Which is your preferred messaging app? I just want some insights about these two.
You may share other messaging apps too.
Matrix is open source and federated, end of the story.
Completely different use cases.
Matrix is shared interest groups.
Signal is for personal communication.
I’ve come to distrust Matrix, the metadata leaking is one thing but then combine that with the fact that .org is basically the default server and you almost have to federate with it, and they were started as an Amdocs project before spinning off into “the matrix foundation,” and Amdocs is Israeli, and while I don’t have PROOF they’re connected with Mossad I’d rather not chance it.
Plus, the apps all sucked last I used them, Element was the best and it was still buggy as all hell, and the Linux app is just an electron wrapper, and it was too hard to use for most of my “normal” friends (I agree, they should get good, but they do not get good, what should I do hold 'em at gunpoint and install Fedora, my options are limited). And the rooms had such a bad CP spam problem they stopped them from being publically searchable, you (now still?) have to know the room’s addr to join. Even still, with that CP problem, it becomes hard to reccomend family/friends to make an account. I don’t want to see that, I don’t want them to have to see that, and I don’t want them to think I want to see that and judge me because of spam in the RasPi room because I’m the guy that recommended the app, I don’t need that in my life.
Signal requiring phone numbers is also not my favorite, and the single point of failure is not the best either. Better than Matrix imo, but still. Also last I used it they still supported SMS and when a contact would delete Signal without deleting their account, the message would still try to deliver through Signal instead of defaulting back to SMS, so I’d have to switch my default to Messenger every time I wanted to talk to them and back to Signal when I was done. That was annoying.
Now happily using Delta Chat, easy onboarding for “normals,” low (no?) metadata leaks, webXDC seems cool, p2p video/audio calling, multi-relay support for resiliency, groups (but anyone can kick anyone, they’re meant for known contacts or family more than matrix-like rooms), no discoverability so nobody gets your acct by just having your phone number or etc (so my friend doesn’t have to worry about their abusive ex finding them on it like on IG or Snapchat), due to those last two things it doesn’t seem to have the same CP problem as Matrix rooms, channels are pretty neat, you can share location for increments between 30min and 24hr, bunch of cool stuff!
Isn’t Signal a CIA honeypot?
Ehhhh idk, afaik jury’s still out on that, but imo “could be.”
That’s partly why I use Delta Chat instead actually. Only partly, but it makes the list.
Even still, gun to my head, I think I’m picking Signal over Matrix as far as who I trust a little more. Not that I trust either entirely, and DC I trust more than both of those, but there’s always the possibility of some vulnerability if not a full backdoor. At least DC is FOSS and decentralized, I honestly doubt there’s a “backdoor,” but never know who has a 0-day.
The CIA financed Signal (I believe they stopped a few years ago), however that was never really secret. It also happened in simpler times, in the earlier days of internet and mobile phones. In general it’s quite plausible that the CIA just wanted a really secure comms system that people they wanted to undermine regimes could use.
Contrast this with how the FBI and the Australian feds bankrolled Anomphones, which they then used to read the communications of criminals. That was kept secret until they were ready to brag about it.
My understanding is that the CIA also funds TOR, because they want to use TOR.
Only because nobody answered with this one:
IRC
Decentralized and an open protocol. Client setup to connect is not so straightforward, but it’s a one and done. Very robust.
I’m allergic to centralized communication schemes, though I do use signal to communicate with one person.
I want to research some of the other suggestions that have been brought up, so thank you for the post!
That’s new to me. Thanks!
Lmfao that’s funny, IRC is the oldest of them all.
Do you want it to be so complicated that no one you know in real life is able to use it for more than two weeks before they make some kind of mistake or change that deletes their entire message history and identity? Matrix
Do you want a slim chance that friends and family might use it, but you have to listen to privacy nutjobs tell you your app is a CIA NSA PsyOp and you might as well cc: potus(at)whitehouse(dot)gov all your messages, it’s run by an american non-profit obviously it can’t be trusted? Signal
Beeper which runs over Matrix (with bridges) has been pretty good and straightforward.
It’s setup like a chat app rather than a slack/discord lookalike so its easier for usual folks to get used to.
Does Beeper not break Signal encryption?
I don’t use either, bcz I use simplex in my personal life. It is really quite great!
I actually prefer XMPP. It’s also less of a hassle to set up than Matrix and the protocol is much more mature. There are still issues, but it’s rather functional for audio and video calls (if you’re using a supported client).
Edit: For clients, I use Cheogram on Android and Profanity (which is a TUI) or DinoX (for calls) on Linux.
I prefer matrix for two main reasons:
- I can host my own server (and I do)
- It’s not centralized
As a bonus it has briddes for almost anything you can think of, so I use the signal bridge.
Simplex
Matrix is nice but it’s clear they’re appeasing more towards shareholders than the community, self-hosting via Docker Compose was a PIA as there are 4-5 services that need to talk to one another.
My wife and I use signal. It has more features (encryption included) than regular texting.
I’m aware of decentralized alternatives but convincing my wife to use those (with the potential extra setup) would have been to much to ask. It took me years to get her to use matrix and that’s super easy to get up and running.
Signal is a centralized, US-based service which requires your phone number (thus your real identity, IE name and address), has social networking graphs of everyone you talk to, and must forward that information to the US government when asked, as well as (by law) not tell you that they’ve been asked to do so. During the Obama era, 60 NSLs were issued for this private information every single day.
People overlook its privacy concerns for the same reason they do with apple: it has a shiny interface and is easy to use, and makes people very attached to it. Behind all that, is a surveillance network that its creators have explicitly said they do not want it to be able to run in a decentralized, private manner.
It has a long history of privacy offenses below (such as refusing to publish its server’s source code for years, its reliance on other US tech services (amazon, google), US-government funding, and a US-defense-tank friendly administration) which get ignored or shouted down by many of those above. See the article below.
Pretty much any alternative is better, as long as its not hosted in a five-eyes country, and especially if it doesn’t require phone numbers or real identities like signal does.
I personally have been using SimpleX for friends and real life contacts, and Matrix for larger more anonymous group chats.
has social networking graphs of everyone you talk to
Source?
US government funding does not mean it’s immediately bad… The internet, thr flu vaccine, closed captioning, and wheather radar were all funded by the US government. A truly secure messaging encryption is beneficial to the United States, and is evem good enough for the president apparently.
Since their messages are truly secure, it wouldn’t matter where you store them. Just store them in the cheapest places possible. It being centralized makes it far more usable to the average person, making it much more likely for them to use.
Read the linked doc, because it’s clear you didn’t.
I read it. They also have no source or evidence.
Signals database, which we must assume is compromised due to its centralized and US domiciled nature, has a few important pieces of data;
You can’t simply say “we must assume” as evidence. In fact, they implemented “Sealed sender” in 2018 where they are not able to see who the message is being sent to.
They are also legally required to provide all information they have on users for warrants and subpoenas. Any time they do that, they post the (slightly redacted) document they provided to the courts. See the list here: https://signal.org/bigbrother/ This confirms they did not have any metadata on those users. The only info they have is what they openly state (phone number, date of registration, and last time a message was sent).
While there may be other US government requests they are not alllwed to disclose, they were legally required to provide the same information to the courts, and we can see what they provided.
And sure, while the US government funds Signal, you know who else endorses it? Edward fucking Snowden. If anyone knows about secure messaging, it’s the man that physically removes the microphone and camera from his phones before using them.
You can’t simply say “we must assume” as evidence.
Okay yeah you definitely didn’t read it. Large sections in that doc just before that are on phone number identifiers, NSLs, and 5-eyes countries, the US goverment pushing signal in privacy spaces… literally the reasons why signal isn’t trustworthy. Unless you can tell me what an NSL is, then I’ll assume you didn’t read it.
While there may be other US government requests they are not alllwed to disclose, they were legally required to provide the same information to the courts, and we can see what they provided.
Did you ignore the large section on NSLs? These come with a gag order, meaning its illegal for signal to notify their users about them being spied on.
In fact, they implemented “Sealed sender” in 2018 where they are not able to see who the message is being sent to.
This is a “just trust me” from signal, since neither of us have access to their centralized DB, but you also ignored two paragraphs down, where it showed that with message timestamps and recipient information, this would be trivial to find the real sender of a message, regardless of sealed sender. Again, actually open source software can’t say “just trust me” like signal can, we actually have to show code to prove it, and let people run that code in a private manner.
And sure, while the US government funds Signal, you know who else endorses it? Edward fucking Snowden. If anyone knows about secure messaging, it’s the man that physically removes the microphone and camera from his phones before using them.
Elon musk and jack dorsey also endorse signal. An endorsement means nothing, especially for centralized software based in a 5-eyes country.
Large sections in that doc just before that are on phone number identifiers, NSLs, and 5-eyes countries, the US goverment pushing signal in privacy spaces…
Two things:
- Get a burner phone with cash
- This has nothing to do with the claim Signal collects metadata.
If Signal stored a DB of messages sent and received, they would legally have to provide that for a court warrant. The fact they did not provide that to the courts proves they do not store that data.
Did you ignore the large section on NSLs?
No, those are the government requests I mentioned in the quoted section. I just didn’t say “NSL”. Their example with Lavabit was fundamentally different since Lavabit was in control of the TLS keys and was able to decrypt the content, but they refused. Signal is complying without giving anything to the government because they have no way of decrypting the messages, even if they wanted to.
actually open source software can’t say “just trust me” like signal can, we actually have to show code to prove it, and let people run that code in a private manner.
Open Source: Open source is the practice of publishing digital resources publicly alongside their source code or source files, enabling use, study, modification, and redistribution.
Here is there Server source code with GNU AGPLv3 license. I’d say that fits the definition of open source.
I recognize there isn’t a way to confirm they are running the code they published. Even signal has recognized the server source code trust issue:
Of course, what if that’s not the source code that’s actually running? After all, we could surreptitiously modify the service to log users’ contact discovery requests. Even if we have no motive to do that, someone who hacks the Signal service could potentially modify the code so that it logs user contact discovery requests, or (although unlikely given present law) some government agency could show up and require us to change the service so that it logs contact discovery requests. More fundamentally for us, we simply don’t want people to have to trust us.
https://signal.org/blog/private-contact-discovery/
That’s why the set it up to minimize the required trust. The client side code is fundamentally built to make the trust required in Signal to be very minimal. You can build the client app from the source code and confirm everything in it.
An endorsement means nothing, especially for centralized software based in a 5-eyes country.
Edward Snowden is mentioned several times, and quoted, on the 5-Eyes wikipedia as a whistleblower. If the worlds most famous 5-Eyes whistleblower endorses Signal as a way to hide from the 5-Eyes, that’s a pretty damn good endorsement. I recognize that means nothing to you, and that’s fair. I’m more so pointing out the humor.
I will concede that the US government could force Signal to start collecting metadata and we would have no way of knowing. I do think they would fight it, or move to another country, given they have threatened to withdraw services from other countries already. It’s not a great comparison, since the Government was trying to get access to message contents rather than metadata, and Signal would only be stopping service and not change country of operations.
Regardless, Signal is convenient. We all know the balance between security and convenience, and Signal is a good middle ground. It’s a single app users can download, and it’s quick to setup, and they can use the same phone number/contacts they already have. They don’t have to determine a server they want to create their account on, learn what federation is, etc. Signal is a good option, and I would 100% tell people to use Signal over Whatsapp, Telegram, RCS, and especially SMS.
If we wanted to discuss the problems with something like Matrix, it would also be very flawed. You shift the trust to the home server of your choosing not to keep the metadata (It’s not realistic to ask a random person to start their own server). It has a much larger attack surface, between the different clients, servers, bridges, bots, extensions, etc. Even if Matrix itself is relatively secure, it only takes a single integration with a vulnerability to compromise their data. For example, they may bridge Matrix to Slack for specific use case, but if that bridge gets compromised then you could be vulnerable.
Good question. I looked in the attached essay source, and he covers this there https://dessalines.github.io/essays/why_not_signal.html#social-network-graphs
This is my comment to the other person, I just don’t want to type the same ideas out a second time:
I read it. They also have no source or evidence.
Signals database, which we must assume is compromised due to its centralized and US domiciled nature, has a few important pieces of data;
You can’t simply say “we must assume” as evidence. In fact, they implemented “Sealed sender” in 2018 where they are not able to see who the message is being sent to.
They are also legally required to provide all information they have on users for warrants and subpoenas. Any time they do that, they post the (slightly redacted) document they provided to the courts. See the list here: https://signal.org/bigbrother/ This confirms they did not have any metadata on those users. The only info they have is what they openly state (phone number, date of registration, and last time a message was sent).
While there may be other US government requests they are not alllwed to disclose, they were legally required to provide the same information to the courts, and we can see what they provided.
And sure, while the US government funds Signal, you know who else endorses it? Edward fucking Snowden. If anyone knows about secure messaging, it’s the man that physically removes the microphone and camera from his phones before using them.
Insightful! Thanks. I agree and I’ll give SimpleX a try as others suggested.
This is how I explained Matrix to my mom: its like an email address, but for chat. You can chat at me, even if we aren’t using the same server, like someone can send an email from Gmail to Hotmail. She got set up and promptly went back to texting me every dang time.
Try Delta Chat, it’s even more like email but for chat (it runs off off Chatmail relays, it’s literally email but for chat).
But more importantly it’s easier to use, I’d have to set my mom up on Matrix but on DC I just sent her the invite link, she downloaded the app and made an acct (and may have had to click the link a second time to get to me but still), it was easy as hell! Then next time we were together I had her open her phone and I set her up with a few extra relays for redundancy. And she actually uses it now! It’s basically a whatsapp clone UI wise so I guess that helped, and at first she’d text me and I’d reply on DC until she started remembering DC exists.
My dad’s a bit better, all I had to say was “it’s encrypted” and he made an acct and hasn’t used SMS with me since lol.
That is where signal once shined before they removed the capability of being default sms app
That’s why they removed it actually, people think being the default SMS app means you’re actually sending encrypted messages now. Nope, it just means you’re sending regular old SMS but with thr Signal app.
That’s an extreme minority though. The only people who use Signal are privacy and security conscious people and the people who those people forced to use signal. For the second group, they couldn’t care less if it’s encrypted or not, for the first group, they will make sure what’s a Signal message and what’s a regular SMS message.
This mythical user that accidentally sends an SMS message when they meant to send a Signal message doesn’t exist.
That user might be in the slim minority but they do exist and I appreciate them taking that into account and taking seriously the security of people who aren’t super technical.
But then the only use case is if you literally take someone’s phone, switch the default SMS app to Signal, and they don’t know how to switch it back themselves. If they’re that tech illiterate, they’ll probably call you for tech support as to why text isnt working, instead of switching to Signal. And even if they then agree to do it your way, the mythical user you described is no longer mythical, it is easier to make a mistake in the Ui for someone tech illiterate. You will often see a person’s phone number in their Signal profile, after all, it’s not unthinkable.
Also, as time goes on, more people start using Signal as more people see how fascist some governments are getting and how intense social engineering is with spam calls/texts/whatnot. I know a random 60 year old bus driver who switched to Signal and made other privacy changes like turning on Safari’s relay because her accounts got hacked and she was using the same password for everything. To someone that is blind Googling something they don’t have context for, Signal is a trusted encrypted app, therefore anything I send through Signal should be trusted. I don’t think it is as impossible as you think. And again, to what benefit? There is some benefit to prevent Google possibly scanning your messages, but there are also plenty of other SMS apps which can avoid this, if it is avoidable at all.
Signal. Matrix was made by Israeli spyware company Amdocs and when an employee was asked about it after the split to a UK company they pretended like Amdocs wasn’t caught in multiple global spyware scandals already.
So neither is the answer, I guess. We’re cooked.
For easy privacy the answer is Signal. If you want to put in effort then SimpleX or others seem better.
Matrix MIGHT be okay if you self host it, but I definitely wouldn’t trust the main Element hosted server. But the dev team sketches me out too hard so I’d just pick alternatives.
Matrix is literally an open standard, use a server and client written by people you trust, or write your own.
Signal is literally made by a private company and is completely closed source.
Signal is open source but it’s hosted centrally. So you’re trusting their server.
Matrix is a protocol it’s not hosted anywhere. But the primary developer and host instance now called Element.
But it being created and initially bankrolled by an Israeli spyware company known for creating backdoors, and the lead devs still refusing to acknowledge that doesn’t inspire me much more confidence.
If you want privacy SimpleX seems like better option than Matrix.
You can host a server which uses software not written by Element. Same for the client.
I don’t trust the Signal devs because I have no reason to. I don’t want to use anyone else’s servers unless I’m paying them or they’re paying me 😅
And I love swapping/trying new clients.
You glossed over the fact that it came from Israel’s intelligence-community. Its design is woeful–that’s the protocol, regardless of client or server implementation. The project reeks of a state-backed program to get ahead of the increasing desire for encryption in everyday communications. Yet encryption has always been an after thought within that program. All those bridges to funnel different protocols into the program.
But they say Signal is centralized, and hosted in the US.
Signal is more stable & simple to set up. So for its intended use, getting people to actually talk to me on it, it’s better.
Matrix is obviously better as a Discord replacement. It doesn’t require a phone number which is also good. Not centrally managed so easier to decouple from big tech corruption. So it is better in those ways.
Isn’t Signal a CIA honeypot?
No
I agree. Signal is easier to use and to get people switch to it since the UI/UX are vey similar to other big platforms.









