Imnebuddy - pronounced “I am any buddy”

Techie, hippie, commie nerd

  • 0 Posts
  • 31 Comments
Joined 4 years ago
cake
Cake day: March 17th, 2021

help-circle
  • I’m not denying that major flaw of Signal, in which part, yes exposing your phone number tied to your Signal account basically negates Signal’s security, as well as Signal’s centralized server being proprietary. Nevertheless, when using Matrix, you need to ensure you and everyone you communicate with uses a client that isn’t still using the deprecated libolm cryptography backend (and that it uses vodozemac).


  • https://lemmy.ml/comment/15999861

    In the blog posts I read where the author, a security engineer, audited and/or reported vulnerabilities with two E2EE chat protocols commonly recommended as Signal alternatives–Matrix and XMPP–both had implemented half-baked solutions or refused to solve the issue at all in some regards, and both had evangelists that gave dismissive responses. The XMPP chud dev gave a laughably childish response, and the Matrix dev even admitted the team being aware of the olm vulnerability and deliberately refused to fix it for years. Not that Signal cultists are any better and not negating the legitimate security and trust issues with the Signal platform, but Signal is still a decent platform for most people’s threat model, though it would be nice if there was an alternative that could compete with Signal to recommend to most people instead. If you care about metadata resistance and your threat model involves high stakes if your assets are compromised, the blog author suggests Tor-based solutions such as Cwtch and Ricochet Refresh.


  • I’m with you there. This wasn’t meant as an argument against your statement. I brought up the issues regarding Matrix and XMPP as they are often recommended as alternatives to Signal, and after learning about this blog in a previous conversation I had about this topic, I thought it would be a good resource to bring up so people can be informed about those platforms and some alternatives that may be better than Signal while being metadata resistant.


  • Many Signal alternatives also have security issues of their own, often making them less secure than Signal. This includes Matrix and XMPP. In the blog post regarding XMPP+OMEMO, the author replies to a question about which would be better than Signal, Matrix, and XMPP with this suggestion:

    Anyone who cares about metadata resistance should look at Cwtch, Ricochet, or any other Tor-based solution. Not a mobile app. Not XMPP. Not Matrix.

    In regards to Ricochet, not having a mobile app version makes it difficult to recommend to less tech savvy people.






  • I was able to get some Linksys E8450 routers for cheap (~$40 each) on eBay a couple years ago, but they are more expensive atm (but $70 each, which is cheaper than a lot of other options). They require a bit of work to get OpenWRT installed, but it’s not bad once the work is done (I have received nearly 400 Mb/s when I am close to the wireless connection sometimes, which is what my internet is capped at). I have used them as a mesh with one as a main gateway and the rest as access points with additional Ethernet ports. They do have the OKD issue fixed now, too, and they’re also Wi-Fi 6. I’m looking into getting a Banana Pi BPI-R3 or R4, though I am not sure how well they are with mesh specifically, but have seen a few forum threads of people having some issues with mesh on these specific routers. I hope to switch to fast roaming (wired backhaul) eventually.