Granted, the part

The globally recommended app by privacy and security experts, Signal, is now being downloaded massively and tops the Danish Google Play Store

is a little ironic, but you gotta push this winning tide and then work from that.

  • TheCorminator@lemmy.ml
    link
    fedilink
    English
    arrow-up
    97
    arrow-down
    1
    ·
    2 months ago

    Are they switching in the hope they’ll get added to a group chat planning the invasion?

  • 🦄🦄🦄@feddit.org
    link
    fedilink
    English
    arrow-up
    89
    arrow-down
    2
    ·
    2 months ago

    Kinda ironic that if the danish representatives in the EU got their way with chat control, danish people wouldn’t even be able to install signal (officially at least), since Signal said they would leave the EU in such a case.

    • dzsimbo@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      39
      ·
      2 months ago

      I’m pretty sure this isn’t irony, but rather a reaction from the population that is realizing the shit their government is doing.

    • PlutoniumAcid@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      2 months ago

      What’s she flag equivalent of blasphemy? This is what it would look like.

      Mushing two nation flags plus an app logo plus some sort of pattern overlay into a headline image is just so wrong.

  • comrade_twisty@feddit.org
    link
    fedilink
    English
    arrow-up
    32
    arrow-down
    5
    ·
    2 months ago

    Unfortunately Threema the European alternative that’s at least as secure as Signal costs money - and that one time fee is enough to send everyone to Signal.

  • rumschlumpel@feddit.org
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    1
    ·
    edit-2
    2 months ago

    If only the threat didn’t (also) come from inside the house when it comes to privacy. I don’t want my national police to have full access to my chats at all times any more than I want the USians to have that access, possibly even less. FBI or CIA isn’t going to personally bust down my front door, arrest me and seize all my computing devices because I called a local politician a dick.

        • VisionScout@lemmy.wtf
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 months ago

          no. But if you mean independent access with various devices, neither signal is since you need always the phone to access the desktop version.

          • Wrdlbrmpfd@feddit.org
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 months ago

            Thats why I personally prefer Matrix.

            However, the solution that Signal offers is the easiest for most people. Also it is not true that you always need the phone. The desktop version works fine alone unlike Whatsapp it doesn’t request you to connect the devices all 2 weeks. It does need a first installation on a Mobile or Android device in order to get the PC version running.

            The difficulty is when you need to exchange the encryption keys between different clients. This is where it gets complicated with Tox and Jabber/OTR. And to be honest the solution of Matrix is easier but also can get confusing for people who are just used to having a phone as their main device.

            • VisionScout@lemmy.wtf
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 months ago

              It does need a first installation on a Mobile or Android device in order to get the PC version running.

              I stand correct.

              And to be honest the solution of Matrix is easier

              What is the matrix solution for that? Keys will always have to be exchanged between devices

              • Wrdlbrmpfd@feddit.org
                link
                fedilink
                English
                arrow-up
                1
                ·
                2 months ago

                I stand correct.

                Yes, but fact is, that this is the easiest way for most users. And also most users don’t care if you can use it stand alone on a PC or not, and if it is linked to a phone number or not.

                What is the matrix solution for that? Keys will always have to be exchanged between devices

                You can use devices to cross-sign each other or use a passphrase.

    • paulcdb@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 months ago

      Sadly Meshtastic is limited to the number of nodes it’ll go through (think it was 7) so pretty limited. MeshCore goes up to something like 64 so is better but still both have huge limitations right now besides the ‘no nodes around me’ issue.

      still, I have some MeshCore nodes and hopefully get 1 fairly high up when I can afford the £100 to buy it but its a lot to waste when no-one around here is interested.

    • percent@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      IIRC, I looked into Meshtastic a while back, and it was known to be unreliable. Is that still the case? It seems like a really cool concept

  • poVoq@slrpnk.netM
    link
    fedilink
    English
    arrow-up
    23
    arrow-down
    8
    ·
    2 months ago

    Like one of the main things Signal is really terrible at given that it is based in the US and hosted on AWS servers 🤦

    • VisionScout@lemmy.wtf
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      2 months ago

      Besides being hosted in the AWS servers, there’s no way to check if what’s running there is the same as the published code. That’s why i don’t use signal.

      When the signal foundation is losing money every year, i can just wonder what will happen when the money runs out. Even the good guys need to eat.

      Or what will happen when trump will decide to seize the AWS servers running the signal application server.

      • devfuuu@lemmy.world
        link
        fedilink
        English
        arrow-up
        12
        ·
        2 months ago

        You don’t need to care about the server code since the secure bits and encryption that matters is all on the client side and verifiable.

          • desertdruid@lemmy.blahaj.zone
            link
            fedilink
            English
            arrow-up
            6
            ·
            2 months ago

            as in phone number, IP and timestamps? If I were worried about that I wouldn’t have a phone in the first place but if private messaging (content is private) I think signal works fine

          • devfuuu@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            2 months ago

            If you care about it then just use Signal since it’s the one with least amount of metadata fying around. A big central server with many normies using it also ensures that it’s very hard to correlate traffic.

            • VisionScout@lemmy.wtf
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              1
              ·
              2 months ago

              If you care about it then just use Signal

              No, because of:

              When the signal foundation is losing money every year, i can just wonder what will happen when the money runs out. Even the good guys need to eat.

              I have seen this film so many times…

      • mjr@infosec.pub
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 months ago

        when trump will decide to seize the AWS servers running the signal application server.

        How do we know he hasn’t already?

        • poVoq@slrpnk.netM
          link
          fedilink
          English
          arrow-up
          9
          ·
          2 months ago

          No need to size them. AWS is deeply embedded into the intelligence apparatus of the NSA as one of their prioritized suppliers.

    • copacetic@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      10
      ·
      2 months ago

      I believe the fact that Signal is hosted on Apple or Google clients is worse than its server host. (I still use and recommend it though)

      Convincing people to use an open Android build is much harder than installing another messenger.

    • fxdave@lemmy.ml
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      4
      ·
      2 months ago

      It’s e2e encrypted. Although, as I noticed, the key is just a short pin, unless you use password, but the recipient might not use it and your messages are just as secure as your recipient.

      • rumschlumpel@feddit.org
        link
        fedilink
        English
        arrow-up
        21
        ·
        2 months ago

        The PIN isn’t actually the encryption key, it’s just a display lock for the local client. But if whoever wants to read your messages has physical access to your phone and already bypassed the normal android lockscreen, you’re fucked anyway.

      • Dionysus@leminal.space
        link
        fedilink
        English
        arrow-up
        10
        ·
        2 months ago

        The other party is always the weakest link.

        But also signal’s pins are a little more complicated than that, but you’re right, switch to a passphrase.

        Plus side, even if signal themselves edited the secure enclave, the world would need a new client pushed and probably notice something was off.

        The way signal’s encryption works is really an art in paranoia.

        • plyth@feddit.org
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          3
          ·
          2 months ago

          the world would need a new client pushed and probably notice something was off.

          Not if the US have the support of Google.

              • Vincent@feddit.nl
                link
                fedilink
                English
                arrow-up
                2
                ·
                2 months ago

                Because there will always people running Signal from a different source, and only one of them is sufficient to notice the server has been tampered with.

                (And I’m not sure if they have reproducible builds yet, but if they do, people can also verify that even the Google Play-provided APK does or doesn’t match the published source code.)

                • plyth@feddit.org
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  2 months ago

                  notice the server has been tampered with.

                  Which server?

                  doesn’t match the published source code

                  People don’t control their phone. There is no way of knowing if the installed app is the one that is running.

      • Ricaz@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 months ago

        Facebook Messenger also claims to be end-to-end encrypted… There’s literally no way of knowing if they can decrypt your messages.

        The only way to know is to host it yourself and preferably use post-quantum secure encryption.

      • poVoq@slrpnk.netM
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        4
        ·
        2 months ago

        And? That doesn’t help at all if the US government decides to force Signal to stop servicing Denmark.

        • rumschlumpel@feddit.org
          link
          fedilink
          English
          arrow-up
          13
          arrow-down
          1
          ·
          2 months ago

          It helps in that they still can’t read your messages. The EU is likely to make e2e messaging illegal before the USA cuts access.

          • poVoq@slrpnk.netM
            link
            fedilink
            English
            arrow-up
            5
            arrow-down
            2
            ·
            2 months ago

            You can’t really make e2ee messaging illegal, at least it is impossible to enforce with decentralized open-source messengers.

            It is much more likely that the US will mess with Signal, than that you will stop being able to use an e2ee messenger like XMPP, which is just as secure as Signal regarding the e2e encryption.

            • rumschlumpel@feddit.org
              link
              fedilink
              English
              arrow-up
              10
              ·
              2 months ago

              The issue is that it’s already pretty hard to convince people to use something easy like Signal, most people just don’t care enough for something “complicated” like XMPP-based messengers, especially if mainstream app stores had to stop letting EU-based users install messengers with these features.

              • poVoq@slrpnk.netM
                link
                fedilink
                English
                arrow-up
                3
                arrow-down
                6
                ·
                2 months ago

                Well, yes. But when it comes to digital independence Signal isn’t better than WhatsApp. At least recommend something like Threema if you think the much better alternatives are too hard.

                • rumschlumpel@feddit.org
                  link
                  fedilink
                  English
                  arrow-up
                  16
                  ·
                  2 months ago

                  Except Meta fully owns the WhatsApp metadata, and frankly Signal is a lot more trustworthy about its e2e implementation being actually, in practice, secure.

            • plyth@feddit.org
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 months ago

              at least it is impossible to enforce with decentralized open-source messengers.

              All you need is a central registry where licensed messengers register their e2ee connections. Then network providers only have to report all ip addresses with connections that are not on that list.

              Impossible with VPNs, but politicians have already announced their desire to make them illegal.

              • poVoq@slrpnk.netM
                link
                fedilink
                English
                arrow-up
                2
                arrow-down
                1
                ·
                2 months ago

                What? You are not making much sense. What is a “e2ee connection”?

                • plyth@feddit.org
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  2 months ago

                  An encrypted connection between two endpoints.That’s required for “decentralized open-source messengers”.

                  Currently it’s impossible to prevent because of all the encrypted video calls of the Meta messengers and similar connections between endpoints.

                  If those video streams are marked then it is known which endpoints use software that evades surveillance.

  • copacetic@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    1
    ·
    2 months ago

    Is it about the geopolitics or did SaveSocial’s marketing campaign “digital independence day” last weekend (look for #DIday and #DIDit) also contribute? I’m not sure how visible that was internationally or if it was just a German campaign.

    • freeman@feddit.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      2 months ago

      DID stemms from a Talk AG the CCC this year. It is a month old and was held in german. I think this isnt DIDs work here

  • architect@thelemmy.club
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    2 months ago

    The people that are orchestrating the takeover of Greenland literally owns that fucking platform you fucking idiots.

    Does no one in the west have a fucking brain?

    • GarbadgeGoober@feddit.org
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 months ago

      Perfect is the enemy of the good.

      Just see it as a first step. Signal is still better than WhatsApp being owned by Meta. If we get more people of WhatsApp, in the future there might be more European alternatives.

      There are no big European alternatives the majority of people are willing to switch.

      I got rid of WhatsApp last year myself and could only convince 8 people to use Signal. I tried Threema and Matrix, but most normal people are not willing to do this and don’t care they give up their data and so on…

      • kaulquappus@feddit.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        Thank you for contributing to the critical mass o7

        I joined Signal for the very few people in my contact list that use it, but I am holding out for the further establishment / gaining traction of a non-walled-garden solution before I start evangelizing Signal… So that I don’t get more people to switch, and then after a few months/years have to try to get them to switch again e.g. to a Matrix solution (and once again losing my chat history in the process).

  • vga@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 months ago

    From one american service to another american service? Good job m’Danes, that’ll show’em.

    Less flippantly though, Signal is a better american service, and incremental improvements are good too.