HACKER Q&A
📣 supermatou

Am I Being Paranoid?


I've been using Signal for years; I like it, but some things made me frown (having to provide a phone number, server software becoming closed-source, thus non-auditable; integrated crypto and so on). I then discovered Session - and I liked the fact that they avoided having a single point-of-failure, by having many servers, in various geographical locations. Still... something bothers me with Session: the devs say that maintaing a server incurrs a non-trivial financial burden ($15,000/year), while claiming that all those servers are maintained by volunteers around the world; most of the servers are in First World countries (US, Germany), but, a couple of days ago, once I connected, one of the servers appeared to be in Ukraine. Seriously? Fifteen grand a year is not peanuts even for someone in the First World, let alone for someone residing in a country with a collapsing economy and battered by an active war.

What are your thoughts on this?


  👤 jeroenhd Accepted Answer ✓
I don't know where the $15k number comes from, but I imagine that number is more about the parent company (Oxen) which runs a blockchain system. Adding a new server to this system requires an amount of cryptocurrency (set to 15,000 $OXEN according to their docs, or about $2,706).

I don't know exactly how their infrastructure is designed, but the direct integration with any cryptocurrency tech is reason enough for me to be sceptical about it. If their integration was just for sending back and forth cryptocurrency then that's somewhat acceptable (i.e. Signal's approach, though I still don't like it myself) but with Session the blockchain is deeper ingrained.

As for server cost, I imagine hosting a server in a country where the power infrastructure is under attack from a foreign invader isn't exactly making life cheaper. I'd expect the price for electricity to skyrocket, especially for unimportant services like messaging servers.

Source: https://docs.oxen.io/products-built-on-oxen/session


👤 cbluth
My real thoughts are, I want to suggest a different heading, not sure where you're headed, but something less vague like: - "Is Session Chat at risk?" - "Are we at risk for using Session Chat?" - "Session Chat servers are up in Ukraine?"

I dunno, I'm terrible at this


👤 lilsoso
That depends on whether or not your paranoia is warranted. If your communication is compromised, what's the cost?

Are you naive enough to think you're secure from the most sophisticated actors? Those with nearly unlimited funds? They run a lot of other 'nodes'. They're also involved in the development of many projects. They're involved in the infrastructure.


👤 greggarious
Your main goal is avoiding ss7 stuff if identify rather than encryption is your concern maybe just change sims often?

(But unless your contacts do too you’ll still be spotted, so just turn on disappearing and blend in w the sexts and weed dealers imho.)


👤 profstasiak
smoke some weed to fuel your paranoia and go back sending emails with encrypted messages

👤 jacooper
Personally, I see matrix as the best private and mainstream-able chat protocol.

👤 pestatije
You already trusting "volunteer" servers, what difference does their location make? You should be paranoid with all of them or none.

👤 spacechild1
clickbait headline

👤 axegon_
Bruh... For real?