this post was submitted on 17 May 2023
0 points (NaN% liked)

Privacy

32665 readers
748 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

How I accidentally breached a nonexistent database and found every private key in a 'state-of-the-art' encrypted messenger called Converso

@privacy

But wait – it gets much, much worse

As I was finishing up the above post, I noticed something a little strange in the code – something I'd glossed over earlier. There are a ton of references to what looks to be functions related to Google's #Firestore database.

#Converso

Using the Seald credentials from the app's code, plus a random user's phone number and user ID from Converso's public database

top 3 comments
sorted by: hot top controversial new old
[–] shreddy_scientist@lemmy.ml 1 points 2 years ago

Thanks for the breakdown, I'll be sure to stay away from Converso! You should 100% check out DataBag. It's my current favorite as its pretty much selfhosted signal. Except without the need for phone numbers and while decentralized, it can be federated too. Definitely my current favorite up and comer in the messaging world

[–] sxan@midwest.social -3 points 2 years ago (3 children)

TFA claims Signal is the gold standard, which raises my eyebrows, especially as th] author - in the same breath - admits Signal leaks metadata.

There are chat clients, less popular, less well funded, that don't leak metadata. Signal may be a good choice for the average non-techie, but it's hardly the gold standard for private chat.

load more comments (3 replies)