this post was submitted on 07 Feb 2025
378 points (99.0% liked)

Technology

61968 readers
3747 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

I currently use Telegram for my friends and family, but have reluctantly come to the conclusion that the UK Government is either reaching agreement for backdoors with messaging services, or is trying its hardest to.

I'm also on Element/Matrix. Before I try to get my contacts to join me on there, should I be aware of any privacy issues or is that a good place to head?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 52 points 1 day ago* (last edited 1 day ago) (17 children)

I currently use Telegram for my friends and family

Telegram is probably the worst thing you could use, it doesn't encrypt messages by default and they are stored on Telegram's servers, so they can read them at any time.

I'm also on Element/Matrix. Before I try to get my contacts to join me on there, should I be aware of any privacy issues

Yes, Matrix leaks a bunch of metadata and doesn't have post-quantum encryption.

The best option is to use Signal. It uses end-to-end encryption by default for everything: Normal chats, group chats, voice and video calls and even stories. Messages are only stored on their servers (in encrypted format, so they can't access them) until you receive them, after which they are promptly deleted and only stored on your device. And Signal has much better metadata protection than Matrix. The UX is also much better and less confusing, making onboarding new users much easier.

[–] cmhe 8 points 1 day ago (16 children)

But you should also be aware that Signal does not federate, so the company can be bought. They have control over all accounts and the servers, without easy way to migrate away again. So it might just be another trap.

Try to use federated services (like matrix), they are more robust against hostile take overs.

[–] [email protected] 9 points 1 day ago* (last edited 1 day ago) (6 children)

At least (to my knowledge) the Signal messages are decrypted on the client end, so buying the company doesn't give them automatic access to messages.

Having said that, I'm sure a hostile new owner could update the app to decrypt and then send the messages as plaintext to the servers if they wanted..

[–] cmhe 3 points 1 day ago (2 children)

Well, you can still insert client side decryption into the app.

But it isn't really about the messages, it is about the control of the servers and the accounts. You cannot easily move away from their servers, because you will lose your contacts. This gives the people controlling the servers power over you. A sort of vendor lockin.

[–] [email protected] 3 points 1 day ago (1 children)

In the 1990s US ISPs would "give you" an e-mail account with their service: [email protected]. Of course, this is insta-lockin for that e-mail address, you can never port it.

Owning your own domain name and running e-mail service through that worked, for a few years, but the big players have made whitelist / blacklist such a frustrating whack-a-mole game in the e-mail space that running your own e-mail server quickly became impractical.

[–] cmhe 2 points 16 hours ago (1 children)

There are different degrees of vendor lock in. If you use email (or Matrix) with a domain, you have no control over, you are soft-locked it. You can buy a domain, self-host or pay for a managed service and inform everyone that you are now reachable over some other address, but nobody else has to change.

If you use Signal (or Discord or whatever) and want to switch to a different domain. You cannot. If you switch to a different protocol, everyone in your contacts has to switch as well, or you lose that contact. The network effect forces you into the service of one provider. The only way out of there would be if the service get so bad, that a critical mass leaves, but you will have to deal with that bad service all the way.

As long as financial interest are there, non-federated services will sooner or later start to enshittyfy. So if you choose a communication medium, choose something that leaves your options open. If you don't like Matrix, try XMPP, it has come a long way as well.

[–] [email protected] 1 points 8 hours ago

This was outlined 50 years ago as part of Anarchist analysis of the system then. Not exactly an easy read, but "the second watershed" can be equated to "jumping the shark" or "enshittification" or whatever other term you want to apply to: a good thing gone bad due to the business owners switching from serving customers to enriching / empowering themselves:

https://archive.org/details/illich-conviviality/page/9/mode/1up

The alternative proposed by Illich to "Radical Monopolies" are "Convivial Tools" which empower individuals instead of central decision makers.

[–] [email protected] 3 points 1 day ago (1 children)

Well, you can still insert client side decryption into the app.

That's why all clients are fully open-source. You can also use a fork like Molly.

[–] cmhe 3 points 1 day ago* (last edited 1 day ago)

AFAIK, Signal does not want anyone to use alternative clients, has that changed?

As far as I know moxie, signals lead dev, considers only the use of the officially build and distributed client authorized to use their servers.

So if they ever manage to detect someone using their services with an alternative client, they might delete your account.

https://techcrunch.com/2016/11/07/signal-app-maker-rebuts-criticism-of-dev-direction-by-calling-for-more-community-help/

load more comments (3 replies)
load more comments (12 replies)
load more comments (12 replies)