this post was submitted on 02 Mar 2021
154 points (97.5% liked)
Privacy
33560 readers
360 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
What about Tox?
I had high hopes on Tox, but now a days I no longer do. Its security status hadn't change for a while: https://github.com/TokTok/c-toxcore See there:
And the 2 issues highlighted there are scary:
https://github.com/TokTok/c-toxcore/issues/210
https://github.com/TokTok/c-toxcore/issues/426
To me experimental, as highlighted in the github repo, is not enough, as mentioned in the 2nd issue.
I really had high hopes on Tox, given its peer-to-peer distributed nature (much better to me than just decentralized by self hosting or so) but I don't see it improving unfortunately...
Briar is similar, but a 3rd party is just adding support for desktops, and as well as Tox, and I'd guess as any peer-to-peer distributed messaging mechanism, it's really battery hungry, and phones don't survive even half a day with them active. I don't like Briar's reliance on Tor btw: https://briarproject.org/how-it-works
And on such peer-to-peer distributed systems, it seems really hard to get multi-devices support or syncing. But I'd guess there's no other choice for some people other than Briar. I'm still looking for a distributed peer-to-peer messenger, not consuming the whole battery at least in a day, and that somehow, through mechanisms like the one keybase uses, allow some sync between devices... But the most important thing of course is battery life... Hopefully supporting as well voice/video calls, and some other common stuff to avoid needing other meesengers to support them...
qTox
qTox is just a desktop client. The Tox protocol implemented by c-toxcore is the one with security issues. BTW, part of the issue is precisely that the Tox protocol is not an e2ee one, and in one of the issues referred the axolotl protocol is shown as an example... So, no matter the client, the Tox protocol is lagging behind in terms of security.
Oh, I hope it improves. Personally I want my IM client to send and receive e2ee text. Rest should be handled by other programs.
Tox has a terrible security track record. At the same time, developers are still making wild claims that Tox can protect your from nation-state sponsored attacks:
This is not a code problem.