this post was submitted on 22 Jun 2025
1 points (53.3% liked)

Technology

71857 readers
4376 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] LWD@lemm.ee 1 points 2 days ago

A few observations from others about why Delta Chat is neat but not remotely close to a replacement for Signal (or probably much else):

It hasn't achieved the bare minimum for serious encrypted messaging

"No, Delta Chat doesn’t support Perfect Forward Secrecy (PFS). This means that if your Delta Chat private decryption key is leaked, and someone has collected your prior in-transit messages, they will be able to decrypt and read them using the leaked decryption key."

https://delta.chat/en/help#pfs

It's great they're being open about the implications. But given that there's better protocols out there (Signal protocol for example), it makes no sense to use inferior apps.

Forward secrecy and metadata privacy are table stakes in any modern secure messaging design, and Delta Chat has neither.

If Keybase hasn't managed to "fix" the same base encryption Delta Chat is using, there's no reason to assume this small project will have better luck.

PGP isn’t architecturally well-equipped to provide forward secrecy. In the mean time, I think it’s borderline negligent to put this in the category of secure messaging; the world’s expectations for security baselines have moved on beyond the mid-2000s.

(My reference point here is Keybase, which built a very user-friendly and misuse-resistant encrypted chat on top of PGP in the mid-2010s. They couldn’t get to forward secrecy either with PGP as their substrate.)

Delta Chat treats encryption as optional and requires extra steps to avoid accidentally exposing more data

No forward secrecy and will automatically switch to unencrypted messages if you receive an unencrypted message from a contact.

The way to have guaranteed encryped is creating two user encrypted group chat.