What's the closest thing we have to a perfect private messanger?

In my mind the perfect private messanger is both completely secure, and also completely anonymous.

All the mainstream messengers can pretty much ensure the contents of the message will not be revealed....but that is not good enough. I want to be able to deploy and establish a completely anonymous AND private channel of communication on a dime without having to jump through extreme operational security hoops.

Does it really exist?

top 50 comments

sorted by: hot top controversial new old
[–] 28 points 10 months ago (2 children)

SimpleX is currently the best one possible.

All the security of signal without needing a phone number.

Everything can be through tor. Contact link can be formed with a one time use code that you DM someone privately.

Anything more advanced and you're basically in internet dead drop territory. An encoded message on a pastebin through tor. Congratulations, you've entered pedophile/terrorist level security realm.

  • source
  • hideshow 4 child comments
  • [–] [S] 7 points 10 months ago (5 children)

    Simplex does check alot of those boxes... but smp traffic is easily identifiable unless your jumping through the major hoops of establishing a totally anonymous proxy.

    An encoded message on a pastebin through tor. Congratulations, you've entered pedophile/terrorist level security realm.

    Thats to bad being anonymous and secure puts you in that category. It shouldn't!

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (5 replies)
  • [+] 25 points 10 months ago* (last edited 5 months ago) (1 child)
  • [–] 2 points 10 months ago (1 child)

    Are there any cool i2p sites or apps? Since it doesn't have exit nodes I never found a reason to use it.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 21 points 10 months ago (1 child)

    Briar, SimpleX, I2Pchat on desktop, maybe LXMF/Reticulum/Sideband over I2P if you want to get techy.

  • source
  • hideshow 2 child comments
  • [–] 17 points 10 months ago (2 children)

    AFAIK simplex is the closest we have to perfect privacy.

  • source
  • hideshow 4 child comments
  • [–] 9 points 10 months ago
    [–] 9 points 10 months ago (1 child)

    Signal is far from perfect but its good enough for me.

  • source
  • hideshow 2 child comments
  • [+] 9 points 10 months ago* (last edited 10 months ago)
    [removed by mod]
  • source
  • [–] 7 points 10 months ago

    SimpleX?

    Tox would also be fantastic, but they need to improve their encryption and get it audited. Also, some nicer UIs in the various clients would be nice.

  • source
  • [–] 5 points 10 months ago

    Session, Signal, Matrix, and more.

  • source
  • [–] 4 points 10 months ago (1 child)

    I think you don't want to know the real answer. It sounds like you want a phone app, but what you really have to do is flush your phone down the toilet and use a totally different approach. Also, there is absolutely no way to avoid difficult opsec. The communications technology is irrelevant since the greatest vulnerability in any security system is the people who use it. Do you think the private messenger software will free sessions with your therapist from spying? Guess again.

    As the saying used to go, you're seeking a Star Trek solution to a Babylon 5 problem.

  • source
  • hideshow 2 child comments
  • [–] 2 points 10 months ago

    Technically, you should keep your phone and run false, normie activities on it. Give it to someone else to use and move about while you're actually operational so it remains actively pinging the world while you're away from it. All while also using the real approach, but not within range of your phone, or any windows or apple hardware linked to you either.

  • source
  • parent
  • [–] 3 points 10 months ago

    You need to define extreme operational security hoops.

    For me, meeting a human in person and scanning a qr code or relying on an out of band scheme to do the same is a huge hoop.

  • source
  • [–] 3 points 10 months ago* (1 child)

    I would still like to understand why Jami is never mentioned in these posts. I'm not aware of any technical or security objections, and the less I hear about Jami, the more concerned I become about using it.

  • source
  • hideshow 2 child comments
  • [–] 2 points 10 months ago (1 child)

    You can't have big groups in Jami, it's limited to a small number of participants (can't remember how many).

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 10 months ago (2 children)

    Yeah. SimpleX has a similar problem, because it's basically creating a bunch of 1:1 connections between everyone to preserve anonymity - IIRC (I freely admit I could be misremembering this). As I understood, it's a decent limit, though - more than the 7-12 friend/family group you'd reasonably trust in a chat group.

    I did not consider this a blocker - who's using encrypted chat for large groups? Large group chats are fundamentally insecure; is the use case about anonymity, not encryption?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 1 point 10 months ago

    Sure, encryption may not be important for large groups but it can happen that it may be needed. If I were to make a group with my coworkers, I'd want that to be E2EE. On top of that, even without E2EE, you need good UX to host discussion groups for various topics, and Jami is simply not there yet.

  • source
  • parent
  • [–] 2 points 10 months ago (1 child)
  • [–] 1 point 10 months ago (2 children)
  • [–] 1 point 9 months ago

    I host one but the more I analyze privacy implications the worse it looks.

    Only you and maybe 10 other people will connect to that server's IP, port 5222. This makes it very easy to track your group by telco operators and people who have access to their logs.

    Even if you use a VPN or Tor at all times, most of your other users likely don't.

    And the domain is registered to someone's name too, although I know this can be worked around.

  • source
  • parent
  • [–] [B] 1 point 10 months ago* (3 children)

    Lot of people mentioning SimpleX but I can't imagine trying to make someone go online at the same time as me to start sending each other messages without being annoyed. It also relies on funding from the British state IIRC.

    On the other hand XMPP is a W3C internet standard, the server is super lightweight, plenty of tools and bridges work with it. Movim uses it, which is like an encrypted Mastodon where you can selectively make a post public but otherwise gates everything behind a login. Also you can send messages on the main phone network with the paid Cheogram service, but I realize that an unencrypted SMS relay is not a priority for everyone. I think it's the bee's knees.

  • source
  • hideshow 6 child comments
  • [–] 2 points 10 months ago* (3 children)

    Lot of people mentioning SimpleX but I can't imagine trying to make someone go online at the same time as me to start sending each other messages without being annoyed.

    Do you just keep your phone off or do you not use your IM clients there? Literally never had this issue with simplex, it deliveres notifications just fine to my phone.

    Though I did manually have to give it notification perms on android. Annoying but very easy fix.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (3 replies)
  • [–] 0 points 10 months ago (1 child)

    At first I read 'The Perfect Private Massager'

    You want both, a completely anonymous AND completely private channel of communications? I mean, not to sound sarcastic, when you find one, please do share. There are no absolutes. For every technology, there exists or will soon exist, an equal, yet undoing technology. I have amended this to exclude most strong ciphers as pointed out by one of the Lemmies here.

  • source
  • hideshow 2 child comments
  • [–] 2 points 10 months ago (1 child)

    Yeah. AFAIK there is no messenger that purposely delays your messages anywhere from 1 second to ,I don't know, a month? To stop someone from correlating your time online with the time messages are sent. That would be insanity. But it does increase privacy and anonymity a bit

  • source
  • parent
  • hideshow 2 child comments
  • load more comments
    view more: next ›