Skip to content

Signal – an ethical replacement for WhatsApp

Technology
146 94 0
  • Signal is not capable of SMS and quite a lot of people still use it.

    yes, i know SMS isn't secure at all. but if the option is "keep in touch with close family" or "don't keep in touch" they will probably choose the former if they want to keep that.

    I would rather SMS than use WhatsApp. But even then if my family is far away, why am texting them at all very often? With the time zone differences I'll call or email, or nothing. It's weird how people got along just fine with letters that took weeks and suddenly we now need instant communication for some reason?

  • Wish more of my contact list would switch over to Signal. It's nearly the same. I don't see why it's so hard for some people to just start using Signal instead of WhatsApp.

    Oh well.

    I tried switching my family over, but being unable to install it on a second device or tablet was a deal breaker.

  • This post did not contain any content.

    I can't call ethical an app that relies on Electron.

  • The exit plan from WhatsApp is quite simple. Start by installing Signal and setting it up – it takes only a couple of minutes. Then, resume any WhatsApp conversations on Signal if that person is already a Signal user. If they are not, then switch to regular text messaging and gently suggest to that person to switch over to Signal.

    Sadly for me, this doesn't really work for some relatives as

    • They live abroad and the cost of sending text messages abroad is not insignificant
    • Some are so tech un-savvy that even installing a new app by themselves is too much.

    All I can do for those relatives is to leave WhatsApp installed but take away basically every permission I can, including running in the background.

    How did they get WhatsApp installed? Is a FaceTime or other video option available? Never give up, never surrender

  • This post did not contain any content.

    I wish I could do this, but trying to convince people to ditch an app they've never had problems with and where they all have their family, friends, work groups and school groups already mashed together, how do you convince them? Its not even about me convincing my friends or family, its about everyone else doing the same and when everyone has so many contacts in WhatsApp, that number starts to snowball real quick. Its just not feasible to try and explain this to someone who literally doesn't care. I mean even though I myself know what Meta is and how Zuck is complete asshole, I still can't switch off of WhatsApp because nobody I know is on Signal and I'd just be alone there. What's the point? WhatsApp is pretty much the first app anyone installs on their phone (regardless of platform), they're not gonna switch now.

  • I would rather SMS than use WhatsApp. But even then if my family is far away, why am texting them at all very often? With the time zone differences I'll call or email, or nothing. It's weird how people got along just fine with letters that took weeks and suddenly we now need instant communication for some reason?

    How is that weird? You can be fine with suboptimal stuff, and recognize it's suboptimal. Some people like their relatives and wished they could talk together more readily. Letters were just the fastest (while economical) method of doing that for a while.

  • Could you explain a bit? I see main issue with Signal (though I'm not an expert, and they're not strictly related to security): it's centralized (and the server isn't even open-source).

    The question is also a lot about your threat model right?

    The encryption being crap really does not depend on the threat model. Sure, in some threat models you may not need e2ee at all but in that case, what's wrong with WhatsApp?

    The issue with XMPP is that security really was an afterthought. Not only is e2ee an optional extension, but there are actually 2 incompatible extensions, each with multiple versions. Then you have some clients not implementing either, some clients implementing the older, less secure one. Some implement the newer one but older version of the spec with known issues. And of course, the few clients that implement it well become incompatible with other clients that don't if you enable e2ee, so it is disabled by default.

    That is all before you start looking into security audits or metadata harvesting.

  • I can't call ethical an app that relies on Electron.

    Weird goalpost but Ok

  • I wish I could do this, but trying to convince people to ditch an app they've never had problems with and where they all have their family, friends, work groups and school groups already mashed together, how do you convince them? Its not even about me convincing my friends or family, its about everyone else doing the same and when everyone has so many contacts in WhatsApp, that number starts to snowball real quick. Its just not feasible to try and explain this to someone who literally doesn't care. I mean even though I myself know what Meta is and how Zuck is complete asshole, I still can't switch off of WhatsApp because nobody I know is on Signal and I'd just be alone there. What's the point? WhatsApp is pretty much the first app anyone installs on their phone (regardless of platform), they're not gonna switch now.

    Yep. I know the details. I'm tech savvy enough, but I use what my contacts use, and I'm not leaving WhatsApp. Same goes for youtube. The content I consume is there. There is no suitable alternative until the content creators switch. It's not really about the technology at all.

  • I would rather SMS than use WhatsApp. But even then if my family is far away, why am texting them at all very often? With the time zone differences I'll call or email, or nothing. It's weird how people got along just fine with letters that took weeks and suddenly we now need instant communication for some reason?

    we used to be fine with candles and stinky lanterns filled with perfectly good kerosene too. who tf needs electricity? 🤨

    on the topic of family connection, I can't speak to your family experience. only my own. and our family group chat is pretty damn active.

  • I wish I could do this, but trying to convince people to ditch an app they've never had problems with and where they all have their family, friends, work groups and school groups already mashed together, how do you convince them? Its not even about me convincing my friends or family, its about everyone else doing the same and when everyone has so many contacts in WhatsApp, that number starts to snowball real quick. Its just not feasible to try and explain this to someone who literally doesn't care. I mean even though I myself know what Meta is and how Zuck is complete asshole, I still can't switch off of WhatsApp because nobody I know is on Signal and I'd just be alone there. What's the point? WhatsApp is pretty much the first app anyone installs on their phone (regardless of platform), they're not gonna switch now.

    Just ditch WhatsApp. Don't give in to social pressure to install malware on your phone

  • Wish more of my contact list would switch over to Signal. It's nearly the same. I don't see why it's so hard for some people to just start using Signal instead of WhatsApp.

    Oh well.

    "But why, everyone is on WhatsApp", and also a lot of businesses.
    "Privacy? I've got nothing to hide, what are they gonna do eith my info?"

  • https://blog.cryptographyengineering.com/2024/08/25/telegram-is-not-really-an-encrypted-messaging-app/

    To get encryption one must start a "secret chat". It's an opt-in! Regular users will not even know the option exists, that's how well hidden it is.

    Regular chats? Plainly readable on the server.

    The main differences between a regular chat and a secret chat in Telegram, from a security standpoint, are:

    1. End-to-End Encryption
      • Regular Chat: Messages are encrypted client-server-server-client, meaning Telegram servers can technically access the content.
      • Secret Chat: Messages are end-to-end encrypted, so only you and the recipient can read them. Not even Telegram can decrypt them.

    2. Cloud Storage
      • Regular Chat: Messages are stored in the cloud. You can access them from any device logged into your Telegram account.
      • Secret Chat: Messages are device-specific and not stored in the cloud. They can only be read on the devices where the secret chat was initiated.

    3. Self-Destruct Timer
      • Regular Chat: No self-destruct functionality.
      • Secret Chat: You can set a self-destruct timer for messages after they’re read.

    4. Forwarding
      • Regular Chat: Messages can be freely forwarded.
      • Secret Chat: Messages cannot be forwarded.

    5. Screenshots
      • Regular Chat: Screenshots are not restricted or notified.
      • Secret Chat: Telegram tries to prevent or notify about screenshots (depends on the OS).

    Summary:

    Use secret chats if you need maximum privacy, as they’re more secure and don’t rely on Telegram’s servers to store message content. However, they’re less convenient because you lose cloud sync and multi-device support.

  • we used to be fine with candles and stinky lanterns filled with perfectly good kerosene too. who tf needs electricity? 🤨

    on the topic of family connection, I can't speak to your family experience. only my own. and our family group chat is pretty damn active.

    Did you get everyone to settle on the same thing, like Signal? We are spread out over about 8 countries, and with all the different phone numbers and plans, we use various methods, with several of us on Signal. Some on whatsapp, some on messenger. So we are not coordinated enough for a group chat. Which is fine, I dont really need to know everything all the time, we catch up when can, or get into small video chats occasionally. Luckily we do tend to physically see each other somewhat frequently.

  • Weird goalpost but Ok

    I think it is more of a hill than a goalpost.

  • That’s not even what it is lol.

    And as the other commenter alluded to, defaults matter. You’re not replacing the thing everyone is already using by pitching “here’s an alternative that is better in ways which don’t affect your usage at all, and also you have to dig into the settings to turn off the optional daily popups”

    They are monthly not daily popups. They are daily at the start kust to make sure you memorize your PIN, then they peter off.

    However if you ignore a monthly one then it doesn't disturb you until the next monthly reminder. What is the point of a PIN if it can be ignored?

  • There is threema, a Swiss messenger that gained some popularity earlier since they had end to end encryption before whatsapp.

    Unfortunately the source code is not open (even though they do get annual audits with public reports), and the client costs 3 EUR or something (once).

    Unfortunately the source code is not open

    Wrong.

  • Did you get everyone to settle on the same thing, like Signal? We are spread out over about 8 countries, and with all the different phone numbers and plans, we use various methods, with several of us on Signal. Some on whatsapp, some on messenger. So we are not coordinated enough for a group chat. Which is fine, I dont really need to know everything all the time, we catch up when can, or get into small video chats occasionally. Luckily we do tend to physically see each other somewhat frequently.

    no we are all on different platforms. half are on android and half are on apple which is irritating. so sadly the sms is our best tool to hit everyone at the same time with any urgency.

  • This post did not contain any content.

    I don't believe in signal.

  • I wish I could do this, but trying to convince people to ditch an app they've never had problems with and where they all have their family, friends, work groups and school groups already mashed together, how do you convince them? Its not even about me convincing my friends or family, its about everyone else doing the same and when everyone has so many contacts in WhatsApp, that number starts to snowball real quick. Its just not feasible to try and explain this to someone who literally doesn't care. I mean even though I myself know what Meta is and how Zuck is complete asshole, I still can't switch off of WhatsApp because nobody I know is on Signal and I'd just be alone there. What's the point? WhatsApp is pretty much the first app anyone installs on their phone (regardless of platform), they're not gonna switch now.

    Well, just an anecdote:

    I simply deleted my WhatsApp and moved to signal. Just did it.

    People installed the app, at least the ones that cared about staying in touch. Which was most everyone I cared about staying in touch with. A few of my friend groups also moved the group chat to signal, though all of them do have other ones with the people who didn’t care enough to move too, but I hear it isn’t that big a deal, they had multiple groups before and will have in future, doesn’t really feel like any extra hassle they say.

    It’s been fine. No problems. I’ve had more trouble trying to explain to my extended family why I’m no longer posting on instagram. Those I never had in WhatsApp either back in the day, so they “stayed in touch” by watching my pictures I suppose. But I just consistently tell people they can reach me always via signal or plain old sms.

    I guess the biggest thing to be scared about would be fomo for most, but I don’t really care enough, I’ve got so much going on already that it’s more of a blessing that I don’t have to be involved in every conversation or meme sharing or whatever.

    It really gets so easy after simply switching. Just do it and that’s that. The people worth anything come with you, it’s just another app and another group chat or personal chat. Most already have discord and the meta messenger whatever its name is these days anyway. I know zero people with only one messenger/chat app and unsplintered groups across them. It’s not a big chore, and if it is, there’s always sms.

  • 77 Stimmen
    21 Beiträge
    0 Aufrufe
    G
    Because the trillions is the point.. Not security.
  • Is Google about to destroy the web?

    Technology technology
    65
    1
    193 Stimmen
    65 Beiträge
    5 Aufrufe
    S
    Or validating source, making sure it isn't AI content which usually regurgitates the same talking points. Homogenizing the entire query and removing actual information variance of personal experience.
  • 456 Stimmen
    48 Beiträge
    13 Aufrufe
    L
    That's good to know, thanks.
  • France considers requiring Musk’s X to verify users’ age

    Technology technology
    20
    1
    142 Stimmen
    20 Beiträge
    9 Aufrufe
    C
    TBH, age verification services exist. If it becomes law, integrating them shouldn't be more difficult than integrating a OIDC login. So everyone should be able to do it. Depending on these services, you might not even need to give a name, or, because they are separate entities, don't give your name to the platform using them. Other parts of regulation are more difficult. Like these "upload filters" that need to figure out if something shared via a service is violating any copyright before it is made available.
  • Building a slow web

    Technology technology
    37
    1
    175 Stimmen
    37 Beiträge
    16 Aufrufe
    I
    Realistically, you don't need security, NAT alone is enough since the packets have nowhere to go without port forwarding. But IF you really want to build front end security here is my plan. ISP bridge -> WAN port of openwrt capable router with DSA supported switch (that is almost all of them) Set all ports of the switch to VLAN mirroring mode bridge WAN and LAN sides Fail2Ban IP block list in the bridge LAN PORT 1 toward -> OpenWRT running inside Proxmox LXC (NAT lives here) -> top of rack switch LAN PORT 2 toward -> Snort IDS LAN PORT 3 toward -> combined honeypot and traffic analyzer Port 2&3 detect malicious internet hosts and add them to the block list (and then multiple other openwrt LXCs running many many VPN ports as alternative gateways, I switch LAN host's internet address by changing their default gateway) I run no internal VLAN, all one LAN because convenience is more important than security in my case.
  • 158 Stimmen
    79 Beiträge
    5 Aufrufe
    M
    But they did give! They did not chose to deny and not have pizza.
  • 31 Stimmen
    1 Beiträge
    1 Aufrufe
    Niemand hat geantwortet
  • 0 Stimmen
    6 Beiträge
    4 Aufrufe
    P
    Outlook.... Ok Pretty solid Bahaha hahahahaha Sorry. Outlook is a lot of things. "Gooey crap" would be one way to describe it, but "solid"? Yeah, no. Gmail is (well, was) pretty solid. There are a lot of other webmail providers out there, including self hosted options and most are pretty solid, yeah. Outlook, though? It's a shit show, it's annoying. Do you love me? Please love me, please give feedback, please give feedback again, please look at this, hey am I the best? Am I.. STFU YOU PIECE OF CRAP! Can you PLEASE just let me do my email without being an attention whore every hour? Even down to the basics. Back button? "What is that? Never heard of it, can't go back to the message I just was on because I'm Microsoft software and so half baked." Having two tabs open? "Oh noes, now I get scawed, now I don't know how to manage sessions anymore, better just sign you out everywhere." What is it with Microsoft and not being able to do something basic as sessions normal? I'm not even asking for good, definitely not "awesome", just normal, and that is already too much to ask. Try running it in Firefox! I'm sure it's totally not on purpose, just "oopsie woopsie poopsie" accidentally bwoken. Maybe it's working again today, who knows, tomorrow it'll be broken again. I run everything on Firefox except the Microsoft sites, they have to be in chrome because fuck you, that's why. Seriously, I can't take any Microsoft software seriously at this point, and all of it is on its way out in our company, I'm making sure of that