For those who missed it, unrelated to this specific ZKP thing the release cycle also now permits Android tablets without a SIM to be first-class adjunct devices without using wierd tricks or alternate clients. It may permit them to be the initiation/sign-on device, which would invoke the ZKP, but the point for me as an existing phone number denominated user, the point is I can be on my tablet with true signal now. Nothing against molly, wanted it in the base.
For the longest time, you couldn't. It wasn't until this release I realised that had changed. If it changed before, it wasn't well communicated to me as an Android signal user. I was on beeper and then molly precisely because there was so little traction on changing this. You could install signal fine, but you couldn't QR code or secret phrase mesh it with your android handset. Oddly, iPad meshed fine with iPhone or Android, and OSX desktop likewise. Just Android tablet which didn't.
Do you think this changed in over 18 months? I think it changed in under 18 months.
If I’m not fully mistaken, I checked for the combination of iPhone as main device/Android tablet as iPad-like second device sometime in the past six months, at most since the beginning of the year, and it wasn’t possible (unlike phone + iPad as tablet, which seemed quite strange to me).
Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.
Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims about being privacy conscious.
That's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/
In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardize and document, 3- I reserve the right to change the deal for whatever reason if I ever feel the need" which is not a good look
Matrix is a vastly different protocol with vastly different privacy implications. Things like leaking reaction metadata outside of the encrypted envelope (though there finally is an MSC to fix that) should make that obvious. Matrix is cool tech and I use it every day, but comparing Matrix to Signal doesn't make much sense. You can't do what Signal does with Matrix or XMPP, simply because the lack of federation affords privacy and security advantages that federated protocols cannot support.
As for Moxie's post: all three points feel completely valid for a service they're offering for free. Moxie does know better than most users (most users don't know the first thing about software, programming, protocol design, or UX design) and it's a companies choices that drive users to their platform in the first place. Users who don't like it can choose from the dozens of other chat apps instead.
As for the second point, Matrix's ever-moving target of a protocol makes selecting a client or server that covers all of your needs a massive pain. Currently, Matrix's primary server software, Synapse (which is also at the base of the matrix.org server many people default to when joining the network), is violating the Matrix protocol, making it impossible to invite users to chat if they are on compliant Matrix servers. On the XMPP side, there are two different methods of achieving E2EE communication, with seemingly no standard mechanism to support the use case "I want to log in to my chat on my laptop and be able to decrypt the messages in the group chat". I can't blame Signal for not wanting to deal with issues like that. One piece of server software, one set of client versions, with fixes ready to deploy when they're called for: Signal's current design saves a lot of time and effort.
As for the third point, that's part of the reason I use Signal in the first place. I like federated networks as much as the next nerd and I like open standards even more, but the decisiveness behind the company, even when I disagree with their decisions sometimes, is what makes it clear what you can and cannot expect.
On the XMPP defence: yes, I believe what they are saying, XMPP could in theory be a good product, just like Matrix could be, and like Signal is. However, currently, it isn't. XMPP is currently losing in terms of public marketshare to Matrix, which I also wouldn't exactly call a great success.
> As for the second point, Matrix's ever-moving target of a protocol makes selecting a client or server that covers all of your needs a massive pain. Currently, Matrix's primary server software, Synapse (which is also at the base of the matrix.org server many people default to when joining the network), is violating the Matrix protocol, making it impossible to invite users to chat if they are on compliant Matrix servers.
This will be referring to enforcing MSC4311 (https://github.com/matrix-org/matrix-spec-proposals/pull/431...) stripped state validation. Synapse announced a 1 year compatibility window to avoid ecosystem fragemtnation: https://github.com/element-hq/synapse/issues/19943. However, due to MSC4311 not better outlining how to handle compatibility, another server implementation chose to enforce the MSC more rapidly, breaking compatibility with everyone who hadn't yet implemented the MSC - including Synapse, which hadn't actually implemented it yet. Speaking as the lead of the Matrix Spec Core Team, we should have handled this better. https://github.com/element-hq/synapse/pull/19723 is the Synapse implementation which is now in the process of landing.
As a former XMPP believer, I will say that the extremely fragmented capability state of the XMPP ecosystem, whatever people may claim, is the exact proof that vindicates Signal's position.
what does debunked here mean? like I can right now go on websites with firefox or safari and they will not be displayed properly. I do personally think federation is worthwhile, but I think it's a bit much to say Signal only cares about power and that all their reasoning for what they did are debunked or w/e.
I've attended the eponymous CCC talk and I've never seen any other talk there where the Q&A section has just immediately turned into nearly everyone almost dunking on the presented ideas. It's a rather poor take (or at least "controversial" if you will).
Realistically nothing is ever perfect, but XMPP comes very close. You've got Signal-introduced double-ratchet encryption if forward secrecy is your jam (so it's as "E2E-secure" in practical terms) and you've got a healthy ecosystem of independent client and server implementers, and service providers to choose from.
Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company?
As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it.
Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.
Why not? Plenty people already use a dedicated '2FA' phone for Work under BYOD policies when they don't want to install any 'work' software on their 'personal' phone.
Depending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you have to pick your poison. If E2EE is important, you also need to determine how encrypted you want your messages to be (as both XMPP and Matrix carry quite a bit of identifying metadata in its unencrypted headers).
For most people and use cases, either will probably do, but if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal.
> if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal
So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delivery?
I mean, as opposed to using something like XMPP which you can completely use over Tor and never even reveal which server you use/that you use XMPP, from a client running a secure and minimalistic OS and no service-in-the-middle ?
Some would label Signal as a honeypot and it would be difficult to falsify that.
Apple, at least, maintained a historical database of your phone's notifications, that it did not clean up after they expired. That includes all notifications from Signal telling you that person XXX has sent you a message that starts YYYY <facepalm>
Forgot about that and that def was bad, though imo not really on Signal and would have just as much affected any XMPP app, no? To me this definitely didn't "[throw] it all away" as in your messages were still only on your phone and never decrypted on any server or w/e.
Well that's the thing, you just don't know what happens once you let Signal send notifications via Apple/Google - clearly they get them plaintext, and who knows if they're retained and subpoena-able directly from Apple/Google. The leak via notifications DB not being cleaned up is just the shot across the bow. You pay a price for convenience.
Anyway, I'm not OP, and they have a mad setup (XMPP via Tor) which is a flaky solution most people wouldn't go for. In general, if you're not going to such extreme measures of hiding among the crowd of Tor users to mask your metadata, you're better off directly connecting and hiding among the crowd of Signal users, rather than hosting your own instance.
to be clear though notifications do the decryption on device themselves. signal uses apple/play services only to notify the device that there has been a message, none of the contents are delivered over these services. if you cant trust the device to do that then no messaging app could ever be secure enough
> Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?
(Note that I don't care about cryptocurrencies except for the cryptography behind it)
There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made for (anyone with a copy of the chain can potentially be the recipient of either the money transfer or the encrypted message).
If people were really serious about privacy and secure messaging they'd look into this instead of constantly attacking the concept.
But then of course there are entire armies of shills who have a vested interest in pushing a narrative explaining that services, at best, collecting metadata and, at worst, being backdoored are offering "secure messaging".
I'm only using Telegram and I don't believe for a second it's secure and private (it's got, supposedly, "one on one" E2EE but not for groups). But at least they're not posturing as the most secure and private messenger on earth.
Signal ghosts people or gets very evasive on other questions to. They've also refused to update their privacy police since they started permanently keeping sensitive user data in the cloud. They can only scream "Don't trust us" so loud.
Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.
Perhaps it shouldn't necessitate it, but I can't think of a good reason why not.
If it were expensive to release it, that would be a reason. But it costs roughly zero dollars to create a public repo on GitHub and a cron job to push to it once a day.
Making the system public potentially increases the likelihood of a hack, which would be bad for Signal users. But relying on this argument to keep the source secret is, I think, a confession that your security is below par. Or to put it the other way round: A secure software system remains secure even if its source code is public, so making your source public is a strong signal that you are confident in your security measures. Security isn't something I expect all non-profits to focus on, but I think it would be telling for Signal to hide behind this reason.
1. A for-profit company rationally doesn't want competitors launching products using their code. Why would a non-profit care at all?
2. An app like Signal depends completely on network effects, so there's even less motivation for a community-fragmenting fork than in most OSS cases, where you'll notice that forks are already rare. There would have to be something very weird or contentious happening with the original codebase for people to want to fork it -- otherwise it's in no one's interests.
> Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.
Actually you're mistaken. Under the 501(c)(3) tax code rules, they are required to act in the public good. Nobody has sued them to enforce this though, but I'd at least like them to acknowledge the game they're playing by ghosting us all on this.
American 501c3 law is extremely lax compared to analogous structures in the EU. A number of 501c3s are run as sinecures where a board (self-selecting, so no input from the membership) just hires its friends for well-paid positions that involve little work. Because the law is so lax and permissive, making a case that a given org is not acting in the public good is extremely rare and uphill.
OpenAI is a 501c4 not a 501c3. Also the structure is much more complicated for OpenAI.
Nevertheless the point stands - I don’t see what relationship company organizational mission has with their technical responsibilities. Indeed, if the open sourced everything, standing up a clone would be easier which creates funding risk due to a race to the bottom of people who didn’t invest into the R&D investing very little additional to compete.
'Apple' was a metaphor to Newton. 'Open'AI was meant as a promise; one that they've since broke both to some of their founders as well to the general populace. Reminding people of that broken promise doesn't seem that wild.
> According to Wozniak, Jobs proposed the name “Apple Computer” when he had just come back from Robert Friedland's All-One Farm in Oregon. Jobs told Walter Isaacson that he was "on one of my fruitarian diets," when he conceived of the name and thought "it sounded fun, spirited and not intimidating ... plus, it would get us ahead of Atari in the phone book."
Not only that. I also question how they pick new features to implement. For example usernames - I am not going to trust another "private" IM app username feature same as what Telegram and WhatsApp questionably chose. Compromise on this? Well, then even WhatsApp and Telegram are good enough with compromises.
Separate usernames completely from phone numbers. Period.
There's a reason Signal is still "US based". No, I am not talking about some CIA/NSA/DoD/tom/jerry funding conspiracy, just good old human obstinacy and hubris. They don't give a f about who uses it, it's about who makes and maintains it all.
I'm being cheeky and implying that the reason signal's active backend is not disclosed as hoped for in a prior poster's comment is because the CIA (or other intelligence) is involved in it.
This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.
> If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.
How do they perform address book matching without an phone number? It just being accessible by SGX does not really count as not storing it.
Problem with phone numbers is they are to short to store as a hash, since you can brute force the sha256 of an phone number in a trivial amount of time on a single consumer device
Wouldn't a payment of about $0.05 do the trick? My understanding of most kinds of spam is that it relies on being able to deploy hundreds of thousands of bot accounts just to get a few hits.
The most ubiquitous, absolutely. Their data collection is unparalleled. They're on almost every website, app, they have fingers into payment and browsers and mobile OSes.
In terms of what they do with big data there's more evil parties like Palantir but data abuse starts with collecting it, and I would object to it even if Google promised to only use it for good. For me my privacy is already violated when my data is collected, not just when it's abused. And I do consider Google's use of that data abusive, just not in the worst ways.
Why? Just raise the prices if they get more spam on non-google payments.
I've literally registered a Signal account on one of the free SMS sites floating around. Why would spammers choose the payment route over phone numbers? They would just choose the one that's cheaper.
googles obligation to hand out all account linked info notwithstanding, one may still create google accounts without associating a phone number, by doing so on old android versions. signal does however explicitly force credit card info here, thus providing direct individual traceability ..
Nobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal.
They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.
Claims without evidence can be dismissed without evidence.
Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX.
If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?
They are the largest messenger that has E2EE backups by default.
If I was the NSA, I would be using the fact that signal uses AWS for their backend combined with the cudgel that .us.gov has with the AWS govcloud contract to mandate that all traffic to and from signal's backend also gets routed to NSA traffic analysis servers, which could then be correlated with other sources like ISP data to get a pretty complete record of all Signal message metadata.
To be clear, I use signal pretty heavily, but that's because my threat model doesn't really include competent .us.gov actors. I don't think that they'd either prove they're doing this or go through the trouble of parallel construction over anything in my messages or who I'm talking to.
Nobody is arguing the e2ee isn't valid, its useful as a metadata collection platform, which is all they care about. Former NSA and CIA Director Michael Hayden famously stated: “We kill people based on metadata." and then he tried to hold back a smile and said "but not with this metadata". It's usefulness as a metadata collection platform becomes much less useful if people don't trust it, so of course it's secure.
If you can convince as many of your enemies (the american people who politically organize against them) to use the same platform, your job becomes easier than having to ETL from 20 different privacy platforms..
To be honest, I use signal, I have nothing to hide but it is useful in that nobody can spoof me (easily). I even talk to my 60 year old mother on signal. It has it's uses. But the EFF is definitely a federal psyop to get people using tools and techniques they control.
Just look at the people who created TOR, they're all feds. All these projects are funded by feds. These tools are advertised in CIA recruitment campaigns, they are literal weapons to circumvent nation state firewalls and deliver psychological weapons, overthrow governments or allow covert recruitment of foreign traitors.
I'll see your conspiracy theory and raise you one: What if the feds fund tech privacy projects specifically so that people like you won't trust them, and instead embrace privacy nihilism?
This is a known strategy of the Kremlin, by the way. They fund opposition groups which protest them, and then leak the fact of that funding so that people who are genuinely upset at the Kremlin get confused about who is captured opposition and who is legitimate.
It can be a signal in some cases, but funding sources are not a reliable way to make a conclusion about a group's motivations.
True, if they're not even going to allow that for payment then they might as well remove it from the app altogether. Because what's the point if they don't even believe in it themselves.
Meanwhile SimpleX and Delta Chat (over chatmail protocol) have it by default for years without any payment requirements, offer relatively better level of data security and are available on F-Droid main repo.
Especially with AI agents being more common this would be very useful. I'd prefer to use Signal over telegram but haven't gotten around to getting another number.
usually, the implication of ZKP is that you buy coupons and claim them without attribution. in this coupon scenario the ZKP can just be a blind signature scheme.
however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.
Main caveat is that ZKPs are probabilistic. The protocol (number of rounds etc) determines how sure, e.g. 99.9%. But never 100%.
Second caveat: tech- and crypto-bros play fast and loose with the term "ZKP", either because they don't know any better (marketing) or they straight up lie. Whether any application you run actually uses ZKP (or any other cryptography scheme) is unknown unless you have the source code.
Yes, very much so. It is basically a standard across the western world for politicians, journalists, whatsapp refugees... Of course there are many alternatives but most of them have most of their users here, on HN.
MacOS, iOS, Windows, Linux, Android are all made in the US and are also virtually universally used. This idea that people avoid American products is super niche.
linux us made in the US? An open source OS, with collaborators from all over the world initially started by a finnish student and still actively the main orchestrator of it, linux torvalds. Not to mention the thousand distros derived from it.
Country of origin doesn't tell you much on its own. Linux is American too, and few question its trustworthiness. What matters is the code being open source and auditable, not where the maintainers live.
"Linux" doesn't keep centralized records that the government can get their hands on. The fact is that the government in the US can (and does) march into US companies and demand access to their data. The government will install their devices on the company's network and even take over entire parts of their offices. What your data sits, who has access to it, and what kind of record the local government has of abuses of their authority are very important things to consider. Much more important than if the code is open source.
I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".
Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there.
I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.
A bare minimum for a company that offers private communication services to people like whistleblowers and activities is that they clearly and plainly explain to their users what their risks will be when using the service. Signal fails at this. They outright lie to their users. They've started permanently keeping sensitive user data in the cloud, but they've refused to update their privacy policy to reflect that. Misleading or lying to users about their risks when their lives and/or freedom are on the line is unforgivable and disqualifies Signal as being a service anyone should consider.
Unless your adversary is divine this isn't true. In general people who believe this way make really bad trade-offs and as a result probably have worse security than most people.
The average person might be legit worried about dragnet (non targeted) evensdropping of non encrypted communication. This is rational given what Snowden said.
So for the average person, WhatsApp (which is E2E encrypted) is probably quite secure. SMS is not.
Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?
I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?
> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?
While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data.
I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.
It's true someone snooping at either end of a conversation could over time correlate timing and sizes to show that two users are communicating, but that's the most they can do. Signal is not peer to peer so you're not connecting to your recipient, and signal itself has enough raw volume that simply correlating sizes and timing of a small number of messages wouldn't really be sufficient to know who is communicating with who.
I think they could make that significantly more difficult by adding csprng delays and padding to the messages. That way you can't really effectively correlate timing and sizes without direct access to signals inner workings. I'm not sure what signal's actual throughput is, but if think as a paid feature it could be economical.
Another crazier way would be to send every message to a large number random latched recipients. Good way to 1000x your bandwidth.
> The metadata is as valuable as the data.
This can be true if you are able to get ahold of a user's device and access their signal messages. It's not true in most other cases. I don't particularly care if you know that I am talking to someone specific as much as I care that you don't know what I'm saying.
> Ex-NSA Chief: 'We Kill People Based on Metadata'
> Hayden made the remark after saying he agreed with the idea that metadata - the information collected by the NSA about phone calls and other communications that does not include content - can tell the government "everything" about anyone it's targeting for surveillance, often making the actual content of the communication unnecessary.
Isn't it? I think it has a setting, disabled by default, to proxy connections via a Signal server. If you're not doing that ... it must be P2P? Probably with the IP address of the person you're communicating with in the header of every packet?
This setting is "Always relay calls", and the only difference it makes is for already established calls. Messages and calls setup always go through Signal's servers.
> the surveillance networks can capture metadata - who talks to who and when
If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.
wake me up when signal can be used with no significant loss of feature or extra-hoops like signal-cli+SMS on non-google/non-apple devices like my linux desktops / linux phones.
I'm curious about the cost because you can buy a phone number for Signal for ~10 cents (spammers likely get them cheaper). I would still buy it because you don't have to worry about losing your number or something.
I stopped using signal when they made their weird change about not supporting SMS due to... whatever weird problem they had with normies. Come on dude. Even my realtor was on Signal. Instantly killed the product.
I know for a fact If you use "signal" matrix or whatever "security" app, you will get branded a terrorist in India, your life will be upended and you will face a long list of problems.
Yes that's bad but that's an Indian government problem, not a signal or other messenger app problem. And really, it sounds like there was a lot more going on with these people than just using a particular app. Discord and WhatsApp are mentioned too.
India also bans most satellite phones by the way. I have one so I looked into that as to not get caught out travelling.
The big deal is, having talked to security people, they are "fine" with WhatsApp because the theory is, they get data from whatsapp so they have some sort of backdoor access.
They are pretty chill with WhatsApp which id unexplainable
Maybe WhatsApp gives them a ton of metadata like all their contacts, when they chat and with who, IPs, etc. Signal only gives out either time registered or last used last time I checked.
Molly is a security-hardened Signal client only on Android for people unfamiliar. They went through a period of not updating (there were no security updates during that time afaict), but now releases should happen faster on top of Signal.
In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.
I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..
Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.
If you're using WebSocket, how do Google and Apple see metadata? Can someone explain why it's so difficult to make a decent chat app divorced from their ecosystems?
Can you point where Signal uses proprietary blobs?
Also, I'm using Signal without the play services notifications just fine. Notifications that don't contain any message content while transiting anyway. The display of the notification was the issue with iOS bug and that would have affected molly as well (if it was on iOS).
I was using Silence from F-Droid for a while back in the day because of these issues, but the lack of interop and needing to make everyone move again soured me on the whole thing. I would rather just get people on XMPP or Matrix and not use some sketchy phone-first app at all. For SMS I use Fossify Messages, which I think was a fork of QKSMS. I don't use SMS as primary or sensitive comms, only as needed. Same as email, basically, but less useful.
I really liked silence. I stopped using it when f-droid said the source code was no longer available. Fossify messages is the best replacement I've found.
(I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)
The problem for me is writing on a mobile device is a terrible user experience.
When I'm at home I don't wanna use a virtual keyboard on a 6.3" (or 7.9 unfolded). I just want to use my triple monitor PC setup with a real keyboard and a wealth of display space.
Mobile is cool for on the go but a productivity killer.
That's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want.
Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation.
It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration).
You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services.
But GrapheneOS relies on a proprietary, black-box security chip from Google... who pinky-promised to open-source it but never did, and that just doesn't sit well with me.
I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/method where the OS is not really aware of what's going on.
I don't believe that they will use this against me. But I do believe in the right to use devices without backdoors for everyone, so I support something else instead.
Qubes can be used together with Heads and a hardware key to verify the boot integrity. Works for me. This is more than good enough for most users, unless you think that your device can be captured while being on by a state adversary I guess. Also it doesn't remove control from the user unlike with GrapheneOS.
I tried it and it was fine while it worked, but eventually I had to go back to regular Signal because Molly's updates did not follow Signal's closely enough, and at some point the server code changed enough to where I was unable to use it for an unacceptable amount of time (after checking, it took them weeks to update). Something to keep in mind if you're not using a custom server.
reply