Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Monday, May 31, 2021

Signal or Session Messenger, and why?

How does Signal Messenger compare to Session Messenger?

That is a question asked by a friend who tracked down an answer; but there's more to it than a user perspective!

Here's the answer he found on Reddit, which is valid as far as it goes. Note it is about seven months old as I write this. My answer follows.
+++++++

Signal vs Session Private Messenger?
Which is better? I was thinking of switching from signal to Session since it doesn't require a phone number (unlike Signal). What are your thoughts on this?

Should I make the switch or continue with Signal?

[UPDATE: Went with Signal. Calling quality has improved A LOT.]

opticillusion
191d
Session is buggy as hell, I would stick with Signal for now, they are bringing out usernames soon so you won’t need a phone number to use it

Reply
KundraFox
191d
Are messages delayed or something? And any idea when Signal will switch to usernames?

Reply
lungdoge
188d
turns out notifications are pretty damn hard when you remove a central server so we've had to engineer quite a few new things for Session. Message reliability and notifications are definitely getting better and our developers are still focused on improving the user experience. There's some big things coming, which im not able to touch on yet, but stay tuned!

Reply
opticillusion
191d
Messages are delayed and the notifications are terrible, cool concept just too many problems with it currently

Signal don’t really give a schedule for when things are going to be released they just release them, from what I’ve been reading they have had to pretty much re-write a big part of Signal to incorporate the usernames feature and it’s currently in testing stages
+++++++


MY REPLY (adapted for Gab)
----------------------------------------------
----------------------------------------------

This thread essentially compares user experience and bugs, but doesn't go into distributed nodes and onion skinning, which is the real benefit of Session. That post was seven months ago; I believe Session have been working very hard to get things stable. If they succeed, and I believe they are, it will be better than Signal. Why?

DISTRIBUTED ARCHITECTURE
-------------------------------------------------
Signal is encrypted but CENTRALISED, whereas Session is DISTRIBUTED. In the end any encrypted device can be accessed - it is just a matter of brute force over time. Authorities can walk into Signal HQ and confiscate the servers and all our private messages; then it's just s matter of time until they have it all unlocked. With Session, If they can't get their hands on physical servers, they can't crack the messages. 

THE PRESSING NEED
-----------------------------------
I have a suspicion Christians and other dissenters of the NWO / Beast Kingdom of Revelation may need secure messaging, and I'm concerned it maybe sooner rather than later. See what our Kabbalist PM  (converted to Judaism) and Dutton are planning:  https://www.bitchute.com/video/6inynJ3nZjrO/.

I believe time is shorter than may anticipate. It's no good complaining but leaving yourself without the ability to communicate with friends and loved ones as you need. The New Testament - our Christian Bible as we know it - will be banned in Australia; Noahide Law will see to that and these laws are being adopted globally. Noahide Law asserts worship of anyone but 'God' as blasphemy, punishable by death (by guillotine, which is being made ready but that's another big discussion).

Tuesday, September 13, 2016

Technology : Damned if you do...

It's your phone, tablet, PC etc  secure? What about 'the cloud', and whether we should use that? Should we use Apple, Android, Windows, Linux or something else? Why?

People sometimes ask me whether they should use Microsoft products, Apple, Facebook and other products & services because they are concerned their personal information can be compromised. So here's an 'off the top of my head' quick commentary whilst I've got it on my mind...

First, we must understand that computing technology is like a layer cake. There's one layer built on another, that's build on another and so on. In many instances , there are perhaps many tens of layers at play when you are using a device, and the more layers you have, the susceptible you are to the app you see being compromised by something in a lower layer.

One common breakup of layers might be looked at as:
1. Hardware
2. Firmware
3. Operating system
4. Virtual machine
5. Window kit
6. App

And if your app is connected to the cloud somehow, you might be interacting with multiple servers that have something like :
1. Hardware
2. Firmware
3. Operating system
4. Virtual machine
5. Service Interface (that talks to your app)

With all this (fairly simple scenario) going on, there's an awful lot at play!

Thought #1. If you are writing something you want to keep confidential due to IP or other reasons, there are a few basic things you can do :

1. Make sure your device (pc, tablet or whatever) has antivirus software installed, running and up to date.
2. Make sure your operating system is up to date too
3. Don't have things you don't need on the device. The more apps, the more risk.
4. Consider encrypting & password protecting your files / documents
5. If it's really sensitive, disconnect from the Internet ; or get to secure your Internet use.

Thought #2. Using the Internet securely.
1. Choose some cloud storage that some may hand over all your files. I use Mega (mega.co.nz) for personal files for this reason.
2. Don't use federated logins. What I mean here is don't use your Facebook, Google, Microsoft is other 'generic' login to access what got want to use as a secure service. May use am email address and password.
3. Consider a separate email address for more sensitive information, so you can keep it more separate from higher use, more social stuff.
4. Don't use cloud based facilities such as Google Docs, Office 360 etc, as they will read your files in the cloud. The safest way is just to STORE your files in the cloud.
5. If you need to connect with someone else, once again ignore the big players and look for safety. The thing that started new writing this post was actually a new secure product for Android. This one's called Zyptonite. I've watched cloud storage become more secure, them browsing online through HTML with a web browser, then use of pictures by encrypting a whole web page. If it's progressing .
6. Use https instead of http (if a site allows it) The 's' means secure. It encrypts the page contents.
7. Consider the TOR project and browser for security purposes. This encrypts your data for you and also hides where you are coming from by passing the requests through a cooperative network of servers.
8. If you need secure video, it's mostly not there yet. Not as streaming from a web site anyway. You can try to download files over a see is link, that's a good idea. If you want secure video conferencing, like Skype (which is now part of Microsoft) but with security, have a look at Zyptonite. If encrypts video chat.

Thought #3. Comments are welcome, and I should add to this if I get inspiration and time to do so!

Thought #4. Android does logging at the operating system level. Android was started by Google, so have strong links to the New World Order. Facebook had funding from a CIA cover company to get going, with the deliberate aim of using social infestations for intelligence. Apple has stood up against the government once or twice, but don't be fooled, I have a hunch they are cut from basically the same cloth.

The bottom line : don't trust the big names or even startups. Look for facilities that prove they encrypt directly instead of through the operating system, which can be like a nosey post office worker reading mail going either way before passing it on.

Lastly: This is not definitive, and may not even be up to date, so don't make decisions straight from it thinking you'll be secure. Please do your own homework 😀.

Saturday, August 13, 2016

EFF.ORG: Data Retention Law Passes in Australia, but the Fight Isn’t Over


Mandatory data retention legislation is never a good idea, which is why EFF has vigorously opposed it in the United States, where Congress tried and failed to pass it in 2009. That year, two ill-conceived bills would have required all Internet providers and operators of Wi-Fi access points to keep records on Internet users for at least two years to assist police investigations. Nevertheless, governments around the world, individually, and in concert, continue to argue that the stockpiling of the private, personal data of entire populations become a global norm. It's a constant battle, but one with some clear victories, most notably in the European Union, and most recently in Paraguay. The latest setback in the global fight against data retention has been in Australia, which, despite widespread opposition from journalists,activists and the general public, passed a comprehensive data retention bill this month.

Read on at https://www.eff.org/deeplinks/2015/04/data-retention-law-passes-australia-fight-isnt-over