Hacker Newsnew | past | comments | ask | show | jobs | submit | writtenone's commentslogin


Fwiw, the FBI use Signal regularly, and it's approved for some specific use cases. Don't ask how I know ;)

There are ways to ascertain how and when a person is using their device by analyzing Signal's metadata, then build a predictive model based on months of daily usage to infer when they're most likely about to pick up their phone.

Delta Chat is years behind Signal's protections, and its claims of "zero metadata" are straight up lies. SimpleX has at least four remote execution zero days that I'm aware of, all relating to media processing. I told Evgeny to make the blur effect actually hash the image instead of acting like an overlay, but I was repeatedly ignored before being set as an "observer" role in the SimpleX Public Group.


Sources about Signal and SimpleX?


Look into SimpleX Chat. It's like Telegram but with trustworthy encryption that's always-on, multiple profiles, and the servers are interchangeable so if one or two go down you can just switch them out.

Evgeny is a venture capitalist (ew) but the product is solid and they've published two TrailOfBits audits with a third completed and awaiting publication by TOB


Having used Matrix for almost a decade, it's hot garbage.

Sync is barely working, "unable to decrypt" still exists, the encryption is flawed [0] and the whole thing is effectively just Element and everyone else follows their lead.

[0]: https://soatok.blog/2026/02/17/cryptographic-issues-in-matri...


About the post you linked, see [1] and [2], which makes me question both whether that is an actual vulnerability (Signal, the messenger recommended by the author, also didn't have that check, and it's addition is absent from release notes and CVEs) and whether the post was made in good faith (the check was added to libsignal on the same day that the author disclosed the vulnerability to Matrix, which can be a coincidence, but doesn't seem likely given that the code has been there for years).

Can't speak about the other issues, I haven't had those but I barely use it. Based on comments, it's clear they exist or have existed for quite some time.

[1] https://blog.erinshepherd.net/2026/02/non-contributory-keys-...

[2] https://matrix.org/blog/2026/02/analysis-of-reported-issues-...


> About the post you linked, see [1] and [2], which makes me question both whether that is an actual vulnerability (Signal, the messenger recommended by the author, also didn't have that check, and it's addition is absent from release notes and CVEs)

I've edited the above linked post several times to make this clearer, but people still keep linking Matrix's flawed response as if it actually addressed the issue. It does not.

The issue is not as simple as "did the check exist? [y/n]". There are actually two issues:

1. Did the check exist? [y/n]

2. Did the group key agreement protocol fall to shit if the check was omitted? [y/n]

Matrix was (n, y) due to how Megolm manages keys in group contexts. Signal was (n, n) due to their protocol design.

Matrix tried to defend point 1 when the blog post was about both 1 and 2.

(Post-Quantum MLS, for comparison, would also have been impervious to this issue due to how KEMs work. Another point in favor of MLS adoption.)

> and whether the post was made in good faith (the check was added to libsignal on the same day that the author disclosed the vulnerability to Matrix, which can be a coincidence, but doesn't seem likely given that the code has been there for years).

Even if you assume the worst possible interpretation of this coincidence (which, sure, you're free to if you want-- you would be wrong if you did, of course): What does it even matter?

Like, what is the notion of "good faith" that's even necessary for someone to do independent security research and publish criticism of the cryptography used by a software project that's being propped up by EU sovereignty movements?

In my opinion, this is a stupid and vacuous framing.

Signal omitting the check didn't harm Signal's confidentiality. Matrix omitting the check demonstrably did.

---

Also, if you're going to decry my blog post for not enumerating unrelated security bugs (n.b., the blog post was about Matrix, not Signal, so why would I talk about Signal's code in that post???), be aware that I reported non-cryptographic bugs to Element (Matrix client) and Conversations (XMPP client) around the same time. Only XMPP actually credited me with any fixes.

https://gultsch.social/@daniel/116125064866469085


Element in particular is embarrassingly bad. (Consistently, for the past 5 years, through the present)


Now if only it would come with Linux instead of MacOS!

Apple's software holds the hardware back, and it's ugly (especially liquid glass!)


Are there any XMPP clients with the UX and privacy of Signal?

All of them seem to look like they're from the 00s!



Thanks! Any good Android clients? "Conversations" seems to be the best and it's nowhere near the polish of Signal & Co. crashes often, UX is clunky, family will never stick with it.


As a counterpoint, I use conversations literally every day, and cannot recall the last time it crashed. My partner and kids have used it for at least the last 7 or 8 years to communicate with me and each other. I don't claim there are no issues, but "crashes often" isn't something I would expect to hear about it.

I don't find the UX to be clunky either, but I acknowledge that could just be my familiarity with the program, so I would leave that for others to dispute.


What makes you think that? I haven't experienced, or heard of people having frequent crashes. Me and my family also use it to communicate to each other with no issues regarding the UI.


Crashes?!? I've been using Conversations for a long time and can't remember any crashes. Something must be wrong with your setup.

For me, the bigger problem is that I was unable to get OMEMO + Apple Clients working properly. I think OMEMO 1 has some design flaws and hope that OMEMO 2 will fix those.


I ran into this exact problem. I needed to fork Conversations to add a lot of polish. My fork is definitely improved but still has a few rough edges I'm chipping away at.


Do you plan on contributing your improvements upstream, or is that not feasible for some reason?


Conversations doesn't crash at all for me.

And I moved to Conversations because I needed a client that wasn't as crashy as Xabber was for me.


Seriously? I'm not saying it's the best app around but the family uses Conversations and we never really have any real issues. Even for the septuagenarians in the family I just set it up once like 7 years ago and they still use it all the same.


exe.dev is NOT open source. Funny


I feel like if you can ignore the bitcoin-bros, Nostr is a better, more lightweight design that doesn't suffer from centralized (localized) shutdowns.


From 1984: "Every record has been destroyed or falsified, every book rewritten, every picture has been repainted, every statue and street building has been renamed, every date has been altered. And the process is continuing day by day and minute by minute. History has stopped. Nothing exists except an endless present in which the Party is always right."


Support your local shadow library: https://annas-archive.pk/donate


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: