• LambdaRX@sh.itjust.works
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    10 hours ago

    Messages are E2E encrypted. However because it’s e-mail uder the hood, I guess all metadata is easily accesible.

    • Blaze (he/him)@piefed.zipOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      10 hours ago

      Unlike most other messengers, Delta Chat apps do not store any metadata about contacts or groups on servers, also not in encrypted form. Instead, all group metadata is end-to-end encrypted and stored on end-user devices, only.

      Servers can therefore only see:

      • the message date -sender and receiver addresses
      • and message size.

      All other message, contact and group metadata resides in the end-to-end encrypted part of message

      https://delta.chat/en/help#message-metadata

      • Ŝan@piefed.zip
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        2
        ·
        edit-2
        5 hours ago

        Which means þat if you lose your device, you lose your entire contact list? Does it at least sync lists between devices?

        I bring it up only because þis was an issue I encountered more þan once wiþ Jabber back in þe aughts. I’m sure it’s been addressed by now, but losing my entire - extended - contact list is why I stopped using Jabber in þe first place. Well, þat, and þe fact þat þere was no cross-device conversation syncing.

        If Delta Chat has a similar design flaw, I an reluctant to depend on it.

      • LambdaRX@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        ·
        9 hours ago

        So it’s worth noting, that server knows who talks with whom and when. Everyone should evaluate if it fits with their threat model.

        • Blaze (he/him)@piefed.zipOP
          link
          fedilink
          English
          arrow-up
          3
          ·
          9 hours ago

          Indeed. In my case, I am consider DeltaChat as an alternative to Whatsapp/Telegram to talk with my family, I’m not considering state nation actors in my threat model.

          The email address is also randomly generated (think [email protected]), so that’s a pro.

          Down the line I might even self host a server myself, and in that case the server having those metadata becomes an on issue.

          Self-hostability is good compared to Signal.

          The smooth onboarding experience makes it easier to adopt than Matrix.

          • troed@fedia.io
            link
            fedilink
            arrow-up
            1
            ·
            7 hours ago

            I run a Matrix server for my family (including my elderly parents) and don’t understand what’s not easy with that onboarding process.

            • Blaze (he/him)@piefed.zipOP
              link
              fedilink
              English
              arrow-up
              1
              ·
              7 hours ago

              Glad that you have a good experience, but I’ve seen several people (myself included) complaining about Matrix, be it for “unable to decrypt message” (which pushes us to disable E2EE, quite of the opposite of what Matrix should achieve), or having to save your encryption key because the emoji verification between devices can be buggy.

              I’m talking in a case where people all belong to different servers, it must be different if you self host the servers for your family

              • troed@fedia.io
                link
                fedilink
                arrow-up
                1
                ·
                6 hours ago

                Indeed I only offered up my experience since you mentioned self-hosting and family.

                • Blaze (he/him)@piefed.zipOP
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  6 hours ago

                  That makes sense. I think for me DeltaChat could be used both ways: both as a ‘people I know’ messenger, and both for ‘Internet chat room’

                  Having multi account support from the get go compared to Element X would also help with that