How's Wire for Infosec/OpSec? Any reasons I should be concerned about it? It's run by a private company but would they be able to turn anything incriminating over to feds if asked? Do they have policies around it? Is the protocol trustworthy or is it like telegram?

Please lmk! Thank you!


okay so

Wire GmbH is a Swiss corp

on signup they have
- your provided e-mail address
- your source IP address
- optionally your phone number if you sign up that way
- hashed+salted account password
- optionally your avatar picture

All messages and calls are E2E by a variant of Signal's E2E protocol. This is a proven and trustworthy protocol.

They have been 3rd party audited, and also a security whitepaper that goes into more detail.

@packetcat @shel ALSO: Messages (and iirc call start/ends) are passed along through their infrastructure, which means they have ability to access the metadata:
- who talked
- to who
- when
- how much

They might very well not COLLECT that data, and also there would likely maybe be jurisdiction issues with handing that data over to US authorities (IANAL), but no TECHNICAL barriers.

(This is the case for 100% every current normal chat platform.)

@packetcat @shel The field of development currently dealing with this metadata stuff is "Metadata-Resistant" stuff.

The most stable thing in the field right now is Briar (Android only*): , aimed at maintaining secure comms against adversity (e.g. has a Local Mesh mode).

The next most promising thing is 's Cwtch (Android and all Desktop, active alpha),
aimed at being a groundwork for safe group converations/spaces.

@er1n If it doesn't that I've COMPLETELY misunderstood large parts of their self-description.

@packetcat @shel
* On Briar's platform availibility: v1.2.7 on Android and very stable/tested there, but that's it for stable -- there's a desktop app that's had it's first Alpha a month ago, is packaged for Linux but is GTK, Python, and Java so portable. iOS is by its design relatively hostile to the design necessities iirc, but they'll take a crack if they get funding.

@packetcat @shel I also wanna specifically say more about Open Privacy ( ) and rec them as a group to keep an eye on, because they're a Canadian non-profit who are EXACTLY the type of people needed here, specifically working on crypto, infosec analysis/tools, and metadata-resistant applications with marginalized groups and protest/rebellion as their announce target demographic.

They're extREMELY fricking GREAT.

@packetcat @shel (Other recent Open Privacy projects include Lockbox, specifically designed for very auditably securing mutual aid group webforms: )

@gaditb @packetcat I really need something that supports both Android and iOS

@shel uses libratchet last I recall, partially owned by US nationals

advertised as like slack but with signal-like encryption. their backend is written by serious programmers but may contain flaws. has been audited in the past.

that's from memory

@shel if you pay for service, they'll have your name and billing info. The end-to-end encryption protocol is based on Signal's double-ratchet protocol. As a non-expert, I'd guess they're as unlikely to be able to hand over plaintext messages as Signal or Apple are. Highly resourced attackers will always find a way, if they care about you personally. The most secure way to communicate remains using one-time pads and dead drops.

@shel my friend says: some metadata is stored in plain text & has been quietly(?) migrated from swiss to US facilities


