@inaruck ich hab' Leute konsequent auf #XMPP+#OMEMO migriert, weil @signalapp zentralisiert und unter #CloudAct fällt, folglich inhärent unsicher.
- Ich empfehle @monocles / #monoclesChat
@inaruck ich hab' Leute konsequent auf #XMPP+#OMEMO migriert, weil @signalapp zentralisiert und unter #CloudAct fällt, folglich inhärent unsicher.
@Avitus @lispi314 @lauren THE REQUIREMENT FOR A #PhoneNumber BY @signalapp IS LITERALLY THE PROBLEM!
If you gonna say "JuSt GeT aN iMpOrTeD #SIM / #eSIM!" then you obviously expect people to have way more #financial means and #TechLiteracy than is needed to get absolute N0obs setup withb#XMPP+#OMEMO and pay for @monocles / #monoclesChat!
Addendum: Funzt wieder. Danke an @Natanox !
Weiß irgendwer warum der #Jabber / #XMPP-#Server vom #CCC / @CCC nicht unter dessen .onion
- Domain via @torproject / #Tor erreichbar ist?
https://infosec.space/@kkarhan/113974956128605484
Ist das nen #Bug von @monocles / #monoclesChat, @guardianproject #Orbot oder warum 404'd das?
@ck @sven222 @kuketzblog problem is @signalapp is a #Centralized, #Proprietary, #SingleVendor & #SingleProvider solution that falls under #CloudAct and demands #PII in the form of #PhoneNumbers.
Cuz all the #advertising of Signal is close to #TrustMeBro and I'd not trust in @Mer__edith to risk jail for users!
@tauon Actually, you want to use a truly secure as in real #E2EE solution like #XMPP+#OMEMO as in @monocles / #monoclesChat and @gajim /#gajim...
@dansup well, @signalapp too is #proprietary and #centralized and peddles a #Cryptocurrency #Scamcoin named #MobileCoin:
https://www.youtube.com/watch?v=tJoO2uWrX1M
Use #XMPP+#OMEMO (i.e. @monocles / #monoclesChat & @gajim / #gajim) instead!
https://monocles.social/@monocles/113925173206088469
No #PII (like a #PhoneNumber!) required...
https://docs.monocles.eu/account/account/
Truly #decentralized, #OpenSource, #MultiVendor & #MultiProvider 1 with real #E2EE using #SelfCustody of all the keys!
@mastodonmigration Obligatory reminder that #Signal relies on a centralized and proprietary server, and does not belong here.
Users of #WhatsApp #Telegram #Discord #Signal and #Threema etc should use #XMPP instead, which is #FreeSoftware and federated.
Users - check out #Quicksy (Android and iOS), #Prav, #Conversations, #Cheogram, #MonoclesChat, #Gajim, #Movim, #Monal...
Self-hosters, check out #Snikket.
Learn more with this user's guide -
https://contrapunctus.codeberg.page/the-quick-and-easy-guide-to-xmpp.html
News
:
For the global switch day monocles chat will be available for free in the Playstore (01.02. - 07.02.):
https://play.google.com/store/apps/details?id=eu.monocles.chat
Take your chance and switch to the XMPP network
@blog @sylv_a @viennawriter @signalapp dann doch lieber €2 p.m. für @monocles / #monoclesStarter oder einfach #monoclesChat mit nem XMPP-Server nutzen...
Alternativ zu #XMPP+#OMEMO gibt's auch noch @delta / #deltaChat, welches #eMail nutzt.
No problem:
I could go on all night, so please shove that #TechPopulism somewhere the sun doesn't shine!
"[...] easy to use solutions that are at the same time private and secure. [...]"
It is easier, faster, cheaper and overall simpler to get someone setup with #XMPP + #OMEMO espechally if they don't have a #PhoneNumber and/or #ID to acquire a #SIM.
And if you go and say, "Just buy a [insert country here] [e]SIM!" and expect #TechIlliterates without a #CreditCard, #PayPal or other means of #OnlinePayment to fiddle around with some #eSIM if not having to get some #eSIMcard because they can only afford to maintain one SIM and can't spend triple-digits on a new devices then you completely missed the point!
It's not that I expect anyone to get #TechLiterate within minutes, but similar to setting up a cordless DECT phone it's something one has to do once in 5 years and just have them put the password in a safe spot to retain...
Point is that #Signal #WontFix their setup and that was evidently clear even before @Mer__edith succeeded #MoxieMarlinspike: Their entire operation has a distinct #CryptoAG stench as it's an #unsustainable #VCmoneyBurning party!
A counterexample on how this could've been done are #Tor, #eMail and other truly #OpenSource as in #MultiVendor & #MultiProvider standards.
NOTHING compells Signal to demand PII, run a #Shitcoin #Scam aka. #MobileCoin that even seasoned #TechLiterates and #CryptoBros can't setup properly, and in fact Signal using phone numbers makes it trivial to discriminate against users and easier for them to identify them!
If my reasoning didn't resonate with you, then try helping i.e. undocumented migrants aka. "#SansPapier|s" to get setup with it without violating laws and/or ToS and/or needing an imported SIM which I'm shure most folks don't have on hand!
Whereas it's trivial to get people setup on one of many XMPP servers I've personally tested!
AFAIK Signal doesn't even have an #OnionService / .onion
for their Website, much less any #API enpoints to use it with!
You're free to also provide evidence and supporting data to your arguments, rather then neighsaying against proven to be more secure and reliable [by virtue of decentralization] options like XMPP+OMEMO and/or #PGP/MIME.
The proper fix is to actually assess the situation and acknowledge the risks and limitations as well as the very nature of communications, which means upgrading later is exponentially more painful, thus getting people properly setup once is way easier.
Speaking of #monocles: That business is at least #sustainable because it's funded by users (€2 p.m.) which they can pay anonymously
@rysiek @kkarhan @agturcz An awful lot of people say they've used #XMPP "a while back". But they're often unaware of the best of XMPP, and have an unfairly negative view of it.
Did you happen to try...
...#Snikket for hosting?
https://snikket.org
...apps like #Quicksy and #Prav which use phone numbers for easy onboarding, same as #Signal #WhatsApp or #Telegram?
https://quicksy.im
https://prav.app
...featureful clients like #Cheogram #MonoclesChat #Gajim #Movim etc?
@rysiek @agturcz that's not how you fix #TechIlliteracy, espechally since things changed for the better.
@monocles / #monoclesChat & @gajim / #gajim are quite easy, whereas @signalapp / #Signal demands #PII in the form of a #Phone number which is more often than not not legally obtainable without "#KYC" aka. "forced #SelfDoxxing" all whilst being an extremely #centralized, #SingleVendor & #SingleProvider solution that falls under #CloudAct ant thus cannot adhere to #GDPR & #BDSG!
"JuSt UsE sIgNaL !"
won't fix #TechIlliteracy but rather provide false sense of security to #TechIlliterates when the correct solution is to teach proper #TechLiteracy like @cryptoparty@chaos.social / @cryptoparty@mastodon.earth / #CryptoParty does...Otherwise we'd only perpetuate the #Enshittification-#Lifecycle as has happened with #AIM, #ICQ, #BBM and so many more...
If #Signal and @Mer__edith actually cared, they would've setup their system truly decentralized as an #OnionService over @torproject / #Tor!
@moh_kohn except @signalapp too is a #centralized, #SingleVendir & #SingleProvider solution that fully falls under #CliudAct and thus CANNOT comply with #GDPR & #BDSG as a matter of principle since this digital rquivalent of #ExtraordinaryRendition is inherently incompatible!
@monocles / #monoclesChat, @gajim / #gajim & @delta / #deltaChat, @thunderbird / #Thunderbird do support that!
@MartinaNeumayer @VixenBlu @thelusciouslibra Re: #eMail and #Chat, I'd still recommend to stick with #SelfCustody, and use @monocles #monoclesMail, #monoclesChat , @delta #deltaChat and many other options.
- One nifty option for #VideoTelephony one may want to look at is #WebCall:
https://timur.mobi/webcall/
I got pointed at it since it's very easy to use and unlike #JitsiMeet they don't demand #PII for registration or record stuff and one can #SelfHost it too...
@zeank @MastoDenunzianten Auch sind all.dies #Merting-#Versprechen oder auch #Lügen, denn woher soll mensch verifizieren können, dass das was #Threeema behauptet auch stimmt?
Bei #XMPP+#OMEMO (z.B. @monocles / #monoclesChat & @gajim / #Gajim) & #PGP/MIME (z.B @delta / #DeltaChat) kann ich im Zweifelsfalle #SelfHosting mit nem #RaspberryPi im Kleiderschrank machen.
Angriffe auf dezentrale & offene, #MultiVendor & #MultiProvider-Standards funktionieren nicht skalierbar!
@zdl @evacide that any the fact that @signalapp is incorportated in the #USA, making them susceptible to #GDPR & #BDSG-incompatible #cyberfacist bs like #CloudAct.
Remember: #KYC IS THE ILLICIT ACTIVITY when it comes to #Communication!
Compare that to @monocles / #monoclesChat which don't demand any PII or KYC and allow people to pay for their services with #Monero and #CashByMail besides #SEPA #WireTransfer, #Stripe & #PayPal whilst supporting both decentralization (#XMPP is not a #SingleVendor / #SingleProvider solution!), implementing real #SelfCustody (#OMEMO, #OTR & #PGP is supported out of the box) for all the keys, and proper #Anonymitiy (using @torproject / #Tor & @guardianproject #Orbot for #privacy), so in case they ever get a duely sumitted warrant by a court they'd have to comply with, they'll most likely have no data whatsoever on clients that could allow identification.
Also having no PII is a matter of reducing #liability in the sense of #DataProtection: All data requested and by #monocles is the bare minimum mandated for #accounting (i.e. only linking a payment like a #TxID / Transaction-ID to an account and then adding up validity/activation period).
@bastibayer nein, weil #Threema ne #proprietär|e +#SingleVendor & #SingleProvider) Lösung ohne #SelfCustody der Keys ist, und damit inhärent unsicher (#KerckhoffsPrinciple)...
Meine Empfehlung ist @monocles / #monoclesChat & @gajim für #XMPP+#OMEMO, ducht gefolgt.von @delta / #deltaChat für echte #E2EE!
I just saw that #Conversations and #monocleschat seem to be currently available for free in the Google Play Store.
Thanks @daniel and @monocles for this great offer.
This might be a good chance to onboard Google Play users to #XMPP.
But do not forget: You can also use #fdroid or #Codeberg to get those apps.