It sucks. Here in the Netherlands, WhatsApp is used by the vast majority of people. The holdouts (like me) consist of people who don't want to deal with smartphones (some elderly, some who deliberately avoid them because of addictive behaviour), or who own a smartphone, but don't agree with WhatsApp's terms of use (essentially paying for access with your data).
Not using WhatsApp has consequences. We sometimes miss out on family events when people forget that we don't use WhatsApp. Anyone with children is basically required to use WhatsApp for communication with other parents, organising school and social events, and what have you. Refusal to do so means you ostracise your kids.
So yeah, great. To participate in some parts of society WhatsApp is now a de facto requirement. A whole nation blindly agrees to whatever terms of use Facebook drafts. And when you do accept those terms, you are forced to use their client software on one of their approved operating systems. Owning a (Android or Iphone) smartphone is a hard requirement.
The network effect means that alternatives never gain any traction, and the price of WhatsApp ('free') is hard to beat.
To be fair, my Signal list of contacts keeps growing here in NL. I do some light proselytizing, but it seems to be moving along on it's own. Hopefully Arjan Lubach (Holland's Jon Oliver) will do a hit-peice on WhatsApp like he did on Facebook at some point in the future.
I'd like to delete WhatsApp, but any conversation I have in Signal vs WhatsApp is a small victory that I'll take. If at some point more than 50% of my messages are outside WA, I'll nuke it.
Signal inherits some of WhatsApp's limitations though. It requires that the primary device be an Android or IOS based smartphone with an internet connection; and your identifier is your telephone number, which has the same privacy implications as WhatsApp. With the centralised server model choosing Signal over WhatsApp is basically betting that Open Whisper Systems won't monetize your data, or won't be bought out by some bigger fish.
Why can't I use a messaging service from my desktop without having a smartphone with pre-approved operating system nearby?
Signal-CLI and Signald both allow one to register a number on a desktop for use with Signal, you can even pull your messages right into weechat if you want: https://github.com/thefinn93/signal-weechat
Signal seems to be growing here in Toronto as well.
I'm virtually ostracized by my lack of social media engagement so my list is short, but I encouraged my girlfriend to pick it up after the more public Facebook fiascos as she was a heavy Messenger user.
As soon as she installed it, she found a good selection of her contact list was already on there, including her company's owner. Her major concern was keeping in touch with friends and family in Montana, California, and BC. She's still stuck between the two apps because of coworkers, employees, and other holdouts, though.
I just made the choice to do it. I let my contacts know I'd no longer be available on WhatsApp - but they can reach me through calling, email, text/signal.
I'm definitely missing out on some interactions but at the end of the day, who cares? If it's really that important I'll get the message another way. I know it's the reality now that most parents/schools use WhatsApp but that's not a reason to not want change. Crucial information should be sent via email anyways.
I also think this is the only way to actually move off the platform. You can't half-ass it, because why would others move away when you're still available?
Sometimes the consequences are are quite difficult to deal with.
These days I am looking to rent a flat in India. It's a tough task for a bachelor here - add to that the fact that builders rarely build 1 bedroom flats.
So any broker I call simply tells me "WhatsApp me your requirement, budget, and details". When (sometimes) say "I'll SMS" the prompt response is "no no, WhatsApp". Most of them/us here don't check SMS - it's reserved for either spam or bank txn notifications and OTPs.
To participate in some parts of society WhatsApp is now a de facto requirement. A whole nation blindly agrees to whatever terms of use Facebook drafts.
Same if you don't have a Facebook account. Speaking of which, WhatsApp was the defacto IM standard before it was bought by Facebook. Previously it was MSN Messenger (or whatever it is called these days. Skype?) and that was horrible as well. XMMP was at least federated, and had backwards compatibility.
The advantage WhatsApp has over MSN is that the data is E2EE.
There are some people who push for an alternative called Telegram, which uses home brew cryptography instead of established standards.
Though if I look at the Mastodon drama (recently posted on HN, apparently from 2017) federated in practice can lead to fractured communities. Heck, you can even see that in the history of IRC (how EFnet and IRCnet got started).
There are some people who push for an alternative called Telegram, which uses home brew cryptography instead of established standards.
No, it might as well have no end-end cryptography.
The crypto is only enabled for "Secret Chats" and Calls, and I have never seen anyone actually use the secret chat functionality. Using a secret chat limits you to one device and blocks features like bots, so most people don't want to use it.
Have you actually seen the implementation of the WhatsApp clients on iOS / Android? How can you say that the data is E2EE when there are no sources, no verifiable builds, nothing but just statements that "yes, we do use E2EE"?
On the contrary, you have open protocol with verifiable implementation and available sources of the Telegram client for mobile platforms; yet you automatically disregard it just because it is not developed by Moxie or whatever.
I am still baffled how people completely turn off their critical thinking when it comes to encryption; I guess this is a fine example how marketing actually works well.
But yeah, you're right, it could be sending plaintext or deliberately leaking keys somewhere. Unless someone really reverses it we won't know it doesn't as surely as we know that Telegram doesn't use encryption at all.
In the context of a messaging system anything other than E2EE is pretty worthless as far as I'm concerned.
If just using encryption is good enough for you, then why not use Facebook Messanger, Google Hangouts or whatever they call it these days, or WeChat? You can verify their use of encryption with Wireshark.
You argue that Telegram is great because it's open source, but what difference does that really make when it's a centralized service and that centralized service has access to all the plaintext? So what if the client is open source? What does that actually help us verify in this case?
In the context of a messaging system anything other than E2EE is pretty worthless as far as I'm concerned.
To each their own. I've made a choice that I'd rather take the risk of leaking data to Telegram (real but I've reason to belive kow risk) than leaking metadata to Facebook (a given).
I'm considering Signal though.
But don't lie and say not not encrypted when you mean not end-to-end-encrypted.
Still sounds better than the US where everyone still uses SMS.
In what possible way does "everyone is de facto forced to use the only permitted client of a proprietary platform and agree to whatever terrible terms Facebook, a surveillance platform, dictates" sound better than "everyone still uses an open standard not solely controlled by a private surveillance company, to which any number of different clients can interconnect peacefully"?
None of the adjectives nor concepts you have applied to SMS apply, including the assertion that any number of clients can interconnect peacefully, that it is open, that it is a standard, that the steering of the technology is not actually done by the private surveillance companies you’ve mysteriously overlooked, not to mention how SMS is easier for law enforcement to acquire than a pack of cigarettes, because the carrier is sitting there waiting for a warrant on account of not angering the government that, you know, gave them spectrum and allowed them to exist in the first place.
Aside from all of that, good analysis.
Aware iPhone owners literally have the “oh, they’re green, looks like I have yet another plaintext compromise in my life and they’ll never figure out Signal” conversation with themselves every time they exchange numbers with someone new, and I’ve met more than one person who has remarked negatively to the person’s face that they are using SMS, including in a dating scenario as a dealbreaker. You might be the only person who likes it, aside from misguided parts of the Android community that praise SMS roughly like you do when discussing the lack of something like iMessage in that ecosystem, all without realizing the surveillance calculus you’ve correctly established is the real reason the carriers tie Google’s hands (even beyond Google going through messaging systems like socks).
You may not realize it, but on Android, Signal acts very similar to iMessages, pulling in your SMS & MMS so that you can seamlessly text regardless whether the other person is using Signal or not. Most features that come with the Android build just don't exist in Signal for iOS, or are delayed by a year, like Giphy support: https://signal.org/blog/signal-and-giphy-update/
Additionally, if someone is so petty as to consider not using iMessage as a dealbreaker, they likely have other issues that would cause a significant relationship to fail. More than a few families have one Apple user ID for 3+ phones, which makes iMessage effectively break (unless you want mom & dad to see Johnny's messages!).
At least buy OP a drink before psychoanalyzing their relationships that aggressively without any evidence to go on beside your cultural assumptions. Mere participation in this community is a beaming, reliable signal that you’re probably not Dr. Phil, so I’d suggest listening rather than explaining familial bond to someone you’ve never met.
If you said something like that to me in person, your evening would not go the way you think it would, and you’d find yourself in a conversation about your departure from the circumstances that allowed you to offer that perceived wisdom.
Some people rely on their tech to take care of a lot of details, and simply forget the edge cases sometimes. People are human and make mistakes. It's pretty disrespectful to jump to conclusions about their relationships.
Comments
It sucks. Here in the Netherlands, WhatsApp is used by the vast majority of people. The holdouts (like me) consist of people who don't want to deal with smartphones (some elderly, some who deliberately avoid them because of addictive behaviour), or who own a smartphone, but don't agree with WhatsApp's terms of use (essentially paying for access with your data).
Not using WhatsApp has consequences. We sometimes miss out on family events when people forget that we don't use WhatsApp. Anyone with children is basically required to use WhatsApp for communication with other parents, organising school and social events, and what have you. Refusal to do so means you ostracise your kids.
So yeah, great. To participate in some parts of society WhatsApp is now a de facto requirement. A whole nation blindly agrees to whatever terms of use Facebook drafts. And when you do accept those terms, you are forced to use their client software on one of their approved operating systems. Owning a (Android or Iphone) smartphone is a hard requirement.
The network effect means that alternatives never gain any traction, and the price of WhatsApp ('free') is hard to beat.
To be fair, my Signal list of contacts keeps growing here in NL. I do some light proselytizing, but it seems to be moving along on it's own. Hopefully Arjan Lubach (Holland's Jon Oliver) will do a hit-peice on WhatsApp like he did on Facebook at some point in the future.
I'd like to delete WhatsApp, but any conversation I have in Signal vs WhatsApp is a small victory that I'll take. If at some point more than 50% of my messages are outside WA, I'll nuke it.
Signal inherits some of WhatsApp's limitations though. It requires that the primary device be an Android or IOS based smartphone with an internet connection; and your identifier is your telephone number, which has the same privacy implications as WhatsApp. With the centralised server model choosing Signal over WhatsApp is basically betting that Open Whisper Systems won't monetize your data, or won't be bought out by some bigger fish.
Why can't I use a messaging service from my desktop without having a smartphone with pre-approved operating system nearby?
Signal-CLI and Signald both allow one to register a number on a desktop for use with Signal, you can even pull your messages right into weechat if you want: https://github.com/thefinn93/signal-weechat
Signal seems to be growing here in Toronto as well.
I'm virtually ostracized by my lack of social media engagement so my list is short, but I encouraged my girlfriend to pick it up after the more public Facebook fiascos as she was a heavy Messenger user.
As soon as she installed it, she found a good selection of her contact list was already on there, including her company's owner. Her major concern was keeping in touch with friends and family in Montana, California, and BC. She's still stuck between the two apps because of coworkers, employees, and other holdouts, though.
I just made the choice to do it. I let my contacts know I'd no longer be available on WhatsApp - but they can reach me through calling, email, text/signal.
I'm definitely missing out on some interactions but at the end of the day, who cares? If it's really that important I'll get the message another way. I know it's the reality now that most parents/schools use WhatsApp but that's not a reason to not want change. Crucial information should be sent via email anyways.
I also think this is the only way to actually move off the platform. You can't half-ass it, because why would others move away when you're still available?
Sometimes the consequences are are quite difficult to deal with.
These days I am looking to rent a flat in India. It's a tough task for a bachelor here - add to that the fact that builders rarely build 1 bedroom flats.
So any broker I call simply tells me "WhatsApp me your requirement, budget, and details". When (sometimes) say "I'll SMS" the prompt response is "no no, WhatsApp". Most of them/us here don't check SMS - it's reserved for either spam or bank txn notifications and OTPs.
Same if you don't have a Facebook account. Speaking of which, WhatsApp was the defacto IM standard before it was bought by Facebook. Previously it was MSN Messenger (or whatever it is called these days. Skype?) and that was horrible as well. XMMP was at least federated, and had backwards compatibility.
The advantage WhatsApp has over MSN is that the data is E2EE.
There are some people who push for an alternative called Telegram, which uses home brew cryptography instead of established standards.
Though if I look at the Mastodon drama (recently posted on HN, apparently from 2017) federated in practice can lead to fractured communities. Heck, you can even see that in the history of IRC (how EFnet and IRCnet got started).
No, it might as well have no end-end cryptography.
The crypto is only enabled for "Secret Chats" and Calls, and I have never seen anyone actually use the secret chat functionality. Using a secret chat limits you to one device and blocks features like bots, so most people don't want to use it.
Parent says cryptography, not end-to-end cryptography.
Cryptography provides value even if it is not end-to-end (it limits the attack surface).
There's a lot to say about Telegram, but can please stick to the facts?
Have you actually seen the implementation of the WhatsApp clients on iOS / Android? How can you say that the data is E2EE when there are no sources, no verifiable builds, nothing but just statements that "yes, we do use E2EE"?
On the contrary, you have open protocol with verifiable implementation and available sources of the Telegram client for mobile platforms; yet you automatically disregard it just because it is not developed by Moxie or whatever.
I am still baffled how people completely turn off their critical thinking when it comes to encryption; I guess this is a fine example how marketing actually works well.
Yes, and Telegram being open allows us to confirm with absolute certainty that it uses no E2EE by default.
We don't have the WhatsApp source code, but we don't have to do a lot of reverse engineering to see that it uses this:
https://github.com/signalapp/libsignal-protocol-c
But yeah, you're right, it could be sending plaintext or deliberately leaking keys somewhere. Unless someone really reverses it we won't know it doesn't as surely as we know that Telegram doesn't use encryption at all.
Telegram uses encryption by default, just not E2EE.
You can criticise them for
- using their own crypto
- misleading advertising regarding the quality of said crypto
... and possibly more, but I still suggest we try to stick to the facts.
In the context of a messaging system anything other than E2EE is pretty worthless as far as I'm concerned.
If just using encryption is good enough for you, then why not use Facebook Messanger, Google Hangouts or whatever they call it these days, or WeChat? You can verify their use of encryption with Wireshark.
You argue that Telegram is great because it's open source, but what difference does that really make when it's a centralized service and that centralized service has access to all the plaintext? So what if the client is open source? What does that actually help us verify in this case?
To each their own. I've made a choice that I'd rather take the risk of leaking data to Telegram (real but I've reason to belive kow risk) than leaking metadata to Facebook (a given).
I'm considering Signal though.
But don't lie and say not not encrypted when you mean not end-to-end-encrypted.
Still sounds better than the US where everyone still uses SMS. You can buy an iPhone and accidentally use iMessage, but that's about the only option.
In what possible way does "everyone is de facto forced to use the only permitted client of a proprietary platform and agree to whatever terrible terms Facebook, a surveillance platform, dictates" sound better than "everyone still uses an open standard not solely controlled by a private surveillance company, to which any number of different clients can interconnect peacefully"?
None of the adjectives nor concepts you have applied to SMS apply, including the assertion that any number of clients can interconnect peacefully, that it is open, that it is a standard, that the steering of the technology is not actually done by the private surveillance companies you’ve mysteriously overlooked, not to mention how SMS is easier for law enforcement to acquire than a pack of cigarettes, because the carrier is sitting there waiting for a warrant on account of not angering the government that, you know, gave them spectrum and allowed them to exist in the first place.
Aside from all of that, good analysis.
Aware iPhone owners literally have the “oh, they’re green, looks like I have yet another plaintext compromise in my life and they’ll never figure out Signal” conversation with themselves every time they exchange numbers with someone new, and I’ve met more than one person who has remarked negatively to the person’s face that they are using SMS, including in a dating scenario as a dealbreaker. You might be the only person who likes it, aside from misguided parts of the Android community that praise SMS roughly like you do when discussing the lack of something like iMessage in that ecosystem, all without realizing the surveillance calculus you’ve correctly established is the real reason the carriers tie Google’s hands (even beyond Google going through messaging systems like socks).
You may not realize it, but on Android, Signal acts very similar to iMessages, pulling in your SMS & MMS so that you can seamlessly text regardless whether the other person is using Signal or not. Most features that come with the Android build just don't exist in Signal for iOS, or are delayed by a year, like Giphy support: https://signal.org/blog/signal-and-giphy-update/
Additionally, if someone is so petty as to consider not using iMessage as a dealbreaker, they likely have other issues that would cause a significant relationship to fail. More than a few families have one Apple user ID for 3+ phones, which makes iMessage effectively break (unless you want mom & dad to see Johnny's messages!).
If family members don't invite you to events because of the lack of whatsapp, you probably are not very close.
At least buy OP a drink before psychoanalyzing their relationships that aggressively without any evidence to go on beside your cultural assumptions. Mere participation in this community is a beaming, reliable signal that you’re probably not Dr. Phil, so I’d suggest listening rather than explaining familial bond to someone you’ve never met.
If you said something like that to me in person, your evening would not go the way you think it would, and you’d find yourself in a conversation about your departure from the circumstances that allowed you to offer that perceived wisdom.
Some people rely on their tech to take care of a lot of details, and simply forget the edge cases sometimes. People are human and make mistakes. It's pretty disrespectful to jump to conclusions about their relationships.