• Serge Matveenko@lemmings.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 hours ago

    Let’s start from the fact that Session isn’t Signal form anymore. It was started as that but now it has its own protocol and it’s fully decentralized. It doesn’t require any user data to operate (not a phone number nor email). Links to a protocol evolution stage from 2020 doesn’t help either. Nowadays all messages are end-to-end encrypted (except just public chat rooms). The post looks like uneducated rant or worse direct attack on Session. Which is the most secure and private messenger out there at this moment. Session and Signal are simply from different worlds now.

    • kbal@fedia.io
      link
      fedilink
      arrow-up
      0
      ·
      4 hours ago

      It’s centralized, it doesn’t officially allow 3rd-party clients, it requires a phone number, and the desktop app kinda sucks. I use it anyway, but it could be better.

    • Confetti Camouflage@pawb.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 hours ago

      I don’t know about other people, but the only thing I don’t like about Signal is that it is centralized. It seems to be the only option to actually get everything right for security though from what I hear.

      • Soatok Dreamseeker@pawb.social
        link
        fedilink
        English
        arrow-up
        0
        ·
        5 hours ago

        That’s a reasonable thing to dislike about it.

        I dislike that I can’t reply to another message with a sticker.

        I also dislike that, despite having admin access, I can’t delete abusive messages left in groups for anyone but myself. That makes it unsuitable for building communities.

  • vollkorntomate@infosec.pub
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 hours ago

    […] it uses the X25519 public key… as a symmetric key, for AES-GCM.
    […] anyone that knows the public key can decrypt it.

    Ouch.