← Back to context

Comment by pmlnr

2 years ago

Unifiedpush to save the day! And an XMPP server with Conversations can be the basis for it: Https://unifiedpush.org/users/distributors/conversations/

You do _not_ need push notifications in the first place. Most definitely not for messaging programs anyway. The "saves battery" arguments are always very fluffy and devices/clients who don't do push notifications (or at least don't force you to) sometimes even have better battery life than devices/clients which do.

Stop promoting and trusting Conversations. Is it bad software which never did OTR verification properly before yanking it unexpectedly and without explanation. To my knowledge it has never been independently audited let alone taken seriously enough by any infosec professionals to warrant such study.

AIU deanonymization happens due to pseudonymity. There are 3 pseudonyms: chat id, push id, phone number. Since all three are constant and linked, they can deanonymize the user. You need some sort of anonymous or confidential protocol to work around it.