I’ve been inspecting this topic quite a lot and I’m a little confused now. So, we have reasons not to use Signal, reasons not to use Matrix, there were also some claims about Session being a fraught. Briar is mostly activists related (not very suitable for daily use), XMPP lacks good clients and suffers from fragmentation of protocol standards implementation, SimpleX is too feature-incomplete (no UnifiedPush support, big battery drain on Android, very decent desktop client without any message sync). I can’t say a lot about Threema or Wire, as I’m not very familiar with them.

So, my question is — is there any good private messenger at all? What do you think is the most acceptable option?

EDIT: In addition to my post:

All messengers have their flaws, I’m well aware of that. I was interested in hearing users’ opinions regarding these shortcomings, not in finding the perfect messenger. I may have worded my thoughts incorrectly, sorry for that.

  • delirious_owl@discuss.online
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    2 hours ago

    Wire is the best for security (it literally won’t let you send messages unencrypted), cost (its free), privacy (no phone number required), and usability for the masses (Foss client on all the platforms, messages sync between each client like you’d expect)

    I haven’t found anything that checks all those boxes other than Wire (though I do wish we had other options that came close)

    https://Wire.com

  • mox@lemmy.sdf.org
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    16 minutes ago

    There are a few that do a good job of protecting our messages with end-to-end encryption, but no single one fits all use cases beyond that, so we have to prioritize our needs.

    Signal is pretty decent at meta-data protection (at the application level), but has a single point of failure/monitoring, requires linking a phone number to your account, can’t be self-hosted in any useful way, and is (practically speaking) bound to services run by privacy invaders like Google.

    Matrix is decentralized, self-hostable, anonymous, and has good multi-device support, but hasn’t yet moved certain meta-data into the encrypted channel.

    SimpleX makes it relatively easy to avoid revealing a single user ID to multiple contacts (queue IDs are user IDs despite the misleading marketing) and plans to implement multi-hop routing to protect meta-data better than Signal can (is this implemented yet?), but lacks multi-device support, lacks group calls, drops messages if they’re not retrieved within 3 weeks, and has an unclear future because it depends on venture capital to operate and to continue development.

    I use Matrix because it has the features that I and my contacts expect, and can route around system failures, attacks, and government interference. This means it will still operate even if political and financial landscapes change, so I can count on at least some of my social network remaining intact for a long time to come, rather than having to ask everyone to adopt a new messenger again at some point. For my use case, these things are more important than hiding who is talking to whom, so it’s a tradeoff that makes sense for me. (Also, Matrix has acknowledged the meta-data problem and indicated that they want to fix it eventually.)

    Some people have different use cases, though. Notably, whistleblowers and journalists whose safety depends on hiding who they’re talking to should prioritize meta-data protection over things like multi-device support and long-term network resilience.

  • dingdongitsabear@lemmy.ml
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    6 hours ago

    good messenger for what?

    if you want a solution for you and a bunch of your henchmen to coordinate and discuss totally-not-crimes with ephemeral comms, practically any E2EE solution will work; once the not-crimen is done, burn your accounts and toss the devices for good measure and you’re scot free.

    if you want a secure messenger that’s part of a widely used communication platform where you can also do normal people shit and also convert normal people to actually use it (think getting contact deets from cute boy/girl at a bar or giving yours to a business correspondent without an elaborate powerpoint presentation on how to use it) and you want to enjoy the fruits of 20+ years of continuous IM development, like having top-notch UX, battery efficiency, network resiliency, quality voice/video calls, etc., without being spied on then such a thing doesn’t exist.

    how come? meredith baxter recently stated that it costs signal $50MM/yr to run their infra. that money has to come from somewhere. if there are no advertising dolts dumping cash on spying on your social graph and convos, the remaining avenues for financing are few and far between.

    in closing, there aren’t any super awesome messengers you weren’t aware of, everything is shit.

  • mipadaitu@lemmy.world
    link
    fedilink
    English
    arrow-up
    77
    arrow-down
    11
    ·
    12 hours ago

    That article in Signal is bogus. It is entirely based on speculation from how funding comes in, and also either ignores, or misunderstands how Signal fundamentally works.

    The EFF recommends Signal, and it’s one of the most secure ways to communicate.

    https://ssd.eff.org/module/how-to-use-signal

    You can make your own decisions, but if you just grab any random arguments, you’ll find a reason to doubt everything.

    • FeelzGoodMan420@eviltoast.org
      link
      fedilink
      English
      arrow-up
      30
      arrow-down
      7
      ·
      10 hours ago

      Lemmy has some sort of slander campaign going against Signal. Can’t tell if it’s just misinformed idiots or a paid shill smear campaign being run here (likely the former, Lemmy is too small for companies to give a shit about.) It’s really annoying. Same with Mozilla and Firefox. Not sure Lemmy likes anything?

        • Cenotaph@mander.xyz
          link
          fedilink
          English
          arrow-up
          21
          arrow-down
          3
          ·
          9 hours ago

          Signal has usernames (must be enabled) and you can have your phone number hidden from public view & prevent it from being used to search up your acc

          • Dessalines@lemmy.ml
            link
            fedilink
            arrow-up
            16
            arrow-down
            2
            ·
            8 hours ago

            That got added recently, but you still need a phone number to sign up. A phone number is tied to your identity, meaning that signal’s database has the names and addresses of everyone who uses it. And since signal is US-based, its subject to US national security letters, meaning its illegal for signal to tell anyone that the US government has requested information about who they’re talking to.

            Under the Obama administration, an average of 60 NSLs were issued every single day.

    • Dessalines@lemmy.ml
      link
      fedilink
      arrow-up
      8
      arrow-down
      5
      ·
      9 hours ago

      The US-state-department funding is important sure, but you also ignored every other point in that article.

    • s38b35M5@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      13
      ·
      11 hours ago

      You can make your own decisions, but if you just grab any random arguments, you’ll find a reason to doubt everything.

      Agreed. Especially if your source is Dessalines. 🙄

  • Dessalines@lemmy.ml
    link
    fedilink
    arrow-up
    26
    arrow-down
    3
    ·
    11 hours ago

    Almost all those can be self-hosted, and built from source, so matrix, xmpp, simplex, are fine. Don’t use anything that’s uses a centralized server in a five eyes country, like signal or threema.

    • MonkderVierte@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      3 hours ago

      How is Threema in a five eyes country?

      I mean, sure, only the clients are open source. Don’t use it for that.

  • Maseo@rebel.ar
    link
    fedilink
    arrow-up
    5
    ·
    8 hours ago

    @JustMarkov “Good” by what standard?
    How anonymous do you really need to be? How much convenience are you willing to sacrifice in the name of secrecy?
    I’m not an activist or journalist, I don’t live in a very authoritarian country (although I’m a bit cautious about sharing my political views)
    So, for me sharing a phone number is not a big deal. But for others it might mean more.

  • rcbrk@lemmy.ml
    link
    fedilink
    English
    arrow-up
    13
    ·
    edit-2
    11 hours ago

    XMPP lacks good clients and suffers from fragmentation of protocol standards implementation

    • For Android: Conversations is excellent, also on F-Droid if you don’t want to use the Google store.
    • For iOS/MacOS: Siskin or iOS/MacOS: Monal.
    • For Linux/Windows: Gajim or Linux: Dino.

    “Protocol fragmentation” is not a valid complaint about XMPP – it’s like complaining that ActivityPub is fragmented; but that’s not a problem: you use the services (Mastodon, Lemmy, Kbin, etc) built with it which suit your needs, mostly interacting with that sector of the federation (eg, Lemmy+Kbin), but get a little interoperability with other sectors as a bonus (eg, Lemmy+Mastodon).

  • troed@fedia.io
    link
    fedilink
    arrow-up
    17
    ·
    12 hours ago

    I don’t consider those comments regarding Matrix as problematic. Don’t use someone else’s server if you don’t trust them - including a third party lookup server.

    /selfhosting Matrix

    • AlphaAutist@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      6 hours ago

      The article he linked specifically mentioned that the data is sent to matrix’s servers even when using a self hosted server though

  • 84skynet@discuss.online
    link
    fedilink
    arrow-up
    11
    arrow-down
    1
    ·
    11 hours ago

    It really just depends on your threat model.

    Think it in this way: What is the most secure way to walk in the city? You’ll need a team of armed bodyguards and wear a full bulletproof vest. Do you REALLY need this level of security? Who are you protecting from? If the answer is a criminal organization or law enforcement, then yes, probably. But if the answer is a random thief, then you’ll probably need to just carry a gun, pepper spray, knife etc.

    Same goes for privacy online and messenger in this case. Are you an activist or a drug dealer? Then you’ll probably need Tails + something like SimpleX via TOR. Otherwise, if you are just concerned of typical surveillance capitalism (and don’t want the government to scan your chats like it probably will in the EU after Chat Control), in my opinion, Signal is the best compromise of privacy, security and convenience.

  • MalReynolds@slrpnk.net
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    1
    ·
    14 hours ago

    Depends a lot on who you’re talking to, and your, and their threat models. For many, signal provides pretty good protection, which brings us to a salient point, anything that actually provides good security will attract plenty of negativity, often from state level actors who feel (are) threatened. If you’re playing at that level, adam_y is right, dead drops and one time pads. Presuming lesser threat, signal beats telegram and FB etc. Email is plaintext unless proton to proton, encrypted email is fine (look at PGP) and indeed if you encrypt at home before sending it’s pretty much a dead drop anyway, as long as the other party has a key, and I’m wandering off the beaten path.

    Seems you want a secure messenger that works and are scared by random crap because you don’t have the relevant knowledge to decide (spoiler, very few do, and it’s insider knowledge, the world is imperfect), fair enough, but don’t let perfect be the enemy of good. As long as you’re willing to give up your phone number, Signal is well regarded (exchange privacy for security, you decide). But yeah, no perfects, world imperfect, trust hard, deal ;)