SIGNAL IS MORE SECURE THAN MOST ALTERNATIVES.

IF YOU ARE A TARGET, GOVERNMENTS WILL COMPROMISE PHONES, AND EVERYTHING ON THEM.

THIS IS WHY SIGNAL AND SIMPLEX HAVE THE AUTO DISAPPEARING MESSAGES FEATURE.

https://cdn.satellite.earth/0f840814e8768d604a3215e037874cf197830984b26247e0f68bcf3eda65c5a1.mp4

Reply to this note

Please Login to reply.

Discussion

šŸ’Æ

Love #Simplex, I just wish the ui was a little more up to speed. Getting people to abandon TG and that other spyware, WhatsCrap is near impossible

#FreeSamourai #FreeRoss

I DELETED TG SO IF PEOPLE WANT TO CONTACT ME THEY NEED TO USE SIGNAL OR SIMPLEX.

I wish I could be so dedicated. Try telling the UK Bitcoin Maxi group this!!!

I have sadly been unable to convince 2 great wallet chats (Minibits and Blitz) to move their discussions away from TG :/

They keep getting better. It's a big improvement from a year ago.

Session?

AGREED & SIMPLEX IS THE BETTER ONE

I USE BOTH.

I HAVE PROBLEMS WITH SIMPLEX NOTIFICATIONS AND GENERAL RELIABILITY.

ALSO GROUPS AND CALLS WORK MUCH BETTER ON SIGNAL.

Yea that makes sense I can see how you feel about that. I use both also and especially signal for groups + it’s more easily accessible for people / learning curve.

Notifications on iOS and calls are the main issue why I can’t convince my girl to use it all the time

SimpleX crashes for me like crazy on iOS. It’s not usable for me in its current state. I’ll wait until it matures.

Love Signal! Its my No1 Messenger App for Most contacts. šŸ‘šŸ»

Imagine signal, but using your NOSTR key!

nostr:npub1tm99pgz2lth724jeld6gzz6zv48zy6xp4n9xu5uqrwvx9km54qaqkkxn72

https://www.0xchat.com/#/

Odell, so can old messages be retrieved if set to auto disappear after 30 seconds if one has your phone number?

NO. IF YOUR PHONE IS COMPROMISED EVERYTHING FROM THAT POINT FORWARD CAN BE SEEN.

THESE ARE TARGETED ATTACKS AND NOT VERY COMMON.

If someone is looking over my shoulder while im typing my super secret squirrel messages on Signal, the encryption is irrelevant...

EXACTLY.

Love SimpleX - the team is pretty transparent about their goals.

AGREED! SIMPLEX WORKS REALLY GREAT AND THE LATEST UPDATE IS šŸ”„!

Was the Tucker Carlson/signal "hack" ever elaborated on? What do we know? A web search provides very little that I can see.

CONSIDERING HE COUPLED IT WITH SHILLING TELEGRAM HEAVY IM GOING TO CONTINUE TO ASSUME IT WAS TUCKER ACTING IN BAD FAITH.

SAME DUDE HAD ROGER VER ON AND TELLS THE WORLD THE CIA CREATED BITCOIN.

Yea. I read some more. Likely alt channels like compromised people in the Kremlin. Someone else HAD to know. You can't go "Hey yo Vlad, how about an interview". It's more likely the 50 people planning the meeting leaked it somehow.

Treat every device connected to the internet as compromised

THE GOLDEN RULE.

Not a fan of Tucker. The signal ā€œhackā€ was definitely bs. He didn’t elaborate on it or how it happened then shilled telegram shortly after. He’s a fiat whore that can go fuck himself.

His name rhymes with it. So. He is here to give us lessons in how to spot clever con artists.

Yes, and…

it seems like Rogan doesn’t understand metadata (which Signal leaks) vs content data (which Signal encrypts), but I know Odell and Gladstein do.

Much simpler explanations like client side scanning. End to end encryption only works if you're also secure at the ends.

Even getting normie friends on Simplex these days. People are waking up 🧔

Finna to join, myself.

Does this apply to grapheneOS as well, or they only can scan ordinary android / ios ?

GRAPHENE IS MOST SECURE FROM TARGETED ATTACKS.

A FULLY UPDATED IPHONE 15 OR16 IN LOCKDOWN MODE SECOND BEST.

WE NEED TO ONBOARD GRAPHENEOS TEAM TO #NOSTR

I believe the act of having a physical sim card severely compromises your privacy. Telecom networks are built to track by default. Being Ed Snowden requires dedication beyond mere mortals.

Signal requires phone number lol, privacy that we've deserved...

Explain

Relays. SimpleX lets you spin one up yourself; signal requires signal dot org for every message.

Right by failure you mean go offline

šŸ’Æ

Requiring a phone number is not ideal

USE A BURNER.

THEY DO NOT BLOCK VOIP NUMBERS.

You don't even need that phone number again to recover the account on another phone, as long as you have pin lock and a backup file, so even one time burner numbers work well.

Didn't Signal cave to Putin?

NOPE. FAKE NEWS.

Fear is not a factor for me nice try Joe

I was waiting for the guy to explain to Joe that signal is secure, phones are not.....

šŸ”„

Don't forget Session https://getsession.org/

I tried it, but I missed Telegram bots too much and went back šŸ§˜ā€ā™‚ļø

STAY HUMBLE AND STACK SATS🫔

> SIGNAL IS MORE SECURE THAN MOST ALTERNATIVES.

- Am i watching the same video as you ? They just said that they can get into your signal app if they know your phone number ?

Seems like Simplex and Session are one of the few real options left

Signal is amazing. Specially if you combine it with other general privacy recommendations.

Graphene OS + Anonymous Sim paid with lightning + pseudonym

Most people don’t need more privacy than that.

That’s a great combo. You can also use something like smspool and get disposable number just to receive the comfirmation. And use Signal’s username for everything.

Although I’d love for them to integrate Lightning.

🫔

Agree.

Simplex (own server) is next step and it should keep improving.

I have normies (mainly) that have Signal b/c I asked although more and more are joining.

Getting people off WhatsCrap and Telegram (even amongst nostriches) is a lift but people are catching on.

Step by step.

all my spook friends have been using Signal for years. so it's at least not completely pwned by US adversaries (to the USGs knowledge)

that being said, if it's online, someone else will see it

Signal is the one thing..... I don't buy it. Sorry

WHY DON’T ANY OF THESE FUCKTARDS KNOW ABOUT PEGASUS????

I learned about Pegasus through Rogan's Snowden episodes. I guess it's hard for him to internalize all the 3 hour convos he has.

Session and simple chat are the best

i degoogled my phone, as far as I could possibly go, with ABD. Now signal is complaining it cant find playstore. I uninstalled signal. Simplex is fine.

There is one big problem with open source and central servers, you can never tell if there are asynchronous offline , non open source processes that are harvesting server data and analysing it. If you cant run your own server, then maybe find an app where you can.

typo : ADB

What about Keet? Compromising phone means that also p2p is not secure?

The Nostr is public. We use it. We know it’s public.

If you don’t know it’s public…

decentralize. run a matrix synapse server at home. encrypted messaging stored securely on your own server not Amazon's

This doesn’t help protect you against state actors having access to your device.

that isn't an issue with matrix

Spot on. They get access my compromising the OS. Signal might be encrypted but at the end it relays on the OS to display the message to you

Why Signal is not a secure messenger!

Signal runs its entire traffic via the clouds of Google, Amazon, Microsoft & Cloudflare. They don't tell their users this, but speak of ā€œ3rd partiesā€ in a trivializing way.

These 4 IT giants have enough of your IP address and the Americans know who is writing to whom = valuable metadata!

There are no ā€œfreeā€ messengers!

Why do they use these 4 cloud providers and not just one of them, or another cloud service?

Because they are the biggest, with the widest distribution. And they have the most data!

Google's Android runs on around 85% of all smartphones. This sends encrypted data ā€œhomeā€ every day. So you can assume that Google can always link 85% of all smartphone IPs to the respective user!

Amazon is the online shopping market leader (in the West) and can provide the name and address for IPs.

Microsoft is the world market leader in operating systems and can provide further user data, for example the IP of your wifi.

And Cloudflare is ā€œstuckā€ invisibly in front of many well-known websites and knows the surfing behavior for the IP!

More espionage or user data collection is almost impossible!

Financing

If you want to know who is behind it, you have to look at where the money comes from.

Signal gets money from the Open Technology Fund = US government.

https://www.opentech.fund/projects-we-support/supported-projects/signal-open-whisper-systems/

If they put money into it, then they want something in return = namely data!

Open Technology Fund = ā€œAffiliations U.S. Governmentā€

https://en.wikipedia.org/wiki/Open_Technology_Fund

In addition, WhatsApp billionaire Brian Acton has invested millions of dollars in the Signal Foundation. That alone should give you pause for thought!

He had a lot of functions built into SignalApp that were stolen/adopted 1:1 from WhatsApp. Both messengers also use the same protocol.

So you can assume that if the Signal app has enough users, he will sell the whole thing back to Facebook/Meta. The data in the cloud services will then be the real treasure for which Zuckerberg will again make billions.

Cloud Act

And everything that the cloud services have on you can be obtained and viewed by US services via the Cloud Act!

ā€œThe law obliges American internet companies and IT service providers to guarantee US authorities access to stored data even if it is not stored in the USA.ā€

https://en.wikipedia.org/wiki/CLOUD_Act

MetaData, MetaData, MetaData....

The Americans are only ever interested in MetaData! So: Who writes when with whom, how often, etc.

A quick reminder:

ā€œMetadata tells you absolutely everything about a person's life. If you have enough metadata, you don't really need the content.ā€

NSA General Counsel

Stewart Baker

See:

ā€œWe kill people based on metadataā€

https://www.nybooks.com/daily/2014/05/10/we-kill-people-based-metadata/

How ā€œgreatā€ the encryption is only plays a subordinate role. Cloud spies almost always only need your IP and that of the recipient and they know who is writing to whom = valuable metadata.

Compulsory telephone numbers

Even today, Signal still demands that you give out your mobile phone number and this will always remain the case (I've been saying this for 6 years).

This reveals your complete identity, because in the EU all mobile numbers must be registered by name. And if not, government services can query device and location data via ā€œsilent SMSā€ without the user being aware of it.

All of this together (cloud storage, compulsory mobile phone numbers and CloudAct.) gives a very detailed user picture, which works into the arms of the US services.

If you want to know how to do it right, take a look at Threema, the messenger that can be used 100% anonymously:

Threema does not use any third-party (cloud) services, but runs everything via its own server.

Messages are only stored until they have been successfully delivered. Then they are deleted.

And most importantly:

Threema does not store any metadata or IP's!

Quasi confirmed in court here (translate for yourself)

https://magazin.nzz.ch/wirtschaft/threema-wehrt-sich-erfolgreich-gegen-staatliche-ueberwachung-ld.1558968

If you want to communicate securely and anonymously without leaving any traces on the operator's infrastructure, there's no way around Threema.

There are no ā€œfreeā€ messengers. You always have to pay - either with your privacy or, as with Threema, with a few euros in return for not storing anything about you. The latter is clearly the better option.

> These 4 IT giants have enough of your IP

Someone connecting with a service through their private IP from the phone or laptop should expect the servers to log it when not mentioned otherwise. Signal officially states, that last connected IP address can be shared, when requested from legal entities.

But this can be mitigated with a VPN with a no-log policy.

> "Google's Android runs on around 85% of all smartphones. This sends encrypted data ā€œhomeā€ every day. So you can assume that Google can always link 85% of all smartphone IPs to the respective user!

Amazon is the online shopping market leader (in the West) and can provide the name and address for IPs.

Microsoft is the world market leader in operating systems and can provide further user data, for example the IP of your wifi.

And Cloudflare is ā€œstuckā€ invisibly in front of many well-known websites and knows the surfing behavior for the IP!

More espionage or user data collection is almost impossible!"

This takes in the assumption one is using an IP as one person and that those companies would figure out your network with only knowing IP connection time and package size.

But many people can share the same IP and IPs change regularly. So I agree, that through the use of such Servers of these companies some surveillance of their side is possible. But considering all the connections that come and go from VPN and TOR network, the picture those companies get, would not get them significant information from signal chats.

I can support the point, that Threema does several technical things better than Signal. But I would argue, that when the switch from Whatsapp to Signal it is 1k privacy points, then from signal to threema accounts for additional 20 or 30 privacy points for protecting user data with their own datacenters and not having any unique identifiers used somewhere else.

But for a messenger to be useful, my contacts need to use it actually. There I like the model of signal better, where I can ask whatever contact to install signal and make a fast login to start chatting. It is known, that Signal does protect their user data and who messages with whom from courts and commercial companies.

They use opensource software. There is even an android client, that does not use any google framework integration within the Molly-foss app.

So I agree, that Threema has some parts that are superior compared to signal (and I have the app installed). But Privacy is not a one size fits all solution. So I rather use Signal with as many people as possible, since I trust Signal much more than I would Meta with the data of a messenger.

Privacywise I would put personally the following row:

SMS < Telegram < Whatsapp < iMessage < Signal < Threema < Simplex < Briar (top of private messaging)

Probably in the future some nostr messaging apps will come to that ladder somwhere at the top. But depends on the relays used and if there are public security reviews of the app.

Disappearing Messages are false security!

Even if a message has disappeared from the chat, it remains in the notification log of the cell phone operating system, for example, and can be read by third parties using simple means.

This gives you a false sense of security.