Avatar

andylicious1337

andylicious1337@lemmy.world
Joined
8 posts • 45 comments
Direct message

ok but if I’d recommend a client to the people I want to text with via xmpp I can be certain which client they use. My idea isnt to write with strangers but only with real people I know (friends and family).

permalink
report
parent
reply

I am asking because I want to understand the “hype” about XMPP that and why it is always mentioned when someone is asking for a good privacy friendly messenger :)

permalink
report
parent
reply

I would love to do the same (although not the hardcore step with arch :D) but how would I game and also isn’t the support for drivers sometimes really iffy?

permalink
report
reply

that is only done once at the creation of an account and does not proof that the number ist not saved hashed.

permalink
report
parent
reply

ah ok. that makes sence. so only if the secure channel of the key exchange is somrhow attacked, the encryption can be broken, correct? i dont wanna ever use telegram (not even on 1-1 e2ee chat) but basically they are still bad since they use encryption wich is not a standard and could be compromised?

(i hope thats it with all the question i have 🙈)

permalink
report
parent
reply

ok but if the source of the server is not know, how can the client be save?

I know how e2ee works but couldn’t a bad closed-source server still be a problem?

btw. not trying to call you out, I just really want to know, cuz I cant get my head around it 🙈🙊

permalink
report
parent
reply

but if this is your argument, you could also say that Telegram is good because their client can also be built from their open source. of course you have to activate e2ee on a 1-1 chat first…

permalink
report
parent
reply

good points altough the number is note saved. the hash of the phonenumber is hashed so Signal could not hand out your number, just the hash.

permalink
report
parent
reply

that’s why I love great communities like this one here. you aks one think, maybe totally overthinking and read an answer like this, which helps you realize the overthinking :)

thanks for that. what you say makes sence. I really NEED to make a threat-model to find out, what is worth keeping private and what isn’t worth the trouble.

Thank you :)

permalink
report
parent
reply

oh ok, I have not tried that yet. I have only set up one address which I use yo send and receive from.

about the encryption: I thought the point with e2ee encryption on proton is mainly, that the mails are stored encrypted one their servers so they can not read them or hand them out to anyone.

permalink
report
parent
reply