You may setup "burner" phones for specific activities which may face repression including device seizure and forced unlocking. #deltachat does not require a sim card/number and works #OfflineFirst. Seek out wifi or mobile hotspots to connect. At best form or join affinity groups and pre-establish ephemeral chats so everyone can help each other stay safe. Group onboarding is trivial with delta. Note: Digital tools are only ever supplementary to the security coming from caring for each other.
#deltachat is secure against server-side group membership changes but for a very different reason than #signal which keeps encrypted group membership data in a central store. Delta Chat has _no_ central store but implements a rigidly tested #p2p group membership model where servers play no role Both signal and delta chat are safe against recently published attacks against #whatsapp that can add members to chats, breaking end to end encryption.
#whatsapp claims end to end security of content but: - ties your identity to a phone number - owns your identity - can see who messages whom and who is in which group etc - forces you to send local search in your private chats to Meta AI - does not allow to disable Meta AI on the main screen None of these problems exist with #deltachat devs and distributors. We have arguably the world's easiest onboarding process for a messenger that offers a Whatsapp style interface on all platforms.
Since June 1st there is a big sudden surge of new Delta Chat users and so far things are going pretty smooth. We are happy that our #chatmail infrastructure is holding up and that there is growing recognition that #deltachat is a ready-to-use and resilient chat solution. Some stats from the last days, a brief discussion of centralization risks and what we plan to do about it, also introducing a brand-new chatmail OpenCollective with a european fiscal host.
our friends over at @npub1f5gx...3gr2 just published a monster milestone, humbly tagged 0.16 😍 with - streaming decryption and encryption - post-quantum-cryptography - API streamlining. #rPGP is a full Rust implementation of #openpgp which counts among the fastest and most compliant implementations today, and includes security audits. Note: #deltachat uses a restricted subset of OpenPGP, and follows best practices (eg using the same ed25519 keys implementation as #signal)
#whatsapp has been feverishly copying #telegram features the last year. Both are now in a battle who enshittifies faster. Mr. Durov announced that #Telegram, sitting on the biggest cleartext data and metadata pile second only to #Meta, is to integrate "AI" the next days, see ... Let them fight. We stubbornly continue to focus on resilient private messaging for families, groups and communities, with end-to-encrypted #webxdc apps and decentralized agency at all levels.
By design, end-to-end-encrypting #deltachat and #webxdc apps only need ephemeral transport. It's a big deal. Let's compare: - #matrix home servers maintain a cryptographic forever-chain of cleartext social-graph metadata. - #WhatsApp servers maintain cleartext metadata visible to Meta. - #Signal keeps encrypted metadata, hosted at GAFAM #chatmail relays do not persist any social graph state, also not in encrypted form. A key goal of our designs: chatmail operators can sleep well at night :)
#deltachat Desktop can now run on Firefox and Safari, entirely avoiding Electron and Chromium! It's an intended side-effect of the "porting Desktop to Tauri" effort led by @npub1t0n6...7d8g which aims to provide a non-Electron packaged version of the Desktop. Here is a video and deep dive into what's working on regular browsers now, and what's missing for a full Web version:
For those wondering about Microsoft Recall because of #Signal's blog post about an option to block screenshots on Windows: #deltachat Desktop on Windows and MacOS have an option to disable screenshots in "Advanced" settings since beginning 2025. It's not enabled by default because we first need to work hard on drafting a big blog post about it .... just kidding :) We'll see if we change the default. We certainly agree that Microsoft needs to change their AI-grabbing and privacy violations.
Transparency report: #deltachat gave out data for the following number of users in the last years: 0, nada, zilch. granted, it helps to not have data to begin with :) #Telegram is the exact opposite: they have _all_ the data about users, message histories, contacts, group and channel memberships, phone numbers, media files, bot interactions etc .... all in the clear on their central server, ready to be grabbed.