To be even more critical of Session, it uses Oxen which is like someone took Onion routing and decided to dress it up as a cryptocurrency grift
What are everyone’s thoughts on Molly, advertised as a hardened fork of Signal?
Don’t care too much about the supposed hardening, but it’s on FDroid and has UnifiedPush, so I use it over Signal
I’ve used it because it actually allowed me to register, while the registration in the official app broke (my best guess is due to lack of Google services, because that’s the popup the app got stuck on). And if I knew about it earlier, I could’ve used it to register in an Android VM and then tie a desktop client - because unlike the original, it did not force you to use your camera, you could just use a link. Another important quality for me is the ability to use arbitrary Socks rather than Signal’s own - when every protocol has a chance to be blocked, flexibility is important, and having a standalone proxy may be more convenient than a whole-device VPN (that you’d have to keep on all the time to receive notifications).
I’ve been using it for several months mostly due to it’s UnifiedPush notifications support and been really happy with it.
Let’s start from the fact that Session isn’t Signal form anymore. It was started as that but now it has its own protocol and it’s fully decentralized. It doesn’t require any user data to operate (not a phone number nor email). Links to a protocol evolution stage from 2020 doesn’t help either. Nowadays all messages are end-to-end encrypted (except just public chat rooms). The post looks like uneducated rant or worse direct attack on Session. Which is the most secure and private messenger out there at this moment. Session and Signal are simply from different worlds now.
I’m OOTL, why do people want an alternative to Signal? It thought that was the good app
It’s centralized, it doesn’t officially allow 3rd-party clients, it requires a phone number, and the desktop app kinda sucks. I use it anyway, but it could be better.
I don’t know about other people, but the only thing I don’t like about Signal is that it is centralized. It seems to be the only option to actually get everything right for security though from what I hear.
That’s a reasonable thing to dislike about it.
I dislike that I can’t reply to another message with a sticker.
I also dislike that, despite having admin access, I can’t delete abusive messages left in groups for anyone but myself. That makes it unsuitable for building communities.
The replying with stickers bugs me so much, your pack has been helpful too. Hopefully we’ll eventually be able to edit created packs though.
[…] it uses the X25519 public key… as a symmetric key, for AES-GCM.
[…] anyone that knows the public key can decrypt it.Ouch.