@simplex@mastodon.social avatar

simplex

@simplex@mastodon.social

SimpleX - the first messaging platform without user identifiers of any kind - 100% private by design!

Security assessment: https://simplex.chat/blog/20221108-simplex-chat-v4.2-security-audit-new-website.html

This profile is from a federated server and may be incomplete. Browse more on the original instance.

simplex, to random
@simplex@mastodon.social avatar

SimpleX network: v5.8 released with private message routing, IP address protection for messages, files & media, new chat themes and more!

Also new in v5.8:

  • group improvements - reduced traffic and additional preferences.
  • improved networking, message and file delivery.
  • Persian interface language - thanks to our users.

Read more: https://simplex.chat/blog/20240604-simplex-chat-v5.8-private-message-routing-chat-themes.html

Install the apps: https://simplex.chat/downloads/

Please upgrade your self-hosted servers!

See the new server guide: https://simplex.chat/docs/server.html

simplex,
@simplex@mastodon.social avatar

@anchel updated!

simplex, to privacy
@simplex@mastodon.social avatar

Protecting children's safety requires privacy and end-to-end encryption:

https://simplex.chat/blog/20240601-protecting-children-safety-requires-e2e-encryption.html

Proposed "upload moderation" would fuel the very problem it aims to solve, undermining rather than protecting children's safety.

simplex, to random
@simplex@mastodon.social avatar

Please sign the petition to the EU Council by the Global Encryption Coalition about the proposed "upload moderation" that would create serious security and privacy risks:

https://actionnetwork.org/petitions/global-encryption-coalition-joint-statement-on-the-dangers-of-the-may-2024-council-of-the-eu-compromise-proposal-on-eu-csam

We all want to solve child abuse problem, but these proposed measures will make it worse:

  • centralized scanning of family photos risks leaking them to criminals, increasing child abuse.
  • the criminal case against Meta in the state of New Mexico shows how its content algorithms enable child abuse.
alshafei, to privacy
@alshafei@mastodon.social avatar

Comparison of instant messengers: "SimpleX probably has the best privacy and anonymity of all the messengers compared here"

https://eylenburg.github.io/im_comparison.htm

Follow @simplex to keep track of the latest updates and ongoing improvements.

#Privacy #Anonymity #Security #Messengers

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei

sorry, where did you get 3 days from? It was actually 10 days by 2 people with 5 of them billable (as the report says).

Additional, longer assessment is coming this year.

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei

Ed448/Ed25519 curve choice is controlled by the client, and currently Ed448 curve is not used. What are you specific objections to Ed448 curve?

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei

To reference Signal algorithm specs: https://signal.org/docs/specifications/doubleratchet/#integration-with-x3dh

https://signal.org/docs/specifications/doubleratchet/

It does recommend X448/X25519 algorithms and AES-GCM.

All seems rather boring, isn't it... What's daring here?

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei

we understand the limitations of AES-GCM, and they do not apply here, but we will revalidate it.

Groups don't use shared keys, they are based on pairwise ratchets.

The encryption scheme evolved with the addition of sntrup761 to double ratchet, and if AES-GCM proves suboptimal, it can be replaced too.

Also, it is customary to follow a process to report vulnerabilities: https://simplex.chat/security/

Doing it in public forum hurts your credibility.

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei

> My complaint with Curve448 is that most things don't use it, so implementations are less reviewed.

OpenSSL (both library and the tool) includes it for a long time.

> The primary reason to select 448 over 25519 is a "biggest rock is best rock" approach to cryptography parameters. It doesn't help in any realistic scenario, nor against quantum attackers at all.

This view is contrary to the advice from DJB to always choose a bigger key size that is necessary.

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei

arithmetics says it's 4 :)

And they generously billed 5 days having spent more than 10 (engineer-days).

TOB are very good with Haskell btw, and double ratchet implementation was one of the focus points.

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei

Whether you like design or not is secondary to whether it is a secure or not, isn't it?

Design evolves though.

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei no, we absolutely love criticism - it's what was driving the design evolution so far, and will continue.

Just please send any real findings (if you get deeper) privately - as real people security depends on the app, whether you like it or not.

But the criticism of the design itself is very appreciated.

So far it's all good. AES-GCM given how it's used seems adequate, but we will revalidate it.

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei In DR neither party has control of the AES key to use, so maybe I am missing something, but I don't think this attack works... will re-assess.

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei two more assessments are coming this year - one focussed specifically on the protocols design, and another on implementation.

simplex,
@simplex@mastodon.social avatar

@soatok @triskelion @alshafei I agree about full disclosure once fixed - it's what our policy is, similar to OpenSSL's.

simplex,
@simplex@mastodon.social avatar
simplex, to privacy
@simplex@mastodon.social avatar

Improving communication requires making many hard choices:
https://simplex.chat/blog/20240516-simplex-redefining-privacy-hard-choices.html

simplex, to random
@simplex@mastodon.social avatar

We are upgrading the preset SimpleX relays to the new version - it is compatible only with the apps starting from v5.5.3 (released early February) - please upgrade to the latest version and ask your friends to upgrade too.

simplex,
@simplex@mastodon.social avatar

@MartinBe @MartinaNeumayer we have the GitHub issue, but it would be really helpful to have the logs from the device when it happens. Also, having a full list of settings might help reproducing.

echo_pbreyer, to random German
@echo_pbreyer@digitalcourage.social avatar

🇩🇪270 Wissenschaftler aus 33 Ländern zerreißen den neuesten Vorstoß des EU-Rats zur in der Luft und warnen vor "katastrophalen Konsequenzen":
▶️untergräbt Kommunikations- und Systemsicherheit
▶️nie gekannte Überwachungs- und Kontrollmöglichkeiten
▶️Millionen Falschtreffer zu erwarten
▶️ ist Techno-Solutionismus und wird Kindesmissbrauch kaum eindämmen

https://nce.mpi-sp.org/index.php/s/eqjiKaAw9yYQF87

simplex,
@simplex@mastodon.social avatar

@echo_pbreyer instead of dramatically increasing the risks for children by reducing their and their family privacy, the legislators should consider raising the age where parents have the right to access children information to at least 16 years, as technology platforms can't identify sexual predators masquerading as children.

By the time the abuse materials distributed it's already too late - so by reducing the privacy legislators are trying to hide the symptoms rather than solve the problem.

simplex,
@simplex@mastodon.social avatar

@echo_pbreyer in the stand-off "protect children" vs "protect privacy" we will lose both. The reality is that the only way to protect children is by increasing their and their family privacy.

That is of course if legislators really want to protect children, and are not simply using it as a pretext for large scale surveillance against their citizens.

Let's not be fooled by "protect the children" narrative - if Chat Control surveillance succeeds, children will be a collateral damage.

simplex, to random
@simplex@mastodon.social avatar

SimpleX Chat v5.7 released:

  • quantum resistant e2e encryption will be enabled for all contacts.
  • forward and save messages without revealing the source.
  • in-call sounds and switching sound sources.
  • customizable profile images - from square to circle.
  • better network connection management.

Also, we added Lithuanian interface language to Android and desktop apps - thanks to our users!

Read moret: https://simplex.chat/blog/20240426-simplex-legally-binding-transparency-v5-7-better-user-experience.html

#privacy #security #messenger

simplex,
@simplex@mastodon.social avatar

@anchel done

simplex,
@simplex@mastodon.social avatar

@anchel weird, not for me. Please try force-refresh the page maybe?

simplex,
@simplex@mastodon.social avatar

@anchel I see, you were asking about simplexmq... Updated :)

GrapheneOS, to random
@GrapheneOS@grapheneos.social avatar

In the latest release of GrapheneOS, you can now enable hardware memory tagging for all user installed apps on the Pixel 8 and Pixel 8 Pro to make them substantially harder to exploit. This is particularly useful for apps like Signal and WhatsApp.

https://grapheneos.social/deck/@GrapheneOS/111479244810981775

simplex,
@simplex@mastodon.social avatar

@GrapheneOS

> E2EE does no good if app is exploited.

I think this is a very wide and generally misleading statement. It's not that black and white. You are talking about different attack vectors, and the purpose of E2EE is to protect from the operator, and the attacks you describe are from untrusted/malicious contacts. Also, the attack via media that would lead to the compromise of E2EE with other contacts is very hard - it's on you to demonstrate it, before stating it's possible.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • InstantRegret
  • ethstaker
  • magazineikmin
  • GTA5RPClips
  • rosin
  • modclub
  • Youngstown
  • ngwrru68w68
  • slotface
  • osvaldo12
  • kavyap
  • DreamBathrooms
  • Leos
  • thenastyranch
  • everett
  • cubers
  • cisconetworking
  • normalnudes
  • Durango
  • anitta
  • khanakhh
  • tacticalgear
  • tester
  • provamag3
  • megavids
  • lostlight
  • All magazines