• 1 Post
  • 65 Comments
Joined 2 months ago
cake
Cake day: June 30th, 2025

help-circle

  • I’m not really sure what you want to say with that. I always loved that comic although I always thought that my reason for wanting high security is not to be 100% protected from any thread. If you show up with a wrench I’m going to give you my btc seed before you even hit me. But I’ll know. If something has low security. It can happen without my consent and without me knowing







  • I did some quick googling and found this. I haven’t looked too much into it yet, but it doesn’t sound like such a bad reason on the surface, although I do suspect things should be better now

    From their website in the section titled “Privacy over convenience”


    One of the main considerations often ignored in security and privacy comparisons between messaging applications is multi-device access. For example, in Signal’s case, the Sesame protocol used to support multi-device access has the vulnerability that is explained in detail here:

    “We present an attack on the post-compromise security of the Signal messenger that allows to stealthily register a new device via the Sesame protocol. […] This new device can send and receive messages without raising any ‘Bad encrypted message’ errors. Our attack thus shows that the Signal messenger does not guarantee post-compromise security at all in the multi-device setting”.

    Solutions are possible, and even the quoted paper proposes improvements, but they are not implemented in any existing communication solutions. Unfortunately this results in most communication systems, even those in the privacy space, having compromised security in multi-device settings due to these limitations. That’s the reason we are not rushing a full multi-device support, and currently only provide the ability to use mobile app profiles via the desktop app, while they are on the same network.


  • What they have right now may not be in contradiction with what he said in the talk. Again,I haven’t seem it so this is a made up example

    Maybe because of the double ratchet encryption, every message had to follow a precise order. Of it doesn’t, everything breaks. Multi device with handoff is easy since only one can send and science messages. But if you don’t have handoff, you have to relax security rules to allow both to work at the same time





  • Right now signal is the best. I’ve basically tried them al and at least for me, the known good confidentiality of messages is worth the lack of anonymous accounts. All the other options have issues or have not been properly verified / audited.

    When simplex is ready, it will be the best by a lot. But right now you might randomly lose contacts and a few different





  • Right now when you establish a connection with someone, you exchange between 2 and 4 connections. Each person shares that receive servers out of which one of them is for, and the other is clear net. If you don’t have to running and one of the servers goes down, half of the messages no longer deliver. There is no server rotation. Even if you swap your servers ahead of the server shutting down, contacts don’t cycle and they are lost

    That is currently my biggest reason not to recommend. There are also UX improvements like live messages which I think are useless and will cause people to get confused (they are messages that the other person can see in real time as you type them). They should also include some soft of recommended backup solution because people WILL get mad about losing everything