← Back to context

Comment by fredski42

1 day ago

Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

Realistically nothing is ever perfect, but XMPP comes very close. You've got Signal-introduced double-ratchet encryption if forward secrecy is your jam (so it's as "E2E-secure" in practical terms) and you've got a healthy ecosystem of independent client and server implementers, and service providers to choose from.

XMPP. Run your own (federated) server, chat with anyone outside it, with e2e encryption.

Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company?

As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it.

Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.

Depending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you have to pick your poison. If E2EE is important, you also need to determine how encrypted you want your messages to be (as both XMPP and Matrix carry quite a bit of identifying metadata in its unencrypted headers).

For most people and use cases, either will probably do, but if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal.

  • > if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal

    So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delivery?

    I mean, as opposed to using something like XMPP which you can completely use over Tor and never even reveal which server you use/that you use XMPP, from a client running a secure and minimalistic OS and no service-in-the-middle ?

    Some would label Signal as a honeypot and it would be difficult to falsify that.

> Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

(Note that I don't care about cryptocurrencies except for the cryptography behind it)

There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made for (anyone with a copy of the chain can potentially be the recipient of either the money transfer or the encrypted message).

If people were really serious about privacy and secure messaging they'd look into this instead of constantly attacking the concept.

But then of course there are entire armies of shills who have a vested interest in pushing a narrative explaining that services, at best, collecting metadata and, at worst, being backdoored are offering "secure messaging".

I'm only using Telegram and I don't believe for a second it's secure and private (it's got, supposedly, "one on one" E2EE but not for groups). But at least they're not posturing as the most secure and private messenger on earth.