“Signal is being blocked in Venezuela and Russia. The app is a popular choice for encrypted messaging and people trying to avoid government censorship, and the blocks appear to be part of a crackdown on internal dissent in both countries…”

You are viewing a single thread.
View all comments View context
22 points
*

Matrix is entirely self-hostable, and you can turn off both federation, and the requirements for any linkable identifiers.

Signal by contrast requires your phone number, isn’t self-hostable, and is based in a five-eyes country.

permalink
report
parent
reply
10 points

Matrix doesn’t protect metadata, which is arguably just as (if not more) important than message data. Signal by contrast does protect metadata and proper implements Perfect Forward Secrecy for all chats. I do think Signal’s centralized design and phone number requirements problematic, but Signal still has many merits. Such as its massive user base for a AGPL-only project.

permalink
report
parent
reply
7 points

Matrix also implements Perfect Forward Secrecy, and that’s been the case for a very long time: https://security.stackexchange.com/questions/162773/are-matrix-messages-encrypted-using-perfect-forward-secrecy

What do you mean by AGPL-only? Synapse is also AGPL. And you can only guarantee that there won’t be projects with other licenses if you prevent them from existing… which is not something to be desired

permalink
report
parent
reply
1 point
  • AGPL-only is a license, I didn’t want to misrepresent the license by being general. I was just trying to say that it is surprising that a fully open source application like signal has a large user base.
  • PFS isnt enabled by default for group chats and generally feels messy as the end user to deal with. I was unaware that they have properly implemented it for group chats as well.
  • My point about metadata still stands. Matrix still does not protect metadata (one eg: reactions to messages are in unencrypted).
permalink
report
parent
reply
3 points
*

for a AGPL-only project.

Citation needed. It is undisputed that the software that runs on their servers is not identical to the code they release; if they release at all because sometimes they just stop for a year, until people complain 🫠

permalink
report
parent
reply
-2 points
*
Deleted by creator
permalink
report
parent
reply
9 points
*

This is false. You still need a phone number to sign up and it is used as an internal identifier.

All they did is to allow you to hide your phone number from other users.

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 5.4K

    Monthly active users

  • 1.8K

    Posts

  • 27K

    Comments