this post was submitted on 22 Mar 2026
33 points (94.6% liked)

Android

33684 readers
1120 users here now

DROID DOES

Welcome to the Android community on Lemmy. Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


founded 2 years ago
MODERATORS
 

Trust me, I push Signal hard and even donate to it monthly. As I'm sure many of you know, there are always a few contacts who unfortunately refuse to use it.

In this case: do you prefer to use insecure SMS in something like QUIK SMS or Fossify Messages, or do you prefer to bite the Google bullet to get end-to-end encrypted messages (even if the metadata isn't encrypted)?

I can see good arguments for both sides, so I am curious what Lemmy's take is.

top 22 comments
sorted by: hot top controversial new old
[–] mlg@lemmy.world 8 points 1 day ago

I seriously would not mind RCS if Google didn't monopolize it.

I will be forever on MMS because I'll never use Google's crappy message app.

No one is sending anything substantial over SMS for me anyway, so it's not an issue where I need an e2ee channel with someone who doesn't have signal

[–] DeathByBigSad@sh.itjust.works 23 points 1 day ago (1 children)

RCS is harder for average criminals to snoop into.

Also if in the future bank verification codes use RCS, that makes it harder to get MITM'd

(cuz banks are stubborn as hell, they'd never allow 2fa apps)

[–] 30p87@feddit.org 1 points 1 day ago

I'd rather still have SMS verifications than the proprietary 2FA app mine has now

[–] berty@feddit.org 1 points 20 hours ago

Occasionally I just use SMS for plain text like "Hey let's hang out later". I don't use it for longer chats, sending Pictures or anything like that. I don't care about RCS since I don't use google services.

[–] hexagonwin@lemmy.today 2 points 1 day ago

i would just use sms/mms. it's easier to manage (backups and stuff)

[–] Alvaro@lemmy.blahaj.zone 3 points 1 day ago

Sadly, encrypted will always the be better option, even if proprietary.

[–] Appoxo@lemmy.dbzer0.com 3 points 1 day ago (1 children)

Neither.
SMS/texting is so fucking outdated. Why are ya'll still attached to that stuff?

[–] dgriffith@aussie.zone 10 points 1 day ago* (last edited 1 day ago)

Why are ya'll still attached to that stuff?

It comes with every phone and is the lowest common denominator.

So I can ask a recipient what messaging-app-de-jour they are using, and then install said app , or I have to convince them to use MY messaging-app-de-jour and get them to install it. All this has to happen outside preferred channels of communication, because we haven't yet figured out what shared methods we can communicate with.

Orrrrr I could just send them a SMS and know that even if they are using the shittiest, most locked down non-free piece of crap phone possible, their phone will go 'bing! ' and they will receive my message.

[–] undefined@lemmy.hogru.ch 6 points 1 day ago

I absolutely cannot stand RCS. Here in the US all the carriers have given up implementing it themselves and instead offload it to Google — I’m not even an Android user! I have to explicitly unblock a bunch of Google domains for RCS to work.

E2E will be nice once it’s functional with iOS but I still loathe depending on Google.

[–] sylver_dragon@lemmy.world 11 points 1 day ago (1 children)

What are you more worried about, third party, MitM interception (e.g. IMSI catcher) or Google knowing who you are communicating with? The former is technically harder for an attacker, but the use of such devices is well documented and poorly controlled. Google is, well Google. And you can expect them to monitize any bit of data they have on you. Also, that data will almost certainly be handed over to local law enforcement, especially if they have whatever the local equivalent of a warrant is.

As with most security, there are trade-offs. You have to decided what risks you are willing to accept and what you are not.

[–] sp6@lemmy.world 6 points 1 day ago

Personally, mostly concerned about surveillance capitalism and mass surveillance. But I pose this more as a hypothetical for what "you" (the average lemmy user) would think is the lesser of two evils

[–] hendrik@palaver.p3x.de 9 points 1 day ago* (last edited 1 day ago)

Well, I don't have Google Messages on my phone. And as far as I know there's no open third-party implementation out there to do RCS?! That kind of messenging also isn't part of AOSP ...That means I'd obviously (need to) send and receive SMS.

SMS for uninteresting plain texts to a phone.

RCS for sending a picture over 1mb to a phone.

Email for common everything else.

Matrix\Element or other measaging clients for the uncommon everything else.

A second phone number or virtual SMS client like Google Voice for sensitive SMS 2FA.

[–] Mynameisallen@lemmy.zip 8 points 1 day ago

Personally I hate both options, I've lucked out that most of my steady contacts use signal, currently I'd go with RCS especially as it's supposed to get e2e encryption between iOS and Android. That said both options are rough, your carrier can read all your sms and Google gets all your metadata for RCS

[–] Azzu@lemmy.dbzer0.com 6 points 1 day ago (1 children)

Well if I only get those two options it'd be SMS because I don't do anything interesting enough for a government to spy on, but Google would benefit in knowing my contacts.

But the real answer would be, I would not message that person anymore.

[–] Turret3857@infosec.pub 1 points 1 day ago

this is the way

[–] REDACTED@infosec.pub 3 points 1 day ago

RCS. Even with the added smart features, it's still seen as a more secure alternative due to encryption and sender's verification

[–] Lysergid@lemmy.ml 1 points 1 day ago

Recently I was looking for sms app for ios with PGP integration. Sadly didn’t find any. Was thinking to build one but rolling out to AppStore is too much of a hassle. RCS seems to be carrier dependent.

[–] Onomatopoeia@lemmy.cafe -1 points 1 day ago

RCS is trash.

[–] solrize@lemmy.ml -2 points 1 day ago (1 children)
[–] RushLana@lemmy.blahaj.zone 7 points 1 day ago (1 children)

Email is not an instant messaging protocol.