this post was submitted on 02 Jan 2025
165 points (95.6% liked)
The Signal messenger and protocol.
1726 readers
1 users here now
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Signal is better than Session if you value privacy:
The Session developers dropped Perfect Forward Secrecy because it would be hard to work around it.
Source: https://getsession.org/session-protocol-explained
In plain English, they dropped a security feature for their own convenience to the detriment of their users' security.
For anyone unsure what PFS provides:
Source: https://en.wikipedia.org/wiki/Forward_secrecy
The Session devs also claim:
Reading between the lines, we can interpret that as introducing security through obscurity, which is generally considered bad practice - https://cwe.mitre.org/data/definitions/656.html
Lastly, Session does not provide quantum resistant encryption, the latest and greatest tech in ensuring your messages stay private. Signal, SimpleX (via PQXDH [1] ) and iMessage (via PQ3 [2] ) - as far as I'm aware - are the only messaging platforms that support quantum-resistant encryption.
If you want something like Signal but without phone numbers, give SimpleX a try. It's basically a fork of Signal with a ton of privacy features, like working without a phone number. I like it but the UX still needs a lot of polish before I try getting family/friends on it.
[1] https://signal.org/blog/pqxdh/
[2] https://security.apple.com/blog/imessage-pq3/