in reply to Daniel Gultsch

I recently included XMPP in this post about Signal alternatives:

graphics.social/@metin/1138769…


Signal is a secure messenger, but there are interesting alternatives, such as @matrix , @session , @delta , @simplex or XMPP …

➡️ matrix.org

➡️ getsession.org

➡️ delta.chat

➡️ simplex.chat

➡️ xmpp.org

If you’d like to learn more about these options, have a look at the responses to this toot.

#matrix #session #signal #XMPP #messenger #decentralized #tech #technology #OpenSource #FOSS #WhatsApp #security #InfoSec #data #safety


This entry was edited (1 month ago)
in reply to Daniel Gultsch

the only part of XMPP I am nervous about is security. Signal's marketing is quite open in how the communication is secured and how they are improving it over time. For example they already use ML-KEM for key exchange? Algorithm that should withstand quantum computing. In XMPP we have years old OMEMO and no info about future extensions. And I really don't know where we stand. 🤷‍♂️
in reply to Daniel Gultsch

I'm sure your message is well-intentioned but this is a dangerous and misguided suggestion.

For now @signalapp remains the best option for accessible secure messaging. Right now - especially with the US government being completely rogue - we need secure, vetted, private means to communicate and organize.

When there is a company that provides Signal's guarantees based in the EU, I will gladly use it. Until then, Signal is your best bet for private communications with others.

in reply to Daniel Gultsch

Are you joking? XMPP is cool, but it's nowhere near to Signal in terms of security. Signal's security model is so tight that it does not really matter from which country main servers are provided, as it was proven to court Signal has minimal info about your metadata, let alone message contents. Please do not mislead people and talk shit about Signal.

And I hope you already have read this analysis
soatok.blog/2024/08/04/against…

Unknown parent

mastodon - Link to source

Štěpán Škorpil

@debacle wrench is cheaper now, but will it be cheaper in 5 years? Messages can be collected now and cracked later but data in those messages can still be relevant for the attacker then. Plus you have to add the new tech adoption speed, which seems especially slow in XMPP.
That's why ML-KEM was standardized now and that's why I am asking.