My experiences with anonymous messaging 02-01-2017, 05:03 PM
#1
So as a prologue, I'm fuckin paranoid.
I check my mails from terminal, I review the code of nearly every software I use, I never accept cash with sequentially deterministic ID-s, I always try to go to work on different routes.
So you can believe me when I say I spent a shitload of time researching the most secure and anonymous messaging protocol and software in the market.
Of course you have EFFs comparison table (https://www.eff.org/node/82654) that can be used as reference, it's good for normal people who just want to speak with their friends without NSA daddy knowing it but not for
a paranoid one like me, or someone with attachment to criminal activities (definitely not me
)The motivation of this post is that I saw that people on the forum use varied platforms for communicationg, for eg I saw Enders is using nullPM, others use ricochet etc...
I have more things to consider before using a self-claimed "secure" chat app. Among the essential things like end-to-end encryption and perfect-forward-secrecy I do my code audit manually and check up the people writing it, as well as documentation.
Messenger secret chats
While facebook claims that they implemented openwhispersystem's signal protocol, they showed no evidence of it.
OWS had a blog post mentioning a code review that had no issues with the implementation but a nonprofit organization, even if with good intentions, can be persuaded by one of the richest companies in the world, and there is no proof that facebook won't
make a backdoor into it later. So Messenger is completely out of the question
Signal messenger
This is the one I recommend to every basic user. It's transparent, has good quality code and smart people (OMG MOXIE MARLINSPIKE) behind it.
The two issues is that it's poorly documented and the protocol only gives sense if you are a programmer and read the code.
Second one is when you ask them about "what if NSA takes down you central severs and make a backdoor"? They come with a
really good answer: "You can host your own server". And indeed they have (actually 2) repositories for own-hosted signal servers but after a LOOONG
argument with them I finally got the answer: It's nowhere even ready, so in fact it's not an option and will not be in the foreseeable future.
RIcochet
Ricochet is still in early beta. It has good documentation of the packet layer, utilize TOR and has somewhat good quality code but the people (or more precisely the single person) behind it is a hobbyst that gives
space to much suspicions. While the project has many contributions, If you check the commits you can see that 99% of it is John Brook's, nice work whatsoever but I rather trust someone with crypto
who didn't learn it from youtube.
XMPP
This is philosophically out of the picture. XMPP is fucking heavy and "anything that's meant to stay hidden has to be small", an essential law of hackers.
But.. there's OTR and stuff. Indeed OTR is one of the greatest things in instant messaging thats a big +
But on the other side most "secure" XMPP servers advertise SSL as security feature for you, while that's not even a challenge to bypass on one of the endpoints.
I don't trust servers. Even if they say no logs. Nobody will and nobody can prove that.
Also OTR has a fingerprint that can easily transfer you to the ISP or NSA blacklist (just like torrents)
IRC/SILC
IRC - nope, it's fuckin hard to configure securely. I ran it from a VM with special setup, modified the code and I'm still not convinced that something won't leak. IRC is only lightweight in the protocol, not in the software.
SILC - this one is good, except that it's fuckin old. It was written by a single hobbyst and has not seen any update in nearly 3 years. Also it no longer works on all platforms. Hovewer the simple configuration and dynamic pubkey loading
are great things to have against IRC
Chatsecure
Chatsecure with orbot makes a good software, not a good protocol. The problems with it is already discussed in the XMPP section since it's mostly XMPP with tor

Bleep
First I was really excited to see Bleep. BITTORENT FOR CHATING OMG.
However there's no other way to describe it than: SCAM. For real.
Firstly it's not open. WTF, security without transparency is like a car without wheels.
Secondly it's not serverless at all. I sniffed my device while chatting to my girlfriend with it and I saw that every single one of my messages got forwarded to Amazon AWS servers (in encrypted form of course).
But that's not p2p, with torrent-based chat the only server I want to see besides my peers is the bootstrap, that's not what happened. Big boo for bleep
Wickr
Same. It's not open and also prefers an enterprise solution. Money has no place in secrecy, if you pay for privacy then you are the product.
Also the protocol itself is not documented on technical level, only marketing bullshit. I WANT TO SEE THE MATHS.
Tox
The current winner.
The protocol itself is not only open but completely separated from the client. That means you can make your own client above it. There are several ones, of course.... I use my own.
It's peer-to-peer (for real), NaCL library has high reputation and trust, has voice and video calls, file transfer all basic shit. But currently this is what I put my trust in, an
- open-source
- light-weight
- end-to-end encrypted
- hackable
- updated
- no organization controlled
- No mobile-phone or email attached
- Not vulnerable to traffic analysis by ISP
Feel free to correct me and suggest other software to be torn apart
Reflection of a lonely being trapped in a false time
exposing your precious secrets for I am scared of mine
tox: E321B7DD931582DE0277E578578F37B0E41FB9838E9466035235BFDE5E1F3C1C10026A5982BF
exposing your precious secrets for I am scared of mine
tox: E321B7DD931582DE0277E578578F37B0E41FB9838E9466035235BFDE5E1F3C1C10026A5982BF
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)
















![[Image: giphy.gif]](https://media.giphy.com/media/epRoTgGfkLpxS/giphy.gif)














![[Image: A993dMx.png?1]](https://i.imgur.com/A993dMx.png?1)