28
Molly v.s. Signal (mander.xyz)
submitted 11 months ago* (last edited 11 months ago) by [email protected] to c/[email protected]

I am not comfortable that signal depends proprietary google library. However, I find that Molly lags significantly behind signal (around 1 to 2 weeks, so maybe not as significant as I thought), but I am just concerned that if there is a security fix in signal, molly will not be able to react as fast.

I am also quite frustrated with the general lack of communication from the signal team (for example the lack of communication regarding username). I doubt they will have the good will to help molly when there is a critical security fix.

It is frustrating that signal no longer seems like the gold standard for privacy any more; unfortunately, all my friends are on there (ironic, isn't it...).

top 20 comments
sorted by: hot top controversial new old
[-] [email protected] 13 points 11 months ago* (last edited 11 months ago)

Should note that their GitHub says:

We update Molly every two weeks to include the latest features and bug fixes from Signal. The exceptions are security issues, which are patched as soon as fixes become available.

I’m not sure on their track record, but if their claims are true, this could be a fine, secure client.

[-] [email protected] 10 points 11 months ago

There's a FOSS fork of Signal which removes Google dependencies from the software.

Signal-FOSS

A fork of Signal for Android with proprietary Google binary blobs removed. Uses OpenStreetMap for maps and a websocket server connection, instead of Google Maps and Firebase Cloud Messaging.

https://github.com/tw-hx/Signal-Android

[-] [email protected] 3 points 11 months ago

Is there any advantage of using this instead of molly?

[-] [email protected] 2 points 11 months ago

Hasn't been updated in a year and is over 3000 commits behind Signal. I wouldn't use

[-] [email protected] 1 points 11 months ago* (last edited 11 months ago)
[-] [email protected] 10 points 11 months ago

Molly, like Signal, uses Google’s proprietary code to support some features.

Right at the top of the Molly page.

[-] [email protected] 5 points 11 months ago* (last edited 11 months ago)

AFAIK, they have a FOSS variant

To support a 100% free and auditable app, Molly comes in two flavors: one with proprietary blobs like Signal and one without. They are called Molly and Molly-FOSS, respectively. You can install the flavor of your choice at any time, and it will replace any previously installed version. The data and settings will be preserved so that you do not have to re-register.

Also the line right after your quote:

Versions

Molly, like Signal, uses Google’s proprietary code to support some features.

Molly-FOSS is the community effort to make it 100% free and open-source.

[-] [email protected] 8 points 11 months ago

For some reason I also was able to get most of my friends and family on Signal and just a year later I set up Matrix and now nobody wants no move anymore.

[-] [email protected] 6 points 11 months ago

@baseless_discourse The gold standard has always been XMPP. It's the IETF Internet Standard for messaging, no walled gardens, ability to self-host, no phone numbers required and modern clients use the same end-to-end encryption protocol as Signal does.

[-] [email protected] 5 points 11 months ago

Is there a community for XMPP? I would like to know what clients people use on iOS. So far I found them all to be pretty insufficient.

[-] [email protected] 2 points 11 months ago

@matricaria There is a community around XMPP. Of course you will find most of them in public XMPP channels, but many are also active in the Fediverse/Mastodon. I don't have any Apple devices, but a few of my friends use Monal ( @Monal ) which seems to be the most reliable client on iOS currently.

[-] [email protected] 1 points 11 months ago

It's not the same encryption, it's based on the same double ratchet design that's it

[-] [email protected] 4 points 11 months ago

“prosperity”

Do you mean proprietary?

[-] [email protected] 2 points 11 months ago

Sorry, i think it is fixed.

[-] [email protected] 3 points 11 months ago

What's your threat model?

Signal as a gold standard for encrypted messaging is based on many factors. Ease of use, UI/UX, protocol, platform support and so on.

Even though I'm a hard core FOSS person I'm also a realist. Sticking to a common platform is worth a lot. Bridging stuff with Matrix is cool but will not take off among most people.

Signal using Google blobs is a problem but let's face it, the UI will be presented on a Google branded Android phone or a iOS device anyhow. Sure you can use GrapheneOS and Molly or you can switch to another app altogether but heck you'll have no other to talk to then.

[-] [email protected] 2 points 11 months ago

I've been using it for close to a year because I can't link Signal to my desktop using QR code, Molly allows to provide the link directly and thus I use it. Everything works great.

[-] [email protected] 2 points 11 months ago* (last edited 11 months ago)

For me Molly works but one can't use Signal betas (obviously) and backups are currupted for me for months.

[-] [email protected] 1 points 11 months ago

I see similar complains in their issues. That unfortunately sounds like a deal breaker...

[-] [email protected] 2 points 11 months ago

I use molly and it seems to be fine. You do make a fair point about a delay like that but i am not personally that concerned. If it were a month or more i would be apprehensive, but not a couple weeks.

load more comments
view more: next ›
this post was submitted on 22 Jul 2023
28 points (86.8% liked)

Privacy

30011 readers
1545 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS