this post was submitted on 26 Feb 2025
27 points (90.9% liked)

Asklemmy

45334 readers
719 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy πŸ”

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~

founded 5 years ago
MODERATORS
 

So, I have a Threema license, but from what I've seen its encryption isn't post-quantum. Signal's encryption seems the strongest. I host my own matrix server.

Also, I kind of don't care where the servers are or which provider it is. Everything is encrypted anyway.

top 24 comments
sorted by: hot top controversial new old
[–] Emberleaf@lemmy.ml 34 points 1 day ago (3 children)

Of the three, Signal is the most secure. Now in about 2.5 seconds, someone is going to start screaming about the phone number requirement. This is used so that you can go from desktop to mobile with the same profile. You can set Signal to hide your phone number from everyone else but you. It's a non-issue.

There is a reason why Elon Musk doesn't let people post about Signal on his Nazi social network. Because it works.

[–] Limonene@lemmy.world 18 points 1 day ago (1 children)

It's an issue.

You can't create an account on desktop. You can't create multiple accounts. You can't create an account at all if you don't have a phone number. You can't create an account if your phone number's previous owner created an account. Signal can be subpoenaed for your phone number.

[–] ALiteralCabbage@feddit.uk 3 points 1 day ago (1 children)

Is it possible to use a number different to the one on the device you use? Seems like a simple workaround to use a throwaway SIM to set up, and then use it with that number moving forwards.

That sounds like an awful lot of work to workaround a problem that shouldn't have existed in the first place.

[–] ocean@lemmy.selfhostcat.com 11 points 1 day ago (1 children)

You say this like username logins don’t exist

[–] devfuuu@lemmy.world 8 points 1 day ago* (last edited 1 day ago) (1 children)

No, we know that, but people will still come scream here that you need a phone to register anyway. It's all the time the same people. Not realizing that is the easiest onboard that all the normies are used to and an easy way to control spam accounts.

I mean if you acknowledge that user names can be used like any other website then your point doesn’t work. They don’t need my phone number. Most applications don’t need it but they do? Come on.

[–] BakedCatboy@lemmy.ml 27 points 1 day ago

I prefer signal because it's been the easiest one to convince my friends and family to use. I have like 8 friends on Signal, the 1 I got onto Matrix quit after a week. Matrix I treat more like foss Discord so I only use it for communities. ElementX is really nice though so I have hope that eventually it could be as smooth to use as Signal.

[–] 2xsaiko@discuss.tchncs.de 16 points 1 day ago

Signal is much more polished and less fragile than Matrix, but is pretty barebones especially in terms of features for large communities. Matrix additionally has a browser client and many non-Electron desktop clients. It's really close and depends on the use case imo. For personal messages I think I prefer Signal, for communities Matrix.

I haven't used Threema.

[–] uxellodunum@lemmy.ml 8 points 1 day ago* (last edited 1 day ago)

Self-hosted Matrix.

It still needs polish, but it's on a good path. Meanwhile others are centralized by a single authority with an easy target painted on them for government coercion along with multiple other attack surfaces, and even information easily traced to PII. Also, not everything is encrypted. A lot of metadata is left out of E2EE. And those servers/providers have that data.

By contrast, a drop in the ocean is far more likely to not be targetted from the outset, making pretty much any matrix server (potentially with the exception of the matrix.org one, but it's ok to treat it as a demo anyway) a really good choice in that sense.

[–] olof@lemmy.ml 12 points 1 day ago
[–] SplashJackson@lemmy.ca 3 points 1 day ago

I liked the Matrix because of all the kung fu karate fights, though I got to say the second one was the best, even though the third one had a Dragon Ball Z fight at the end

[–] Limonene@lemmy.world 5 points 1 day ago (1 children)

Post-quantum isn't really a big problem because it will be a very long time before there are viable quantum computers (maybe never). You should focus on the very real risks of security breaks from normal negligence and design errors.

Threema seems pretty unpopular, so the risk is highest. Signal and Matrix are both popular and have a lot of scrutiny on their cryptography.

All 3 have open source clients, but Signal contains some binary blobs. Only Matrix has an open source server, though end-to-end encryption enforced by the client alleviates most of the concern of proprietary servers. All 3 support end-to-end encryption.

[–] chris@l.roofo.cc 4 points 1 day ago

Matrix because I can host it myself. I like self hosting. But I agree that it is the least polished of all.

Self hosted matrix with bridges to WhatsApp and telegram. What else....