Dude for the first 15s I thought this is porn
Privacy
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
its the sauna
Why is this interview happening inside a sauna?
She likes putting guests on the hot seat.
If you watch the video - its explained starting at 1:13, Moxie built it himself: https://www.youtube.com/watch?v=cPRi7mAGp7I
Right? If they're just chatting this should be happening in a jacuzzi with nice glasses of milk 🍼 👍
Why not? I thought it was een interesting choice ;-P
Why is this interview happening inside a sauna?
It's his personal sauna. He built it himself.
Why did he invite the hot reporter chick to his sauna? would be the follow-up question...
You answered yourself.
It's also important to continue educating people about the fact that Signal is incredibly problematic as well, but not in the way most people think.
The issue with Signal is that your phone number is metadata. And people who think metadata is "just" data or that cross-referencing is some kind of sci-fi nonsense, are fundamentally misunderstanding how modern surveillance works.
By requiring phone numbers, Signal, despite its good encryption, inherently builds a social graph. The server operators, or anyone who gets that data, can see a map of who is talking to whom. The content is secure, but the connections are not.
Being able to map out who talks to whom is incredibly valuable. A three-letter agency can take the map of connections and overlay it with all the other data they vacuum up from other sources, such as location data, purchase histories, social media activity. If you become a "person of interest" for any reason, they instantly have your entire social circle mapped out.
Worse, the act of seeking out encrypted communication is itself a red flag. It's a perfect filter: "Show me everyone paranoid enough to use crypto." You're basically raising your hand.
So, in a twisted way, Signal being a tool for private conversations, makes it a perfect machine for mapping associations and identifying targets. The fact that Signal is operated centrally with the server located in the US, and it's being developed by people with connections to US intelligence while being constantly pushed as the best solution for private communication should give everyone a pause.
The kicker is that thanks to gag orders, companies are legally forbidden from telling you if the feds come knocking for this data. So even if Signal's intentions are pure, we'd never know how the data it collects is being used. The potential for abuse is baked right into the phone-number requirement.
Apparently they don't store contact info.
https://signal.org/blog/looking-back-as-the-world-moves-forward/
The problem is that you just have to trust them because only people who actually operate the server know what they do or do not store. Trust me bro, is not a viable security model. As a rule, you have to assume that any info an app collects, such as your phone number, can now be used in adversarial fashion against you.
Best alternative?
It really depends on your needs and what people you communicate with are willing to use. A few platforms that are notable in no particular order.
SimpleX Chat is probably the gold standard right now. It uses absolutely no user IDs such as phone numbers, no usernames, no random strings of text. Instead, it creates unique, pairwise decentralized message queues for every single contact you have. Because there is no global identity, there is no metadata connecting your conversations together.
Session is a popular Signal alternative. It doesn't require a phone number and routes your messages through an onion-routed decentralized network that's similar to Tor. Since your IP address is hidden and messages are bounced through multiple nodes, no single server ever knows who is talking to whom, stripping away metadata.
Jami is completely decentralized, open-source platform. It uses Distributed Hash Tables to connect users directly to one another without a central server. Notably, it supports high-quality voice and video calls.
I really want simplexchat to evolve and get more features. If they ever make a lot of mod tools and the possibility to make giant servers with thousands with chatrooms like discord I could see it having mass appeal due to the ease of "signup"
yeah it definitely has some promise
heard SimpleX is really good, the only thing that bothers me is their vc funding model. It makes me feel a bit suspicious.
Yeah, I'm leery about anything where vcs are involved as well for obvious reasons. The tech itself does seem solid though, and it is open source. If it does start moving in a sketchy direction at least it could be forked at that point.
Probably Briar. Encrypted, P2P, and doesn't require anything but a username and password to sign up. Pretty sure that username doesn't need to be unique, it's just what people will see you as in messages.
Downside is it's only Android, so many people are left out.
If the username doesn't have to be unique, couldn't you impersonate people?
sadly Briar has been stuck at the "cool idea" stage for years. Still no desktop app, still no iPhone app.
Still working android app.
Remember how Telegram said they would stop providing Chinese authorities with user data during the Hong Kong protests. Implying that they were doing it at some stage.
Also remember how the FBI have said in several leaked documents they hate signal because the only data they get is when the user signed up and the last time they were online, nothing else.
Which app would you rather use?
Random mention of Matrix because I feel i should
Nothing federated is private, mind. Even with E2EE on in private rooms for specific messages, Matrix still relies on a constant information feed during use that can be used to deduce who is messaging whom and when, even if the content of the message itself is encrypted.
I've been saying this for years. Telegram is a social media app.
And WhatsApp is worse. It fails to include a libre software license text file. We do not control it. It is never secure.
It fails to include a libre software license text file.
I don't think this really makes sense as the leading point. More like "It's run by Meta and who knows what kind of backdoor they put in"
Yeah, it uses the signal protocol, but who's to say they don't have a secret member of every conversation.
Are they in a sauna?
Pretty sure signal is not the best option, but telegram should be avoided at all costs.