Divested-Mobile / DivestOS-Website

The DivestOS website
https://divestos.org
Other
22 stars 15 forks source link

Information about Session messenger is outdated or wrong. #23

Closed onlineapps-cloud closed 10 months ago

onlineapps-cloud commented 10 months ago

hi i saw on your page https://divestos.org/pages/messengers that Session messenger not support E2EE uses PFS, image on they site i found information that they ise E2EE uses PFS. excerpt from the documentation at the link: https://arxiv.org/pdf/2002.04609.pdf image image image If Session use same protocol as Signal, and signal support PFS, then Session support to?! :) please correct table it it's outdated or wrong infromation. thanks, best regards.

SkewedZeppelin commented 10 months ago

Session does not support PFS. Session protocol is based on Signal protocol which does support PFS, but Session doesn't.

https://getsession.org/session-protocol-explained

First things first, let’s talk about what we’re leaving behind: Perfect Forward Secrecy (PFS) and deniability.

https://getsession.org/blog/session-protocol-technical-information

Switching to the Session Protocol means that Session will no longer have deniability and PFS in 1-1 chats, or PFS in closed groups.

Dicussion here: https://github.com/orgs/privacyguides/discussions/296#discussioncomment-1756211