this post was submitted on 02 Feb 2025
72 points (90.9% liked)

Privacy

42745 readers
837 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
 

So, I was told to not use Signal, so all that is left is Matrix. And I am not techy enough to have my own server and neither are my relatives, so Matrix.org is the only option

top 50 comments
sorted by: hot top controversial new old
[–] devfuuu@lemmy.world 33 points 8 months ago (1 children)

For normal end user average usage signal is the best option available, specially for family since they may already be used to the flow and UX of it. Simple and straight forward. All the "bad" things you read are about nerds being annoying and not liking a very particular specific thing and thinking that specific thing should be the only focus.

So just make people use signal. It's the best and simplest way with the most common features for individuals and small groups. A simple download, in a common known place on a store without confusing people with differences between a protocol and a client and with and onboarding experience most are already familiar and ok using.

Even so you still need to make sure that the app does not have battery optimizations turned on, but that applies to all apps used for communication that are not blessed in specific phones (like facebook and whatsapp already having that setting by default because vendors make it so).

[–] lambda@programming.dev 18 points 8 months ago (1 children)

I have made so many people use Signal now. I sell it as, "I'm on Android. Signal gives us all of the features of iMessage and facetime" no need to mention the privacy concerns unless they are the kind of person who cares.

[–] autonomoususer@lemmy.world 4 points 8 months ago* (last edited 8 months ago)

Great for now. Much better than doomers here who do nothing but cope.

But this teaches nothing to protect them from new scams, new anti-libre software.

[–] nutbutter@discuss.tchncs.de 28 points 8 months ago (6 children)

Who told you to not use Signal, and what reasons did they give? I'm very curious.

[–] bruhsoulz@lemmy.ml 16 points 8 months ago (1 children)

It uses phone numbers and is centralized. I personally dont use it cus of those reasons. Also wouldnt switch cus my folk already use matrix so im nt making a bunch of people get another app lol

[–] toastal@lemmy.ml 4 points 8 months ago (1 children)

Matrix is centralized too in practice … & syncs even more metadata than Signal so I wouldn’t call that an upgrade—especially when you see how slow the clients & servers are.

[–] index@sh.itjust.works 4 points 8 months ago (1 children)

Matrix is centralized too in practice

There are plenty of different available homeservers and you can host yours.

[–] toastal@lemmy.ml 2 points 8 months ago* (last edited 8 months ago) (2 children)

It takes 2 to tango. It’s like trying to send an email from a self-hosted email server without following all of Google’s rules/guidelines… which means you won’t be able to send a message to most (sadly). Most folks are either on Matrix.org or a server they host in practice… you alone self-hosting will only help if you only communicate to folks also doing similar… to which if just one user from Matrix.org (or a server they host) joins your chatroom, then literally everything that is being & has been said in that room will now be synced to Matrix.org by its protocol design. With the expense it takes to self-host Matrix for a community, almost all medium-sized communities had to drop it on RAM & storage costs alone which caused most of those users to move to Matrix.org. You can run a single-user host with some efficiency, but most users are not technical enough for this. The only option to use Matrix & keep costs down is to unfederate… at least with Matrix.org (& servers they host), but that now defeats a huge part of the argument those saying Matrix is federated/decentralized.

It isn’t decentralized in clients or servers either. Almost all servers must run Synapse which is resource intensive but actually has the features folks expect as the de facto reference server & Element is the only viable client considering most users will be using Element-exclusive features like threading, polls, etc. where protocol hasn’t done a great job of providing a progressive enhancement approach to its features & so folks on alternative clients straight-up just don’t see / can’t interact with this stuff.

The accessibility to small–medium-sized communities matters if you want a healthy federated/decentralized network …but luckily there are alternatives.

load more comments (2 replies)
load more comments (5 replies)
[–] comfy@lemmy.ml 18 points 8 months ago

Private against who?

Privacy communities need to really drill in the idea of threat models instead of pretending privacy is some linear scale and the ultimate goal is to bury your phone and computer in a lead-lined concrete block underground. Privacy and security are meaningless concepts unless you know who your are protecting it from and what their capabilities might be. I don't need to hide from NSA Tailored Access Operations because I'm not trying to x the y of the USA. I do need to protect myself from basic scam attackers, copyright trolls and neo-nazi stalkers. And Matrix, along with certain basic opsec guidelines, does that and more for me.

[–] badcodecat@lemux.minnix.dev 16 points 8 months ago (2 children)

simplex is good as an alternative

[–] mox@lemmy.sdf.org 12 points 8 months ago* (last edited 8 months ago)

SimpleX has some interesting ideas, but also some shortcomings for people who want a practical messaging service. For example:

  • It is funded by venture capital, which calls into question its longevity, and even if it does manage to stick around, suggests that it will be leveraged to exploit people once the user base is large enough.
  • Its queue servers delete messages if they are not delivered within a certain time frame (21 days by default). Good luck if you take a vacation off-grid for a few weeks.
  • No multi-device support. (This means a single account accessed concurrently from multiple independent devices.) The closest it comes is locally tethering a mobile device to a computer.
  • Establishing new contacts requires sharing a large link or QR code, which is not always convenient.
  • No support for group calls.

I would not recommend it for talking to family members and people in general, which is what OP requested.

[–] toastal@lemmy.ml 3 points 8 months ago

It’s worth following the project but it’s a bit too new & the funding aspect leads me to question how it will work in the long run (& being written in Haskell is neat, but boy does it have a lot of churn & maintenance issues in its ecosystem).

[–] wreckingball4good@lemm.ee 13 points 8 months ago (1 children)

In signal, You can turn off phone number visibility and make it so that you are only searchable by username or qr code. Yes, it's centralized, but signal is a nonprofit project with generally good guiding ideals. I use matrix for some things and signal for everything else.

load more comments (1 replies)
[–] kevincox@lemmy.ml 11 points 8 months ago (1 children)

Probably yes, it depends on your threat model.

If you are using E2EE on a matrix.org account then your message content, attachments (images) and most other traffic isn't accessible to anyone but the people in the chat. However Matrix isn't the most private option, it has a number of leaks such as reactions and chat topics (these are being worked on but aren't close to happening).

For most people Matrix is a very private and secure option and the fact that it is federated is a huge plus. If you want something more secure you are probably looking at Signal (which you don't want to use and isn't federated) or Simplex Chat (which doesn't have multi-device support).

[–] refalo@programming.dev 3 points 8 months ago* (last edited 8 months ago) (2 children)

Unfortunately even with E2EE, the admins of a homeserver can still impersonate you or take over your channel.

Of course you could run your own instance, or maybe none of this is part of your threat model, but I felt like bringing it up either way.

[–] mox@lemmy.sdf.org 8 points 8 months ago* (last edited 8 months ago) (1 children)

even with E2EE, the admins of a homeserver can still impersonate you

No, they cannot. Your homeserver admin could create an impostor login session on your account, but it would be pointless with E2EE, because it would be flagged with an obviously visible warning. You and all of your contacts would see that the impostor session was not verified as you (this typically shows up as a bright red icon on the impostor and another one on the room they're in). Also, the impostor would be unable to read your communications.

[–] refalo@programming.dev 3 points 8 months ago* (last edited 8 months ago) (6 children)

What do you have to say about this then?

In an encrypted room even with fully verified members, a compromised or hostile home server can still take over the room by impersonating an admin. That admin (or even a newly minted user) can then send events or listen on the conversations.

Perhaps we have a different definition of "impersonate"... not everyone will pay attention to unverified warnings, and afaik they can still communicate with people (just maybe not read old messages)... but I would love to be proven wrong.

load more comments (6 replies)
[–] kevincox@lemmy.ml 3 points 8 months ago

That isn't what that document says. It says that they can impersonate you in non-E2EE scenarios. The clients I use warn me when a message isn't properly encrypted so someone without E2EE keys can't impersonate someone in an E2EE room.

That being said the general concept is a problem. I would love to see progress where all events from a user are signed by a device key and non-forgable. There is some thinking about this with portable identities (such as MSC2787) where you server is basically just storing and forwarding events but the root of trust is your identity and keys that you control. But none of this will land soon, not for many years.

[–] communism@lemmy.ml 9 points 8 months ago

If it's low privacy needs (ie you don't have a state threat model), Signal is completely fine. I use it to talk to my friends. I also use Matrix, though federated Matrix isn't the best for privacy either due to the amount of metadata that leaks through federation. But federated Matrix is also fine for the kinds of things you would use eg Discord or IRC for.

If you do have a state threat model, I personally think SimpleX is ideal for that, but it doesn't have as much of a userbase so you probably need people who care enough (eg people actively under threat) to switch to a new platform. Whereas most people I know are already on either Signal or Matrix, and I'm not having particularly sensitive conversations with them either so both work fine.

[–] poVoq@slrpnk.net 8 points 8 months ago (1 children)

Why would Matrix be the only option? XMPP is significantly better. You can either sign up on a public server or pay a small sum to have your own private server for you and your family for example on https://snikket.org/ or I think https://jmp.chat/ also includes optionally a small server in the subscription.

[–] asudox@lemmy.asudox.dev 8 points 8 months ago* (last edited 8 months ago)

Yeah, sure. But Matrix is decentralized and federated. So you can pretty much join any instance and be able to talk with anyone on any instance. So why not select another instance ~~or maybe even self host one yourself?~~

edit: didn't read the text till the end

[–] Zerush@lemmy.ml 6 points 8 months ago

Matrix/Element is pretty private, but not wide spreaded. For the use with friends and Family is more realisticto use Signal or any other decentralized Chat.

[–] kekmacska@lemmy.zip 6 points 8 months ago (5 children)

both are good, even Signal. For private conversations, you only need to avoid Telegram and other obvious ones

load more comments (5 replies)
[–] ReversalHatchery@beehaw.org 6 points 8 months ago (1 children)

you don't need to use matrix.org. there are several open homeservers, like chat.mozilla.org, but also there are people who host services for others to use. you may have a look at current lemmy hosts, and their other services if they have them.

[–] toastal@lemmy.ml 2 points 8 months ago

AFAIK, chat.mozilla.org was set up on modular.im, now element.io, which if it still using the same host, is owned by Matrix.org. So even using a different host means Matrix.org might still have your metadata.

[–] jaypatelani@lemmy.ml 4 points 8 months ago

Matrix and Simplex is fine but I would recommend Signal for family and friends. Threema is also option but not user friendly for friends and family who wants easy user discovery than sharing userIDs.

[–] toastal@lemmy.ml 3 points 8 months ago

Matrix.org is centralized like Signal (you can say Matrix is not centralized on paper, but in practice this isn’t remotely true). Both are stockpiling metadata in the West… what’s worse is Matrix’s eventual consistency model means syncing metadata to all servers is a by-design requirement (& also why all servers & clients are slow). There are options like Snikket to take all the hard parts of self-hosting out of the equation, but finding someone you can trust to host a server might be worthwhile. I would be wary of anything centralized.

[–] activist@lemm.ee 2 points 8 months ago

why did they told you not to use signal

[–] somegeek@programming.dev 2 points 8 months ago

Matrix is great, you can use another instance though.

https://servers.joinmatrix.org/

load more comments
view more: next ›