this post was submitted on 15 Jan 2025
125 points (94.3% liked)

Technology

60486 readers
4102 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
all 15 comments
sorted by: hot top controversial new old
[–] Sparkega@sh.itjust.works 12 points 15 hours ago (2 children)

What are everyone's thoughts on Molly, advertised as a hardened fork of Signal?

[–] EngineerGaming@feddit.nl 1 points 29 minutes ago

I've used it because it actually allowed me to register, while the registration in the official app broke (my best guess is due to lack of Google services, because that's the popup the app got stuck on). And if I knew about it earlier, I could've used it to register in an Android VM and then tie a desktop client - because unlike the original, it did not force you to use your camera, you could just use a link. Another important quality for me is the ability to use arbitrary Socks rather than Signal's own - when every protocol has a chance to be blocked, flexibility is important, and having a standalone proxy may be more convenient than a whole-device VPN (that you'd have to keep on all the time to receive notifications).

[–] dracs@programming.dev 3 points 1 hour ago

I've been using it for several months mostly due to it's UnifiedPush notifications support and been really happy with it.

[–] Fontasia@feddit.nl 9 points 14 hours ago

To be even more critical of Session, it uses Oxen which is like someone took Onion routing and decided to dress it up as a cryptocurrency grift

Session & Lokinet - Oxen | Privacy made simple.

[–] aport@programming.dev 26 points 19 hours ago (2 children)

I'm OOTL, why do people want an alternative to Signal? It thought that was the good app

[–] kbal@fedia.io 22 points 17 hours ago (3 children)

It's centralized, it doesn't officially allow 3rd-party clients, it requires a phone number, and the desktop app kinda sucks. I use it anyway, but it could be better.

[–] Viper_NZ@lemmy.nz 2 points 32 minutes ago

That desktop app really is super hot garbage.

[–] rottingleaf@lemmy.world 1 points 22 minutes ago

The "centralized" part is not a problem with their protocol and it's well explained.

The 3rd-party clients thing ... I agree with, but one can find justifications for that too. They probably don't want people to use it for filesharing with uuencode and base64. Or even for VPNs, like they did with Tox when it seemed to have a future.

The phone number thing sucks, but there's a need to defend against bot registrations somehow.

The desktop app sucks absolutely and conclusively. If there were a library one can use to make a Pidgin plugin, it would be a godly gift.

[–] EngineerGaming@feddit.nl 1 points 28 minutes ago

Not just sucks, but is limited. Like, you can't even register there! To use Signal without a smartphone, you'd need workarounds that are unfriendly to an average person! All while a computer is far easier to make private than a phone.

[–] Confetti_Camouflage@pawb.social 20 points 18 hours ago (2 children)

I don't know about other people, but the only thing I don't like about Signal is that it is centralized. It seems to be the only option to actually get everything right for security though from what I hear.

[–] rottingleaf@lemmy.world 1 points 19 minutes ago

I personally think they could replace the "centralized" part with the "relay" part. Seems technically possible with their protocol. Their center plays mostly the relay role. So it would be a bit similar to Usenet, or to NOSTR, or even maybe to something like old Freenet.

But yes, there are good arguments that making it decentralized would slow down necessary changes and fixes.

[–] Soatok@pawb.social 16 points 17 hours ago (1 children)

That's a reasonable thing to dislike about it.

I dislike that I can't reply to another message with a sticker.

I also dislike that, despite having admin access, I can't delete abusive messages left in groups for anyone but myself. That makes it unsuitable for building communities.

[–] ZaphodWilde42@lemmy.world 2 points 11 hours ago

The replying with stickers bugs me so much, your pack has been helpful too. Hopefully we'll eventually be able to edit created packs though.

[–] vollkorntomate@infosec.pub 32 points 20 hours ago

[…] it uses the X25519 public key… as a symmetric key, for AES-GCM.
[…] anyone that knows the public key can decrypt it.

Ouch.