this post was submitted on 19 Jan 2021
23 points (100.0% liked)

Privacy

33462 readers
525 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

Molly is a hardened version of the official Signal for Android app. It claims the following features,

  • Protects database with passphrase encryption
  • Locks down the app automatically after you go a certain time without unlocking your device
  • Securely shreds sensitive data from RAM
  • Allows you to delete contacts and stop sharing your profile
  • Clears call notifications together with expiring messages
  • Disables debug logs
  • No SMS integration

There are two flavors of it,

  • Molly - Similar to the official Signal app, plus the additional features
  • Molly-FOSS - Doesn't rely on any Google components for location, push notifications & face blurring, plus all the additional features

Download it from here.

I've been using it for a couple of days & it is pretty decent so far.

Anyone here already tried or are using it? How's the experience so far?

all 13 comments
sorted by: hot top controversial new old
[–] [email protected] 8 points 4 years ago* (last edited 4 years ago) (3 children)

What's the difference between Molly and LibreSignal, for Signal as a company? Shouldn't Moxie ask them to stop using their infrastructure like they did with LibreSignal? Maybe Signal is not aware of its existence?

Anyway, looks promising. A really nice fork

[–] [email protected] 5 points 4 years ago (1 children)

I'm also interested on understanding if Moxie and company would eventually request molly to cease connecting to signal servers. Same thing as with signal-gcm-less. I don't understand why they can still connect to signal servers, since Moxie clearly wants no other clients, than the binaries provided by signal connecting. I don't know if this would last only until Moxie or signal guys realize, or only while these clients don't reach certain popularity... Who knows... Moxie's decisions make signal look like not open source, but who knows, maybe those 2 clients, molly and signal-gcm-less got some approval from signal?

[–] [email protected] 1 points 4 years ago

If i recall correctly, Moxie was primarily frustrated by libre-signal because it was using signal name. He was also frustrated with custom clients, but he should see this as an improvement if he was being genuine.

[–] [email protected] 4 points 4 years ago (1 children)

I had the same query as well. I don't know if it has any direct relation to LibreSignal, since it was abandoned sometime back. But, both aims to remove dependency on Google components.

https://github.com/mollyim/mollyim-android#disclaimer

This project is NOT sponsored by Signal Messenger LLC or Signal Foundation.

[–] [email protected] 4 points 4 years ago

As someone who has been using Signal, and previously TextSecure for almost 10 years, Moxie’s attitude is abhorrent and counter-intuitive. I wasn’t aware of how bad Signal’s privacy model was as it was worlds better than any other option back in 2015(in terms of security, not functionality) and I have not heard cries for an alternative until recently. I just downloaded Session and will promote it moving forward. Does anyone know an alternative to Signal for encrypted local storage of traditional SMS messages?

[–] [email protected] 7 points 4 years ago

am interested aswell, really want my messenger to be named molly tbh

[–] [email protected] 3 points 4 years ago (2 children)

i'm confused by this statement in the readme:

Back in 2018...But this option was removed with the introduction of full-disk encryption on Android.

android doesn't use FDE - it uses file-based encryption (FBE). it used to use FDE but hasn't since android 9. my point being that FDE existed first and has been phased out so it already existed in 2018 and was introduced waaaay earlier. so is this a typo in the readme or am i totally missing something?

[–] [email protected] 1 points 4 years ago

Yeah, that's a bit bugging. Checking Signal commits could give a clear idea about this.

[–] [email protected] 1 points 4 years ago* (last edited 4 years ago) (1 children)

I prefer Session because it routes traffic through ~~TOR~~.

Edit: I stand corrected.

[–] [email protected] 4 points 4 years ago

It doesn't route traffic through Tor, but through their own similar network called LokiNet.