Oddbean new post about | logout
 New #Signal and #Molly (hardened Signal fork) update keeps phone number private, lets you to set up a username.

Plenty of cool usernames still available. I got one I like 😎

Note: Usernames are not public.

#cybersecgirl #privacytechpro

https://signal.org/blog/phone-number-privacy-usernames/ 
 This is great. Usernames are also paired with a random number, and you can get a new random number if you don’t like the one they give you. So there’s no unique vanity username in that sense. 
 so good. yup, must have (at least) 2 digits at the end. cool they don't lock you into a random number and you can manually enter a number to see if it's still available. 
 Didn’t know you could manually enter a number! It didn’t seem to work on iOS when I tried. Maybe I’ll try on Android.

I’d still prefer not needing phone numbers (attack vector) or vanity usernames at all, but rather have a globally unique random identifier. I like how Session does it. But I understand the tradeoff for needing a pleb-friendly identifier paired with a recovery mechanism. 
 very cool. it worked great for me on molly just tapping the numbers section and entering what i wanted. and yes, i agree. still a big win imo. love that you can change the username unlimited times too. good stuff. 
 Never mind. User error. It works on iOS. 
 sweet 
 If you have communicated with somebody using just a username what happens when you change your username?  Do they get notified of the change so they can still reach you or do you need to tell them the new username? 
 changing your username does not delete your current chats or contacts.

"a username is not the profile name that’s displayed in chats, it’s not a permanent handle, and not visible to the people you are chatting with in Signal. A username is simply a way to initiate contact on Signal without sharing your phone number." 
 Rogue, what do you think about Briar and SimpleX? Vs Signal and Molly 
 I recommend both SimpleX and Briar, they both have PFS. Adoption is important for privacy and security. IMO Signal/Molly has more users and is easy to use so it's good for day to day communication and normie adoption while SimpleX and Briar are for more specialized use cases. 
 Don't you think that SimpleX is ready to mass adoption? I mean the UX is far the best of all the chatapps I've tried out of the box 
 www.keet.io 
 We've not yet added SimpleX to our AnonymousPlanet.org guide due to it still being somewhat of an untested protocol. But certainly a cool project and we'll see how it fairs with anonymity and security over time.

Still some growing pains it seems as "fully" deleted messages are still retained in the SimpleX Chat CLI or the "Chat Console" in the GUI, until you clear the terminal. 
 nice guide. simplex is recommended in our guide and most others' as it passes our strict guidelines for inclusion.

i have had multiple conversations with evgeny since we started testing and using simplex ~a year ago. i even helped onboard him to nostr.

there have been growing pains since alpha/beta (voice used to just not work) but as with any app/protocol, development has come a long way since then and they are quick to squash any bugs.

they are open source, e2ee by default, support e2ee for all messages and they have been sucessfully audited.

the only remaining bonus metric afaic is to be battletested in court and that comes with time.

https://simplex.chat/blog/20221108-simplex-chat-v4.2-security-audit-new-website.html 
 Nice! Which guide is yours? 
 thx. it is a paid guide for more extreme clients. i took the old site down. it was deliberately hard to find and not for the general public. everything is currently being overhauled, rebooted, rebranded, and updated from the ground up to include resources for the general public and much more. pretty excited about it. will def link when it is launched. 
 sweet, sounds good, keep me posted 👍  
 awesome. will do 🤙

check out this interview with evgeny and seth for privacy. i respect them both and enjoyed it very much.

Opt Out: SimpleX chat and how privacy aligns with the future of computing w/ Evgeny from SimpleX

Episode webpage: https://optoutpod.com/episodes/s3e02-simplexchat/

Media file: https://www.buzzsprout.com/1790481/12333165-simplex-chat-and-how-privacy-aligns-with-the-future-of-computing-w-evgeny-from-simplex.mp3 
 😏🤣😂

Your advises are for kids from primary schools.

Do not relay on this girl. She seeks attention and she has no idea about security.

Consider her as a social media entertainer.🙃 
 Signal - this app is not even open-source. You cannot reproduce their build.  Secondly, you cannot verify server side code.

Briar- this app disclose addresses of your hardware. 

From proposed apps only SimpleX is worth considering
 
 I think they will break the record of people joining beta just to secure a username.

However I'm not sure how this number works. If I reserve username.01 will someone else be able to het username.02? Or the username is only mine and the number is only needed to fight spam as mentionned? 
 yes, if you reserve username.01, someone else can register username.02, or username.911 etc. you can change your username unlimited times, but when you change it, it will immediately be available for someone else to take. make sense? 
 I'm using Molly FOSS and I like my username 😊 
 Does Molly allow you to contact Signal users and vice versa or do they use completely separate servers? 
 Damn BETA is full on TestFlight! 
 Can I transfer signal info into molly on the same device? 
 Nevermind just restore a backup