Tbf, can’t the other party mess it up with signal too? I have a friend with a Samsung running stock samsung android, bloatware and all; how can I trust there’s no google or samsung keylogger, which I’m pretty sure at least one of those companies installs? With copilot existing now, how can I be sure that, when that makes it’s way to stock android, it won’t capture the signal convo? The man uses windows, how can I be sure he won’t surrender our chats to current copilot?
If you need nation-state level secrecy, rule #1 is don’t associate with idiots who can’t be bothered with at least the most basic opsec. I shouldn’t talk to this motherfucker at all were that my case, or at least not digitally. Thankfully at worst we talk about me middlemanning him some weed, and even local PD dgaf.
My main issue for signal is (mostly iPhone users) download it “just for protests” (ffs) and then delete it, but don’t relinquish their acct, so when I text them using signal it dies in limbo as they either deleted the app or never check it and don’t allow notifs. Now maybe somehow with the removal of SMS maybe that is fixed, but also removing SMS took my biggest selling point to “normals,” so, fuck me.
mistermodal@lemmy.ml 5 months ago
Never cared for the way this fellow tries to argue that everything is too difficult to be useful. I’ve gotten plenty of friends and family on XMPP and the clients that don’t have encryption on by default are easy to remember. Really blowing it out of proportion.
Honestly, what do security researchers like this even know about normal people? They sit through all kinds of inconveniences to use Facebook. This is a thought experiment.
Some of these are valid criticisms, of course, a lot of XMPP stuff feels like it from the 2010s. It’s still the only real option. Matrix client or server is bloated garbage, theu moved server fixes into a walled garden, its development is dependent on funding from the USA National Endowment for Democracy technology fund. Signal has similar funding issues and is very shady with its centralization, trust issues, demanding phone numbers. Sets users up to leak all kinds of stuff in notifications like Matrix.
The strange insistence that only Signal meets their requirements makes me skeptical, as does the way they have operated in Github threads. They seem like an emotional nightmare to work with.