Last year, I outlined the specific requirements that an app needs to have in order for me to consider it a Signal competitor.

Afterwards, I had several people ask me what I think of a Signal fork called Session. My answer then is the same thing I’ll say today:

Don’t use Session.

  • kbal@fedia.io
    link
    fedilink
    arrow-up
    6
    ·
    10 hours ago

    Without any context to suggest otherwise I started reading that expecting it to be some kind of weak vibes-based argument against Session. It is not. Don’t use Session.

    it uses the X25519 public key… as a symmetric key, for AES-GCM