this post was submitted on 13 Oct 2025
135 points (97.9% liked)

Selfhosted

52232 readers
634 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Take control of your data, join the tech chat. Host an XMPP server and leverage end-to-end encryption for your personal data

you are viewing a single comment's thread
view the rest of the comments
[–] ArcaneSlime@lemmy.dbzer0.com 1 points 8 hours ago

Yes, but this is where threat modeling comes into play.

Right,:

If you need nation-state level secrecy, rule #1 is don't associate with idiots who can't be bothered with at least the most basic opsec. I shouldn't talk to this motherfucker at all were that my case, or at least not digitally. Thankfully at worst we talk about me middlemanning him some weed, and even local PD dgaf.

Though btw speaking of:

Can the size or metadata

Plenty of people have been drone striked (struck?) simply because the metadata said they were talking to the wrong guy. Frankly if you need that high of a level of secrecy, you'd be better served using tails/tor, or hell even snail mail with false return addr and a book cipher. But for:

all ISPs, WiFi networks, CDNs, VPNs, script skiddies with Wireshark, and network admins in the path

Then frankly either signal or jabber+encryption (or for that matter, simplex, briar, yadda yadda) should be fine.

Signal also benefits from the network effect, because someone trying to get away from an abusive SO has plausible deniability if they download Signal on their phone ("all my friends are on Signal" or "the doctor said it's more secure than email")

But then again, it's more likely to be known as an encrypted chat which may be a problem for them, while the abusive SO might just think XMPP is some outdated IM they know what signal is, and "my friends" can use jabber just the same as signal.

Alas, this is an issue with all messaging apps, if people delete the app without closing their account

Except not. XMPP not being tied to a phone number, if my buddy Steve deletes Conversations, while I may not be able to message him on jabber I can fall back on text. However (and again maybe now this is fixed), on signal if he deletes the app, I can no longer signal message him, nor can I SMS him because they get lost in limbo as signal messages, I'd have to email or use XMPP to get him to redownload signal, delete it properly, and THEN I can SMS him again. (Maybe no longer now that "no sms," but also "no sms now but still give us your phone number" don't sit right with me.)