Cross-posted from : https://lemmy.ml/post/16566616

Hi, I wanna know what is the most secure and best messaging app/platform… Need an app that is crossplatform and has a very good numbers of features and security. (And it has to be FLOSS) I thought about XMPP clients, Signal, Session, IRC clients… Propose and explain me your choice

1 point
*

Email, probably. Kind of depends on your needs, and how willing other people are to accommodate them. The most secure messaging platform is email with a third party IMAP client using OpenPGP. That way the client and the server are run by different people, and the encryption is based on a verifiable and well known standard. But will other people use that to communicate with you? Probably not. So probably something like Signal would strike a good balance between privacy and ease of use.

permalink
report
reply
5 points

I strongly disagree, email is a train wreck for secure communication.

Proton has done a pretty good job of making an implementation that’s actually secure but PGP email has fundamental flaws like the subject line and recipient being clear text on the message, user error/key management complexity, and it’s also just a high-friction means of communication vs “texting” or “IRC”-like approaches.

permalink
report
parent
reply
0 points
*

They asked what the most secure one is, not the most practical. When I said other people wouldn’t communicate with you, I meant because it is very difficult to set up, so I wouldn’t recommend it for anyone. But unless your client and server come from different parties, you’re putting all your trust into one other party (like with Signal), so that’s inherently less secure.

permalink
report
parent
reply
16 points

Where your friends are?

permalink
report
reply
2 points
*
Removed by mod
permalink
report
parent
reply
3 points

We should be glad that WhatsApp with E2EE is what people jumped to, instead of Facebook Messenger

WhatsApp is part of Facebook. You really think they operate differently?

permalink
report
parent
reply
1 point
*
Removed by mod
permalink
report
parent
reply
15 points

Yup. Reality. No point using a hyper secure chat system if literally nobody you know is using it.

permalink
report
parent
reply
7 points
*

My friends knew I was using it. I said why with very simple words, focused on freedom and abuse over side effects, privacy and security, and they joined. I guess having friends who actually respect you helps a lot.

permalink
report
parent
reply
5 points

You’re one of the few lucky ones.

permalink
report
parent
reply
1 point

Use Matrix bridge Everything else 🙂

permalink
report
parent
reply
3 points

That’s sadly where it’s at. I’ve been lucky and managed to convince most of my friends to give Signal a go and in the end we stuck with it. But we’re all technically minded people so YMMV.

permalink
report
parent
reply
2 points
*

The other day I found this, using an very old inbuild command line tool in Windows, Mac and Unix: finger

https://happynetbox.com

Write for Example

finger zerush@happynetbox.com

in the command line

permalink
report
reply
2 points

Do you finger your friends?

permalink
report
parent
reply
2 points

Not until now, I discovered it only some days ago. I think it’s an interesting methode to send Messages ocassionaly, but not so practically in the daily use.

permalink
report
parent
reply
4 points

Delta Chat is quite good, it’s an email client thats built like a messenger app. It’s E2EE with Autocrypt lvl 1, you can use it with most email services, and they have a self hostable/hosted “chatmail” service that you can also use if regular email services are slowing down the messages (gmail isn’t the best for this). It also supports apps and games in chat using the webXDC standard.

permalink
report
reply
1 point

Webxdc is pretty neat. Cheogram & Monocles clients also support it on Android.

permalink
report
parent
reply
5 points
*

I’d go with Signal or Threema

Signal: Best data protection. They are on a different level from anyone else. They even reimplemented gif search through their app so it can be anonymised (instead of the data-collecting gif search in your keyboard). Just an example, they really try. Also has a desktop app that doesn’t need the mobile app to be running. Downsides are google dependency (for push notifications - but they’re empty, the encrypted data does never even touch google) and required linking to phone numbers. They do have usernames now so you don’t have to give out your phone number to talk to someone. Behind it is an US based non profit - whether that is a downside everyone can decide for themselves.

Threema: No need for phone number, not even a credit card, you can buy it anonymously through their website. No google services required. Swiss based company, so much better laws than USA. Finance themselves through the one time fee of 2 USD and through their corporate offers, no nags for donations, no selling of data. Downsides are server code is not open source, and their protocol is less good than Signals, but still reasonably secure. They’re working on a new one though. Also no independent desktop app yet (also working on it).

permalink
report
reply
3 points

Would maybe choose Signal for its simplicity but I do not would like to use threema, it is a bit too related to his company, rather prefer simplex as example

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 6.8K

    Monthly active users

  • 3.6K

    Posts

  • 96K

    Comments