Realistically nothing is ever perfect, but XMPP comes very close. You've got Signal-introduced double-ratchet encryption if forward secrecy is your jam (so it's as "E2E-secure" in practical terms) and you've got a healthy ecosystem of independent client and server implementers, and service providers to choose from.
Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company?
As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it.
Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.
Why not? Plenty people already use a dedicated '2FA' phone for Work under BYOD policies when they don't want to install any 'work' software on their 'personal' phone.
Depending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you have to pick your poison. If E2EE is important, you also need to determine how encrypted you want your messages to be (as both XMPP and Matrix carry quite a bit of identifying metadata in its unencrypted headers).
For most people and use cases, either will probably do, but if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal.
> if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal
So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delivery?
I mean, as opposed to using something like XMPP which you can completely use over Tor and never even reveal which server you use/that you use XMPP, from a client running a secure and minimalistic OS and no service-in-the-middle ?
Some would label Signal as a honeypot and it would be difficult to falsify that.
> Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
(Note that I don't care about cryptocurrencies except for the cryptography behind it)
There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made for (anyone with a copy of the chain can potentially be the recipient of either the money transfer or the encrypted message).
If people were really serious about privacy and secure messaging they'd look into this instead of constantly attacking the concept.
But then of course there are entire armies of shills who have a vested interest in pushing a narrative explaining that services, at best, collecting metadata and, at worst, being backdoored are offering "secure messaging".
I'm only using Telegram and I don't believe for a second it's secure and private (it's got, supposedly, "one on one" E2EE but not for groups). But at least they're not posturing as the most secure and private messenger on earth.
Realistically nothing is ever perfect, but XMPP comes very close. You've got Signal-introduced double-ratchet encryption if forward secrecy is your jam (so it's as "E2E-secure" in practical terms) and you've got a healthy ecosystem of independent client and server implementers, and service providers to choose from.
> 100% e2ee encrypted and decentralized and open
https://getsession.org
https://docs.getsession.org/contribute-to-the-session-networ...
XMPP. Run your own (federated) server, chat with anyone outside it, with e2e encryption.
Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company?
As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it.
Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.
Why not? Plenty people already use a dedicated '2FA' phone for Work under BYOD policies when they don't want to install any 'work' software on their 'personal' phone.
But they won‘t buy a second personal phone to protect their privacy in a chat group.
I think you can do this with Jitsi: https://jitsi.org/
Depending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you have to pick your poison. If E2EE is important, you also need to determine how encrypted you want your messages to be (as both XMPP and Matrix carry quite a bit of identifying metadata in its unencrypted headers).
For most people and use cases, either will probably do, but if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal.
> if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal
So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delivery?
I mean, as opposed to using something like XMPP which you can completely use over Tor and never even reveal which server you use/that you use XMPP, from a client running a secure and minimalistic OS and no service-in-the-middle ?
Some would label Signal as a honeypot and it would be difficult to falsify that.
> Or throwing it all away anyways when it's using Apple/Play services for notifications delivery?
What do you mean by "all"
5 replies →
Not decentralized (just like Signal), but open and 100% E2EE:
SimpleX, Delta Chat, Matrix
> Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
(Note that I don't care about cryptocurrencies except for the cryptography behind it)
There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made for (anyone with a copy of the chain can potentially be the recipient of either the money transfer or the encrypted message).
If people were really serious about privacy and secure messaging they'd look into this instead of constantly attacking the concept.
But then of course there are entire armies of shills who have a vested interest in pushing a narrative explaining that services, at best, collecting metadata and, at worst, being backdoored are offering "secure messaging".
I'm only using Telegram and I don't believe for a second it's secure and private (it's got, supposedly, "one on one" E2EE but not for groups). But at least they're not posturing as the most secure and private messenger on earth.
https://status.app/
https://matrix.org is used by public agents of France's central administration, Germany's national healthcare system, Germany's armed forces, the Swedish Social Insurance Agency and more: https://en.wikipedia.org/wiki/Matrix_messaging