It’s like a medal of honor for a privacy preserving app 😄
Indeed. If whatsapp isn't on the list, then I have all the confirmation I need.
The Russian government has also allegedly begun preparations to block the WhatsApp messaging app.
https://kyivindependent.com/messenger-signal-blocked-in-russia-media-says/
Zucks check didn't clear yet.
Maduro uninstalled whatsapp live on television a few days ago
"Banned in 15 dicatorships!"
could matrix.org be as easily blocked, since it's decentralized I'm wondering?
At least it means that Signal is working as intended if they are blocking it, I guess that they don't have back doors.
Being decentralized prevents DNS or IP blocks but not blocks through DPI.
Signal has an option to masquerade it's traffic as regular HTTPS, I don't know if Matrix can do such a thing.
I can answer this! All matrix calls are over https APIs. Ports and addresses are stored in a text file on the base domain or in DNS txt entry.
Thanks, nice to have someone knowledgeable.
Would you say matrix is censorship resistant? I've very limited knowledge of it but given what you said I imagine that if I was trying to block matrix I would just need to query the url of the text file and check the DNS text entry, if either exist just add the domain to the blocklist.
Matrix is in fact decentralized but in reality it is not so much, I don't know the number exactly but the majority of users use the matrix.org server
People who live in countries where DNS and IP blocks are common probably use a different server. I've been running my own for over a year and it works like a dream
could matrix.org be as easily blocked, since it’s decentralized I’m wondering?>
Or SimpleX?
It cannot be easily blocked especially if you use your own homeserver every homeserver replicates the channel and it can operate without the original server! That's why signal and telegram are inherently flawed.
Signal honored!
why telegram is not blocked? makes you think...
WhatsApp supposedly uses Signal protocol.
Why is THAT not blocked? Certainly they wouldnt roll their own encryption and bypass Signal security protocols after having Moxie come in, right? Right????
It is owned by Meta and is proprietary
Telegram is not secure, I guess if you can listen to it better not block it.
I mean it was blocked before Signal was blocked. Russia somewhat famously badly broke their Internet trying to shutdown telegram... and eventually gave up.
I'm guessing Signal finally has enough market share to get the Russian government's attention but not enough market share that they think the web of proxies that kept Telegram online will keep Signal online.
Would peer to peer apps be resistant to this sort of thing?
Yes, but you'll have to install them from sources other than what governments deem official. Like F-droid.
Now, if they block p2p traffic that's a different story
I am totally cool with F-droid.
It depends. Somehow it has to discover the peers. Other than that, they could block traffic between residential IP addresses and there goes large part of the P2P network
Russia and Venezuela are huge hotbeds of piracy from populations without access or capital to access most forms of entertainment.
Breaking P2P in this manner would basically be getting rid of the circus part of bread and circuses. Not a good move for an authoritarian.
Smart move, considering Signal is a US-hosted centralized service that has to comply with US NSL laws.
These comments below seem to be unaware of all the issues privacy advocates have of signal.
I don't get it, are you really arguing that Russia and Venezuela are blocking Signal to protect their citizens from American snooping?
All countries should ban US-domiciled companies like signal, or any communication platform hosted in Five-eyes countries, and especially ones domiciled in the US, which has to adhere to National Security Letters.
Isn't the whole point of something like End-to-End Encryption so that not even the company themselves can read your messages?
In that case it wouldn't matter even if they did turn the info over.
Edit: I read more into the page you linked. Looks like those NSLs can't even be used to request the contents either way:
Can the FBI obtain content—like e-mails or the content of phone calls—with an NSL?
Not legally. While each type of NSL allows the FBI to obtain a different type of information, that information is limited to records—such as “subscriber information and toll billing records information” from telephone companies.
You can read my article, or Drew Devaults on why he doesn't trust signal, which get more into this, but the short version is that US security forces don't have time to read the content of everyone's message anyway, they care more about the metadata: message timestamps and social graphs.
Signal stores all that data (via required phone numbers, meaning its linked to your real name and address), and via the US's key disclosure laws, it would be illegal for them to tell you that the US government is hoovering up that data.
Most security experts who actually know what they are talking about do recommend Signal for most users, including [https://twitter.com/Snowden/status/661313394906161152](Edward Snowden), [https://www.schneier.com/blog/archives/2018/06/russian_censors.html] (Bruce Schneier) and [https://linktr.ee/glenngreenwald](Glenn Greenwald). Eveyone should consider whether they would rather follow the advise of people who have literally fought the NSA and read the entire Snowden documents or belive in the FUD spread by some people here.
Mass censorship is never good for civil liberties. Let people decide on there own.
Also Signal is cryptographically sound. Many other messagers use a similar protocol
matrix stays winning
Matrix isn't secure depending on how you use it. It also doesn't protect individual identities terribly well.
Simplex Chat would be the better option however the main Simplex Chat server and matrix server could end up blocked as well.
Matrix is entirely self-hostable, and you can turn off both federation, and the requirements for any linkable identifiers.
Signal by contrast requires your phone number, isn't self-hostable, and is based in a five-eyes country.
Matrix doesn't protect metadata, which is arguably just as (if not more) important than message data. Signal by contrast does protect metadata and proper implements Perfect Forward Secrecy for all chats. I do think Signal's centralized design and phone number requirements problematic, but Signal still has many merits. Such as its massive user base for a AGPL-only project.
Matrix also implements Perfect Forward Secrecy, and that's been the case for a very long time: https://security.stackexchange.com/questions/162773/are-matrix-messages-encrypted-using-perfect-forward-secrecy
What do you mean by AGPL-only? Synapse is also AGPL. And you can only guarantee that there won't be projects with other licenses if you prevent them from existing.. which is not something to be desired
Why countries that do not prosecute political dissent bock apps used by political dissenters? /s
Privacy
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
Chat rooms
-
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)