c-toxcore
simplex-chat
Our great sponsors
c-toxcore | simplex-chat | |
---|---|---|
20 | 247 | |
2,156 | 5,264 | |
1.8% | 4.0% | |
9.5 | 9.9 | |
4 days ago | about 23 hours ago | |
C | Haskell | |
GNU General Public License v3.0 only | GNU Affero General Public License v3.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
c-toxcore
- Tox Core is one of the nicest-to-read C codebases
-
uTox β The Lightweight Tox Client
See also this somewhat infamous thread on Tox's cryptographic design[1].
-
Tox seems slowly dying (change my mind), what alternatives have you researched?
In case with Tox you have to trust in homebrew crypto that was never properly audited (how about that security issue reported by Donenfeld in 2017, which is being tackled only now, sort of?) -- and outdated and outright abandoned clients which were never above, let's say, "beta quality".
-
qTox unmaintained. Is this the end of qTox?
it has the new group chat feature (https://github.com/TokTok/c-toxcore/pull/2269)
-
Π ΠΎΡΡΠΈΠΉΡΠΊΠΈΠ΅ ΡΠΏΠ΅ΡΡΠ»ΡΠΆΠ±Ρ Π½Π°ΡΡΠΈΠ»ΠΈΡΡ ΡΠ»Π΅Π΄ΠΈΡΡ Π·Π° ΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°ΡΠ΅Π»ΡΠΌΠΈ Telegram
"If Tox already does onion routing, why use Tox over Tor?"
-
My list of favorite secure messaging apps
What an arbitrary criteria to judge a project by. There have been 5 releases in the past year, including a major feature release.
-
I know Privacy Guides is the new version of Privacy Tools, but even if so, do the recommendations (or at least most of them) in the old site still apply today?
Signal isn't falling behind and Tox is an old service that has had issues with messages being spoofable since day 1
-
Shadiness in the Privacy Space: Jonah Aragon's (PrivacyGuides) Failed Attempt to Takeover PrivacyTools.io
tox https://github.com/TokTok/c-toxcore/issues/426
-
E2E encrypted voice and chat service similar to Discord/Slack?
You could use a Tox front end like qTox or Toxic. It is a fully encrypted end-to-end communication protocol that allows text, voice, and video chat. The github page for the Tox protocol has some useful caveats about the its security.
-
Tox: Decentralized and Encrypted Instant Messaging
It links to a bug report discussion where one of the developers states that they don't understand the security properties of tox very well[1].
I find that worrying.
simplex-chat
-
What are your favorite End-to-End encrypted tools for online privacy?
For messaging I'm currently on Olvid (E2E with physical key exchange) but since it still use their servers, I'm currently testing SimpleX where I can host my own servers.
- Apple reveals 'push notification spying' by foreign governments
- simplex bugs/ missing features
- Launching Default End-to-End Encryption on Messenger
-
Apple Confirms Governments Using Push Notifications to Surveil Users
Notice how SimpleX (https://simplex.chat/) has no push notifications by default because of this issue.
- Possible today in Signal? Disable link preview
-
SMS Security and Privacy Gaps
I've been using SimpleX [0] with a couple of friends recently. It appears to work as advertised.
- SimpleX Chat v5.3.0 β Local file encryption and delivery receipts
-
U.K. Abandons, for Now, Legislation That Would Have Banned End-to-End Encryption
If you have a mobile phone number, the domestic intelligence agency knows exactly where you are at all times and any LEO (without a warrant) can also find you. In addition, there have been numerous CCC presentations showing how insecure the global (excluding US) and (separately) US carriers are guilty of promiscuous metadata trafficking ($$) and insecure SS7 setups. As a consequence, for low $, you can go to any one of several shady websites and find the last location of almost any phone number (person unique ID) globally. There are additional varying exploitable vulnerabilities depending on the exact combination of {handset x carrier x country} to impersonate them, tap their line, reveal their exact location, and redirect their phone number through a third-party handset or even a PBX. These are more expensive and some capabilities are forbidden for all but a few selective intelligence uses.
Session (Signal fork) doesn't use phone numbers. It's pretty well-designed overall and uses an onion routing approach. It's already a superset of Signal except it doesn't use phone numbers. https://getsession.org
Also look interesting:
* (unproven) https://www.olvid.io/technology
* (unproven) https://simplex.chat
PS: Using regular TOR on home broadband or cloud servers is relatively risky and inefficient. Sybil attacks on it are common. And to network operators and security agencies it gives an easy "flow tag" of your uplink and exit node data traffic as automatically suspicious.
-
Re: Profile Pictures
Why not open up a Feature request on https://github.com/simplex-chat/simplex-chat/issues
What are some alternatives?
berty - Berty is a secure peer-to-peer messaging app that works with or without internet access, cellular data or trust in the network
Element - A glossy Matrix collaboration client for the web.
aTox - Reasonable Tox client for Android
session-android - A private messenger for Android.
qTox - qTox is a chat, voice, video, and file transfer IM client using the encrypted peer-to-peer Tox protocol.
nostr - a truly censorship-resistant alternative to Twitter that has a chance of working
bbs - Forum for discussing Internet censorship circumvention
Signal-Android - Fork from a private messenger for Android with extra options added: full backup and (partial, ony text) xml backup of messages. Restore can happen at any time, not only after a fresh install. Import SMS database. Import of (unencrypted) WhatsApp databases. Removed apk expire. Choose between passphrase protection and the Android screenlock. Choice for the backup location (internal or removable storage on Android < 11 (on 11 and higher this is already possible)). Set the maptype in the place picker. Option to treat view-once media as normal media. Option to ignore remote deletion. Choose between FCM or websocket notification delivery.
toxic - A Tox-based instant messaging and video chat client
termpair - View and control terminals from your browser with end-to-end encryption π
libuvpp - Minimal Change of libUV for P2P Networking
Signal-Server - Server supporting the Signal Private Messenger applications on Android, Desktop, and iOS