Skip Navigation

Posts
15
Comments
49
Joined
4 yr. ago

  • Maybe I'm confused, do the DeltaChat and ArcaneChat clients only work with DeltaChat/ArcaneChat servers?

    The "ArcaneChat/DeltaChat servers" are just normal email servers with some default configurations and tweaks for privacy/security and speed

    Edit: forgot to mention I can see the sender & recipient addresses (Signal uses sealed sender to minimize this metadata leak)

    Signal needs to "seal sender" to be able to send messages anonymously since their service is not anonymous and you login with your phone number, in ArcaneChat it is like you are "sealed sender" from the very beginning, you don't register with phone number or any private data, you log in anonymously always, currently you have an static anonymous identity, and have to manually change it over time if you are the most paranoid person in town, but in the future the app might implement anonymous identity rotation

    I can also see what time the message was sent this is the kind of metadata Meta collects through Whatsapp even though they also encrypt message content.

    Nothing that the server doesn't know, the server knows the time at which you try to send a message because well you are asking it to do so at that time. But I agree this is a problem with stored messages if the server gets audited at a later point, by default with a single device messages are deleted immediately and otherwise after 20 days so still it is limited what they could get, but this can be improved, the header doesn't need to have a real date could be whatever fixed date while the real date is protected in the encrypted part, this needs to be done ๐Ÿ‘

    It doesn't seem - although maybe it now does - that DeltaChat nor ArcaneChat support key ratcheting, so if someone's intercepting messages they can decrypt all future + past messages.

    This is a pretty theoretical situation, first the attacker needs to get control of your chatmail provider/server and start collecting your messages, secondly you need to happen to be using disappearing messages since otherwise when they get access to your phone to get the key they can as well just get all your messages that are available already decrypted in the app, since you need the messages to be ephemeral, in that case you can as well create a temporary profile, ex. For some protest or activism and delete it after the operation is finished, and you get the same results of "forward secrecy" without sacrificing the usability of the app, ex. In ArcaneChat it is possible to have your account in as many devices as you want all well synchronized and every device is totally independent, if your phone dies you can keep using it in other devices or add it back to a new phone without losing a single message

  • Hey, how do you know she is named Nancy!? And that she smokes a bit too much! ๐Ÿ˜ฑ

  • I didn't want to advice/promote DeltaChat/ArcaneChat, they are not the only possible way of using email securely, just came here with the meme as a way of leaving out a rant because I have seen a lot of people talking like that and it is by now an urban legend people just repeat like parrots and pointing to articles that basically are misleading. Had a recent discussion about that in the Privacy Guides forum and just came here with the meme to shake the frustration away ;-)

  • it is all about the sassy retro style and base64 MIME body

    more seriously: Signal is centralized and based on phone numbers, and as said by Signal themselves: "Privacy is Priceless, but Signal is Expensive" https://signal.org/blog/signal-is-expensive/ while email infra is WAY more economic and decentralized

    SimpleX maybe but I it is not powerful/flexible nor as solid/mature as email server infra

  • Privacy @lemmy.dbzer0.com

    Some people are stuck in the 80s

  • When you send ANY message (it doesn't matter if it is just text, image or other attachment) it is end-to-end encrypted and on the server it all looks the same, encrypted blobs, it is only visible in your devices.

    If you have a single device the encrypted blobs are deleted immediately after downloading them, if tyou have more than one device, the blobs are stored up to 20 days in the server to give you the chance to sync your devices, if you use "disappearing messages" option or manually select and delete messages or use the "clear chat" option, then you have more fine control when it is removed.

    About your friend being offline, the same rules apply, they will be able to download the images and other messages you send to them as soon as they come back online within 20 days :)

    Of course, if you host your own server you can tweak it to your needs if the defaults of arcanechat.me don't suit you

  • it seems Pleroma is really bad, you have to scroll down until you find the actual comment in that thread that is marked with a different color, it is showing you the top of the thread, anyway, here is the image:

  • This is simply not correct, the page you link is talking about problems of email as a network of different clients and servers. With ArcaneChat and arcanechat.me server there is no metadata leak, the article talks about leaking subject which is simply not leaked in ArcaneChat since it is moved to the encrypted part as many other headers, the To and From headers are needed by the server to know to whom send the message, this is the same in virtually all other messaging platforms, like XMPP, Matrix, WhatsApp, etc. So why is it listed as a flaw of email?

    Here you can see what someone can see in a message sent with chatmail servers, tell me exactly what metadata you got from this message as the server operator:

    That kind of "no no you can't use email in a secure way" is a so outdated urban legend

  • They are not totally the same tho, for example "Delete messages on device of recipients" says "no" for Delta Chat but it is already available in ArcaneChat (will come to DeltaChat "soon")

    Also "Minimal metadata" says "no" while there is no personal data at all required to use ArcaneChat, accounts are fully anonymous hence what metadata and from whom?

    so the table is getting outdated quickly ๐Ÿ˜„

  • Buy European @feddit.uk

    ArcaneChat: Private messenger based in Europe

  • You download the "model" or whatever they use to translate for each language you want, it is like 100MB each IIRC, then you can fully use the language translator offline, by default only English can be used offline the others you manually click a download button besides the language entry in the language selector

  • I know, but I don't want to self-host it, I want to use it completely offline as an app on the phone just as google translator app, also LibreTranslate can't translate in real time using the phone camera like Google Lens

  • it is pointless to talk in theory without actually trying things out, besides the app doesn't have to do only email, in fact it already has p2p support for real-time that can be used for now inside the https://webxdc.org/ mini-apps, and might be used for calls in the future, or just use WebRTC for calls, one of the mini-apps in the store "Live Chat" already has typing indicators btw. The app already has Jitsi Meet invitations integration.

    Chatting in Delta Chat with chatmail feels just as fast as WhatsApp, Telegram etc. sometimes even faster depending on the chatmail server you use

  • WHen i tried it years ago

    you should try it again, Delta Chat is totally on a different level than a few years ago, there has been tons of improvements, I started using it around 2018, now I am even contributing to it

  • Delta chat is basically email.

    and how is that exactly a problem? the protocol is email, but email done right is actually good and fast, as it can be tested if you actually try out the app. The new chatmail servers are optimized for chatting, the main reason classic email providers suck is because they have to deal with spam and arbitrary decisions like gray-listing etc

  • without being picky about quality of translations vs Google Translator, this can't be used offline in the phone/android, right? maybe trying to setup the server side inside Termux could work, this doesn't solve the problem of translating text just by pointing the camera to some banner or traffic sign etc. which is useful while traveling in a foreign country etc.

  • Can DeepL be used offline? One of the killer features of Google Translate IMHO is the ability to download the language models and translate offline, that plus the integration with Google Lens which also can be used completely offline to translate text in real life pointing the camera or from an image is a killer feature I have not seen other alternative provide, I would like to be completely independent from an online service, even if it is Google if you download the languages and block internet access of the app with a firewall that is better than an online service.

    I am currently not using Google Translator, uninstalled the app together with Lens and have a degoogled phone now but I am suffering in silence every day

  • https://arcanechat.me/ is also European (Germany) and is decentralized, fully OpenSource, free/gratis and registration requires ZERO personal data! Everything is End-to-end encrypted between people, server can't see any data which is encrypted and stored only temporarily on the server

  • and the thing is: Telegram having a proprietary server feels more opensource and open to 3rd party clients and developers (ex. bots, mini-apps etc) than Signal, Signal's issue tracker has a bot auto-closing stale issues and several people are completely ignored, never receive a reply

    I highly recommend you to give a try to https://arcanechat.me/ (I am the developer) it is heavily inspired by Telegram, if you want to test it you can join this community group: https://i.delta.chat/#6CBFF8FFD505C0FDEA20A66674F2916EA8FBEE99=&a=invitebot%40nine.testrun.org&g=ArcaneChat+Community&x=3KvvQZfzU4t-9u5s0PF3USGp&i=AQKH9_8x0R0&s=dbGW9xOhRQX

  • Threema is paid (registration tied to payment is already bad for privacy, most people will not register with some crypto-coin etc) and centralized, any centralized service is vulnerable to enshitification, none of them start evil, also it is easier to block by authoritarian governments and can't be used in a sovereign/independent way (ex. own independent server in a local community)

    Session: it has been a long time since I last used Session, at the time my impression was that it was a bit hacky and it was draining my battery and using a lot of mobile data, more importantly Session doesn't seem to have multi-account support, also doesn't seem to support using your own independent server "off-the-grid". Session groups have a limit of only 100 members while in ArcaneChat groups can have 1000 members for now (or even more depending on the server you use, ex. your own)

    none of them have in-chat collaborative/interactive apps (ex. collaborative editor, calendar, shopping lists, split bills, polls, etc.) and games that can be used even while offline

  • I like SIP and XMPP, but in practice I don't have any contacts to use it and the apps are lacking a bit compared to ArcaneChat/DeltaChat, besides the problem of losing groups because the XMPP server went down etc. there are some downsides but yes, if I was not satisfied with ArcaneChat I would use XMPP and SIP, or anything that is open source, decentralized and doesn't require a phone number

  • Android @lemmy.world

    ArcaneChat: Private chats for the family

    Android @lemdro.id

    ArcaneChat: Private chats for the family

    ArcaneChat @lemmy.ml

    ArcaneChat 1.54.4 released!

    ArcaneChat @lemmy.ml

    Spoilers ๐Ÿคซ

    ArcaneChat @lemmy.ml

    ArcaneChat 1.54.1 released!

    ArcaneChat @lemmy.ml

    It happens every time

    Open Source @lemmy.ml

    ArcaneChat: Private chats for the family

    Delta Chat @lemmy.zip

    New Lemmy community for ArcaneChat users

    ArcaneChat @lemmy.ml

    ArcaneChat 1.54.0 released!

    Delta Chat @lemmy.zip

    ArcaneChat now available in Google Play Store!

    Delta Chat @lemmy.zip

    it is time for a change folks!

    Delta Chat @lemmy.zip

    Delta Chat: Delta Chat introduces realtime Peer-to-Peer networking

    Delta Chat @lemmy.zip

    ArcaneChat is now available in official F-Droid store!