[…] it uses the X25519 public key… as a symmetric key, for AES-GCM.
[…] anyone that knows the public key can decrypt it.Ouch.
I’m OOTL, why do people want an alternative to Signal? It thought that was the good app
You need a phone number for Signal which means that your mobile provider will have your location, your IMSI, your mobile device model, serial number if you are using a T-Mobile or any other Telco" supplied device.
If not then via the IMSI / mobile number they can get your location and details from Google / Apple etc and that not even considering your IP-Address
Any time that there is a unique real world identifier the owner can be located. The only way around this would be to use something like Briar that use cryptographic uniqueness and that communicates via Onion like multihop anonymizers (TOR etc) from the outset.
I don’t know about other people, but the only thing I don’t like about Signal is that it is centralized. It seems to be the only option to actually get everything right for security though from what I hear.
That’s a reasonable thing to dislike about it.
I dislike that I can’t reply to another message with a sticker.
I also dislike that, despite having admin access, I can’t delete abusive messages left in groups for anyone but myself. That makes it unsuitable for building communities.
It’s centralized, it doesn’t officially allow 3rd-party clients, it requires a phone number, and the desktop app kinda sucks. I use it anyway, but it could be better.
That desktop app really is super hot garbage.
The “centralized” part is not a problem with their protocol and it’s well explained.
The 3rd-party clients thing … I agree with, but one can find justifications for that too. They probably don’t want people to use it for filesharing with uuencode and base64. Or even for VPNs, like they did with Tox when it seemed to have a future.
The phone number thing sucks, but there’s a need to defend against bot registrations somehow.
The desktop app sucks absolutely and conclusively. If there were a library one can use to make a Pidgin plugin, it would be a godly gift.
What are everyone’s thoughts on Molly, advertised as a hardened fork of Signal?
Don’t care too much about the supposed hardening, but it’s on FDroid and has UnifiedPush, so I use it over Signal