I currently use Telegram for my friends and family, but have reluctantly come to the conclusion that the UK Government is either reaching agreement for backdoors with messaging services, or is trying its hardest to.

I’m also on Element/Matrix. Before I try to get my contacts to join me on there, should I be aware of any privacy issues or is that a good place to head?

  • Ulrich@feddit.org
    link
    fedilink
    English
    arrow-up
    29
    arrow-down
    1
    ·
    6 hours ago

    The biggest issue with Matrix is that the server collects ALL the metadata. If that’s your server, that’s fine. If thats the default matrix.org server that almost everyone uses, you might as well be using WhatsApp. Same thing goes if any of those people are conversing with people on your server, as they will store all redundant metadata on their server as well.

    Signal is easier to use, more private, and faster.

    • fangleone2526@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      5 hours ago

      Signal requires a phone number on setup.

      Also, matrix has bridges, which alone make it worthwhile for me. They, of course, don’t help privacy, but they are so so nice for convenience.

      Matrix is definitely slow though, and a grand majority of the clients are heavy terrible buggy electron apps. There are a few good ones ( nheko and the new beeper clients ), but even they have some rough edges.

      I still use matrix all the time and love it.

      If max privacy was the goal I think simplex looks wonderful. No required info for sign up, no way for them to possibly collect any metadata ( because there are no identifiers sent over internet for anyone at all ), E2EE, and decentralized.

      • Ulrich@feddit.org
        link
        fedilink
        English
        arrow-up
        9
        ·
        edit-2
        5 hours ago

        Signal requires a phone number on setup.

        It is dumb and annoying and inconvenient but doesn’t affect its use or privacy.

        I do agree that SimpleX seems like the best chat option.

          • Ulrich@feddit.org
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 hour ago

            How do you even exist without a phone number. How do you get cellular data? Does the government not require you to have one? Your employer? What about all the services that require one?

            • fangleone2526@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              27 minutes ago

              To be clear, I have a phone number, but I do not WANT to have one. Most aspects of my life I have removed my phone number from. There are still a few services ( like signal! ) which requires one, and I cope. Cellular data is also something worth avoiding, from a privacy perspective. It is very possible to live a life where you’re never very far from wifi, especially in a city. I do not currently do this, but would love to one day.

          • Telorand@reddthat.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 hours ago

            I have to wonder if you could use a burner number and just disable it after setting up your username

            • mipadaitu@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              1 hour ago

              I think you’d have a theoretical issue if the next person who got that number also tried to set up a signal account.

              • Telorand@reddthat.com
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                31 minutes ago

                You might be right. I’ll have to go double check, but I don’t think that you can just set up a new account with the same number without the password you set up.

                I might be wrong, though.

      • mac@lemm.ee
        link
        fedilink
        English
        arrow-up
        7
        ·
        5 hours ago

        Sure but it allows VOIP numbers. I’m using a jmp.chat number with it just fine.

          • mac@lemm.ee
            link
            fedilink
            English
            arrow-up
            3
            ·
            3 hours ago

            I got an initial verification code and haven’t heard from signal since. Signal doesn’t support totp or SMS 2fa. But has a pin code set along with your password. A new device that is added doesn’t have access to old messages unless you have the correct seed key iirc

        • fangleone2526@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          3 hours ago

          You can choose to share a username instead of a phone number, but they still require the phone number at setup iirc.

          • Optional@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            3 hours ago

            You’re right. Only for setup though, which is something I guess.

            How to Use Signal WhatsApp Without Phone Number?

            As mentioned above, a valid phone number that can receive calls and text messages is required to create and verify your Signal Account.

            Since, your mobile device does not have a phone number or you do not want to use your phone number, you can use a Landline Phone Number or a Virtual Phone Number as provided by TextNow, Google Voice and others to verify your Signal Account.

            Once the account verification process is completed, you will be able to use Signal on your mobile device, regardless of whether or not it has a phone number or SIM card installed on it.

    • mox@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      3
      ·
      edit-2
      3 hours ago

      Signal is easier to use, more private, and faster.

      Unfortunately, it’s also effectively tied to Google services due to the app distribution and push notification channels used by most people on it, and (as a centralised service) is vulnerable to shutdown or network-level metadata monitoring by anyone with sufficient access at the organisation or data center, such as a government who doesn’t like encrypted messaging.

        • mac@lemm.ee
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 hours ago

          Yep, I run my own mollysocket + ntfy server.

          Essentially, molly socket functions as another device, when it recieves a notif, it pings your specified unified push server, which then queues up a notification for the ntfy app on your device.

          You don’t need to run your own unified push server, and can just use one of the main ones, but I figured I might as well.

          I personally have them hosted on fly.io for free via the legacy hobby plan.

          Now all I need to do is get more of my friends to message me on it 🤣