Comment on End-to-End Encrypted Chat that YOU Control: Hosting XMPP (Jabber) with Prosody
ArcaneSlime@lemmy.dbzer0.com 2 days agoYes, but this is where threat modeling comes into play.
Right,:
If you need nation-state level secrecy, rule #1 is don’t associate with idiots who can’t be bothered with at least the most basic opsec. I shouldn’t talk to this motherfucker at all were that my case, or at least not digitally. Thankfully at worst we talk about me middlemanning him some weed, and even local PD dgaf.
Though btw speaking of:
Can the size or metadata
Plenty of people have been drone striked (struck?) simply because the metadata said they were talking to the wrong guy. Frankly if you need that high of a level of secrecy, you’d be better served using tails/tor, or hell even snail mail with false return addr and a book cipher. But for:
all ISPs, WiFi networks, CDNs, VPNs, script skiddies with Wireshark, and network admins in the path
Then frankly either signal or jabber+encryption (or for that matter, simplex, briar, yadda yadda) should be fine.
Signal also benefits from the network effect, because someone trying to get away from an abusive SO has plausible deniability if they download Signal on their phone (“all my friends are on Signal” or “the doctor said it’s more secure than email”)
But then again, it’s more likely to be known as an encrypted chat which may be a problem for them, while the abusive SO might just think XMPP is some outdated IM they know what signal is, and “my friends” can use jabber just the same as signal.
Alas, this is an issue with all messaging apps, if people delete the app without closing their account
Except not. XMPP not being tied to a phone number, if my buddy Steve deletes Conversations, while I may not be able to message him on jabber I can fall back on text. However (and again maybe now this is fixed), on signal if he deletes the app, I can no longer signal message him, nor can I SMS him because they get lost in limbo as signal messages, I’d have to email or use XMPP to get him to redownload signal, delete it properly, and THEN I can SMS him again. (Maybe no longer now that “no sms,” but also “no sms now but still give us your phone number” don’t sit right with me.)
semperverus@lemmy.world 16 hours ago
I dunno if you know this but SMS support got removed from Signal a few years ago
ArcaneSlime@lemmy.dbzer0.com 15 hours ago
I do, but idk how that effects that problem since I stopped using it due to that problem. Also, ironically, removing sms support killed a big selling point, and the fact that phone numbers are still required is pretty lame.