Meta … can’t guarantee “what a third-party provider does with sent or received messages.”
I’m more concerned with what the first-party provider is doing with my sent or received messages when that first-party is Facebook!
Meta … can’t guarantee “what a third-party provider does with sent or received messages.”
We (Meta) can guarantee that we do all the bad stuffs to your data!
I dislike when they say in news clips that Signal represents the “current gold standard” for E2EE chats, it doesn’t, Signal is a helluva lot better than the commercial stuff that mines user data but there’s stuff like SimpleX Chat that doesn’t leak even metadata because it doesn’t have it.
Still, this is a good thing, these megacorps have their iron grip on people because they have raised walls around their services making it painful for people to move to a different service, tearing down those walls can only help us all.
A standard is also about broad adoption though, so I don’t think you can call SimpleX a standard yet.
Thanks for the tip about SimpleX, that looks interesting! I could never use Signal due to the way they operate and force you to rely on their and Google’s servers, actively blocking forks from their network. So much for FOSS…
They do provide an apk outside of the Play Store, that uses a Web Socket for push notifications. Not he best way of going about it, but hey, it exists.
SimpleX is very neat. But it cannot do multiple devices unless you count shutting down, exporting database to new device replacing existing database as a sensible workflow. Using the database on two devices at once will break encryption and cause all sorts of weird problems.
The standard is about the protocol, not every bit of the implementation. 3DH / X3DH and double ratchet, etc, are among the best for E2EE.
It appears SimpleX is not even available for me (Android 8).
@jherazob @Mysteriarch Though great with some worthy competition for Signal!
Signal encryption can be taken out of the app and applied elsewhere, because it has been already done. SimpleX is nice but this is single app single implementation thing.
Would this mean I could finally ditch what’s app and use only Signal?
No, Signal announced they won’t implement interoperable messaging.
kind of dumb they could get huge market share
Yeah, this worked so well for XMPP when everybody federated with Gmail chat.
Well, it worked out for Google when it federated with Jabber, who first open sourced XMPP.
It’s not. There is no privacy if you send your message to Whatsapp servers.
There’s even less privacy if I have to have the WhatsApp app installed on my phone to send that message.
You have the big plus of not having the WhatsApp app installed and snooping around with all those permissions it has.
Would it not be E2EE? Isn’t that one of the reasons for using the Signal protocol?
Yes, the “delivering” part would be E2EE. Do we really know the afterwards if they can read their users’ messages? They probably can.
Whatsapp CANNOT read messages when e2ee is enabled, this client-side snooping was discussed when the protocol was first implemented. Whatsapp collects a ton of metadata and social graph info, but not message content.
Well you type messages in in plain text and they decrypt it to show you the messages at the other end. So they can do the nefarious processing on the client side and send back results to the mother ship. E2EE is only good when you trust the two ends, but with WhatsApp and Messenger you shouldn’t trust the ends.
Sure, but any messaging app (including Signal) could have these backdoors in place. Heck, there’s even vectors for unrelated apps on your phone to read this data once unencrypted.
Signal clients are open-source.
That’s actually true. We don’t know the real-time server code of Signal. Though other apps cannot read what’s written inside Signal, that’s the good part. I prefer private server + Matrix but Signal is the easiest for regular people.
if i remember correctly, it would be E2EE (WhatsApp and Messenger are too) but Meta stores the encrypted message on their server
Signal does not care about “market share”, they’re a non-profit.
Them being nonprofit has nothing to do with the pursuit of marketshare. Plenty of nonprofits want to maximize marketshare. Them being nonprofit means they are mission-driven.
And what is that mission?
Per the Signal Foundation’s website:
Protect free expression and enable secure global communication through open source privacy technology.
Them being nonprofit has nothing to do with the pursuit of marketshare.
Um, of course it does? LOL
Them being nonprofit means they are mission-driven.
And what is that mission?
Let’s talk about what the opposite of their mission is: Mainly operating as a source of data collection and revenue for a corporate surveillance and advertising agency.
Do they want more users? Sure. Are they going to compromise on their core principles out of convenience for their users? Abso-fuckin-lutely not.
There’s also the opposite to consider: that users would decide to use WhatsApp instead of Signal because they can, which then puts you in the uncomfortable position I find myself in often where I have to tell people I’m not accepting their messages from insecure platforms.
Source?
Ugh, an ad-block force wall. No visit.
Not if signal doesn’t want to support WhatsApp, and I don’t think they’re going to unfortunately :(
Does this mean third party apps will be able to interact with whatsapp?
only when the service specifically requests it and agrees to Whatsapp’s terms.
deleted by creator
So I [in theory, I don’t know how to start with this on a technical level] could make a third-party Signal-compatible app, but allow it to connect to Whatsapp instead of Signal? Even if I can’t use my Signal account to contact Whatsapp people, that’s still potentially useful. Although I imagine the terms I’d have to agree to to do so would be full of nonsense that stops this being remotely feasible.
could make a third-party Signal-compatible app, but allow it to connect to Whatsapp instead of Signal?
you’d have to create a messaging service, not just a client.
I guess I’m misunderstanding here - I thought Whatsapp would be the “service” in my case, I’m just making a client to hook into their, presumably open [to people who agree to whatever their terms are] API. So it’s more of a federation thing between services?
So it’s more of a federation thing between services?
yeah, I guess you could call it that.
Removed by mod
Last time they touched an open chat protocol, they hung it out to dry. That was XMPP. That’s why more than half of the fediverse is reluctant or outright hostile to federate with anything meta.
maybe they could convince meta to use it
I think he/she meant convincing Meta to use MLS, not Matrix.
Now that I read it again, you may be right.
XMPP is used in many, many places. It’s just not usually explicitly known that the backend is using that protocol
You are underplaying the damage Google and FB did to XMPP. It wasn’t supposed to be relegated to an obscure backend protocol. The involvement of those companies ensured that it didn’t become a popular user-facing protocol.
What is the advantage of this over olm/megolm?
Removed by mod
Is there a reason this requirement doesn’t apply to iMessage as well?
I’ve read somewhere that iMessage wasn’t considered “big enough” to be considerate a monopoly. Which is bullshit if you ask me.
To be fair here in Europe I know no one who uses iMessage.
Kinda true in Europe though. Don’t know anyone who uses iMessage, it’s pretty much irrelevant. I know the situation in the US is quite different, but ultimately they don’t regulate for the US market.
It’s very popular here in 'merica, the land of the zombies.
Its only big in the US, most of the planet only sees iMessage as that borderline useless app Apple bundles in their phones.
It’s annoying as fuck when I message my wife a video of our kids, it looks like dog shit on her iPhone. I have to instead send it on Whatsapp or signal. I hate apple
That’s because you’re using SMS, that’s not the fault of the messaging app. Using a third party messaging app is the correct way to go, it’s encrypted, supports group chats, and bigger messages.
deleted by creator
Hopefully not RCS, but maybe Matrix or the Signal protocol, as RCS is entirely controlled by Google and there aren’t any FOSS clients.
deleted by creator
Oh I’m well aware of that, I’m just complaining 😂
@aberrate_junior_beatnik @penquin I found a nice page with statistics about the different messengers: engage.sinch.com/blog/most-pop…
It seems that only in the US more people are using iMessage than WhatsApp.
Apple would still feel pressure to add interoperability if all other big players do. iMessage would have a competitive disadvantage if it’s the only one where users are unable to message the rest of the world.
Have you met Apple and their walled garden of “IDGAF”?
Yes. Still, it would be harder to not give a f if others walled gardens open up, and iMessage get disadvantaged by that wall.
It’s as if iPhones were only able to make calls to other iPhones. Whereas all other devices where able to make calls to any device from any other vendor.
It’s as if iPhones were only able to make calls to other iPhones
Don’t give them ideas!
@Mysteriarch I deeply hope that there will be some connection to Matrix in the future.
At least we know that this won’t be open federation. But still maybe some company could bridge them or at least could become a JMP.chat like service for WhatsApp.
Element wrote a first look summary on this: https://element.io/blog/the-eu-digital-markets-act-is-here/
Wake up Neo. Follow the white rabbit