Beehaw
  • Communities
  • Create Post
  • search
    Search
  • Login
  • Sign Up
RecycledAnonymous ( RecycledAnonymous@lemmy.ml )  to Privacy@lemmy.ml · 4 years ago

Thoughts on Simplex Chat? Is It Secure? Is it the new signal?

simplex.chat

external-link
message-square
13
link
fedilink
  • cross-posted to:
  • privacy@lemmy.ml
  • cpo_announcements@crazypeople.online
  • simplex@lemmy.ml
  • privacy@lemmy.ml
  • technologie@jlai.lu
  • hackernews@derp.foo
  • technews@radiation.party
  • opensource@lemmy.ml
  • privacy@lemmy.ml
43
external-link

Thoughts on Simplex Chat? Is It Secure? Is it the new signal?

simplex.chat

RecycledAnonymous ( RecycledAnonymous@lemmy.ml )  to Privacy@lemmy.ml · 4 years ago
message-square
13
link
fedilink
  • cross-posted to:
  • privacy@lemmy.ml
  • cpo_announcements@crazypeople.online
  • simplex@lemmy.ml
  • privacy@lemmy.ml
  • technologie@jlai.lu
  • hackernews@derp.foo
  • technews@radiation.party
  • opensource@lemmy.ml
  • privacy@lemmy.ml
SimpleX Chat: private and secure messenger without any user IDs (not even random)
simplex.chat
external-link
SimpleX Chat - a private and encrypted messenger without any user IDs (not even random ones)! Make a private connection via link / QR code to send messages and make calls.
alert-triangle
You must log in or # to comment.
  • bkrl ( bkrl@lemmy.ml ) 
    link
    fedilink
    arrow-up
    12
    ·
    4 years ago

    No spam and no identifiers (phone number, email, ids, etc.) by design. Local encrypted sign-in. Your whole chat system-in-a-file .zip. Disposal, one-time, connections. This is awesome!

    • Jacob Gonzales 🇺🇸 ( jacobgonzales20@fosstodon.org ) 
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      4 years ago

      deleted by creator

      • kendbi ( kendbi@szmer.info ) 
        link
        fedilink
        arrow-up
        7
        ·
        4 years ago

        They actually had security audit done by Trail of bits. Here’s a link to their reddit post

  • Lynda ( Lynda@lemmy.ml ) 
    link
    fedilink
    arrow-up
    7
    ·
    4 years ago

    Having unique one-time (non-reusable) invite ID is great.

    The wat SimpleX uses one-way queues, and then distributes those queues among servers offers a way to mitigate communication correlation (if the servers are independent and won’t collude). Or you can just self host and not worry. Self hosting an onion service is easy.

    Running SimpleX through a tor proxy (or VPN) offers even more advantages (if you think you need them).

    Perhaps the only downside is SimpleX still controls who gets to be a public server (anyone can self host or offer servers, but they won’t be integrated). I have no way of knowing if the servers are owned by a single entity. This part is not “open”.

  • bkrl ( bkrl@lemmy.ml ) 
    link
    fedilink
    arrow-up
    7
    ·
    edit-2
    4 years ago

    This is not a new Signal, this makes Signal obsolete.

    • jackalope ( jackalope@lemmy.ml ) 
      link
      fedilink
      arrow-up
      4
      ·
      4 years ago

      How so?

      • 🌞🌞🌞 ( amanneedsamaid@sopuli.xyz ) 
        link
        fedilink
        arrow-up
        6
        ·
        3 years ago

        SimpleX > Session > Signal in terms of metadata.

        On Signal, your user id is your phone number, a directly identifying piece of information. That is a major point of weakness in terms of metadata reduction, usernames would remedy this significantly.

        On Session, your user id is anonymous, a randomized string of numbers and letters. However, this user identifier is persistent, meaning if multiple people were found messaging that single randomized ID, that is data about that user even though it the id is randomized.

        On SimpleX (although you do have to option to have a persistent ID on top of using this), every conversation uses a randomized user id you send to your contact via a QR code or link. This means in terms of identifying you’re talking to the right person, SimpleX is weaker as if someone hijacks the link, they can impersonate you. The links are one time only, so you have to make sure you transfer the link securely (i.e. QR code via encrypted video call, a message on another secure messenger, or scanning the QR code in person). Once you establish the connection however, SimpleX is a more private experience because of the lack of a persistent user identifer. This also means no spam, ever!

  • plain ( plain@szmer.info ) 
    link
    fedilink
    arrow-up
    6
    ·
    4 years ago

    Simplex doesn’t need phone number so its different from signal

  • jackalope ( jackalope@lemmy.ml ) 
    link
    fedilink
    arrow-up
    5
    ·
    4 years ago

    Open source?

    • onlooker ( onlooker@lemmy.ml ) 
      link
      fedilink
      arrow-up
      7
      ·
      4 years ago

      Looks like it:

      https://github.com/simplex-chat/simplex-chat/blob/stable/LICENSE

    • RecycledAnonymous ( RecycledAnonymous@lemmy.ml ) OP
      link
      fedilink
      arrow-up
      5
      ·
      4 years ago

      yes it’s open source

  • Yujiri ( Yujiri@lemmy.ml ) 
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    4 years ago

    deleted by creator

  • serenity ( serenity@jeremmy.ml ) 
    link
    fedilink
    arrow-up
    3
    ·
    4 years ago

    I tried SimpleX Chat, and saw it requires the other person to be on-line, maybe that will change ? The project looks promising. I think they wanted to get more money to have a security audit done for the source code.

    • RecycledAnonymous ( RecycledAnonymous@lemmy.ml ) OP
      link
      fedilink
      arrow-up
      7
      ·
      4 years ago

      it’s only for the initial connection

      • serenity ( serenity@jeremmy.ml ) 
        link
        fedilink
        arrow-up
        1
        ·
        4 years ago

        Thanks

    • serenity ( serenity@jeremmy.ml ) 
      link
      fedilink
      arrow-up
      1
      ·
      4 years ago

      Here a security audit (Read on Lobste.rs today) : https://raw.githubusercontent.com/trailofbits/publications/master/reviews/SimpleXChat.pdf

Privacy@lemmy.ml

privacy@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !privacy@lemmy.ml

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

  • Lemmy.ml libre_culture
  • Lemmy.ml privatelife
  • Lemmy.ml DeGoogle
  • Lemmy.ca privacy

much thanks to @gary_host_laptop for the logo design :)

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 85 users / day
  • 678 users / week
  • 2.74K users / month
  • 6.77K users / 6 months
  • 852 local subscribers
  • 51.1K subscribers
  • 4.56K Posts
  • 59.3K Comments
  • Modlog
  • mods:
  • k_o_t ( k_o_t@lemmy.ml ) 
  • tmpod ( tmpod@lemmy.pt ) 
  • Yayannick ( Yayannick@lemmy.ml ) 
  • ranok ( ranok@sopuli.xyz ) 
  • BE: 0.19.15
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code