it was handed 3m near the start by Open Technology Fund which an arm of the US Agency for Global Media which is the US govt, and at best has the mission of pushing us news ideology globally. Ex they did Radio Free Asia after tianamen square, and guess what, that was conceptualized by none other than senator Joe Biden

        Yeah the encryption is probably okay, and I use it daily, but these backdoors are often hella sneaky and we know that the US govt loves doing shit like that if they can

  • Eyedust@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    28 days ago

    I ran into one called SimpleX recently. No accounts or anything and you can host your own chat instance. Downside: The app either needs a constant spot in your notifications or will otherwise only check for messages every ten minutes.

    The desktop app is pretty rough to use, as well.

  • the_doktor@lemmy.zip
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    27 days ago

    Any message application that requires that you first sign in on a phone is garbage.

  • aa1@lemm.ee
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    28 days ago

    I think this question has some sort of relativity. What is your threat model ? Are you trying to protect your data from the service itself, fromyour mom, from the police ? You want anonimity ? And so on.

    There is no an ultimate answer to this question. For example, i’m using WhatsApp because it fits my threat model (messages are encrypted, metadata is not but for me is fine). Then, i use Signal with people that use Signal (where i live, 99% of people use WhatsApp).

    I would never use Telegram since is not encrypted by default.