I am searching for a selfhosted and secure (end to end encryption) chat platform for my family (5-20 users), possibly one i can host on a raspi.

Is matrix a good choice, or should i try something else?

  • Churbleyimyam@lemm.ee
    link
    fedilink
    English
    arrow-up
    7
    ·
    5 months ago

    You could try Jami. It’s peer to peer, so essentially any participants are self-hosting it. Its E2E encrypted, supports group messaging, voice and video calling, has easily ‘linkable’ mobile and desktop apps for all platforms and requires no email address or phone number to use. It’s also the only messenger I’m aware of which is endorsed by the Free Software Foundation. I highly recommend it 👌

    • lemmyvore@feddit.nl
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 months ago

      So all of these encrypt the conversations so not even the server admin can access them?

      • Lemmchen@feddit.de
        link
        fedilink
        English
        arrow-up
        7
        ·
        5 months ago

        XMPP only does it with certain client extensions. And Matrix only does it when the rooms are set up this way. SimpleX does what you want, but is kind of unintuitive for the average user.
        I say go with Signal, it does what you want and is idiot-proof.

        • philpo@feddit.de
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 months ago

          It is literally one setting in Matrix to force all rooms to only do encrypted messages.

          Signal is pretty unintuitive when it comes to multiple devices per user, device transfers after a device has been lost,etc.

          • essteeyou@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            5 months ago

            Signal is perfectly good under normal usage. Everything is unintuitive when it comes to extremes like losing your device.

            • EngineerGaming@feddit.nl
              link
              fedilink
              English
              arrow-up
              2
              ·
              5 months ago

              Signal is annoying to use if you don’t have a smartphone you can trust, since they do not allow registration from desktop. So either an Android VM or Signal-cli. But maybe it was just a one-off bug that the desktop client didn’t bind to signal-cli for me. Still, the fact that you need an unofficial command-line application just to register makes it not exactly user-friendly.

              • essteeyou@lemmy.world
                link
                fedilink
                English
                arrow-up
                5
                ·
                5 months ago

                I imagine that most people’s families will find Singal easier than using a CLI program anyway. It’s rare to find an entire family without typical cellphones.

                • EngineerGaming@feddit.nl
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  arrow-down
                  3
                  ·
                  5 months ago

                  Yea, but a typical cellphone is not as easy to make private as a typical laptop or desktop. Lineage has some tradeoffs and not accessible on all devices, and Graphene needs even more specific, quite expensive hardware!

            • philpo@feddit.de
              link
              fedilink
              English
              arrow-up
              0
              ·
              5 months ago

              Wouldn’t say that. With most Matrix Clients, WhatsApp, etc. it’s far easier. Especially from a perspective of a elderly,less tech adept user.

        • EngineerGaming@feddit.nl
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 months ago

          To be fair, pretty much all major XMPP clients have adopted OMEMO encryption, so doesn’t seem like much of an issue.

  • oldfart@lemm.ee
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    5 months ago

    XMPP. It just works, requires very little resources, is stable and has decent clients.

    I would go with Snikket instead of Prosody if I had been starting now.

    Conversations on phones, Dino or Gajim on PCs, plus a conversejs install on the xmpp server, to allow web access when needed.

    Conversations is easy for the family to figure out.

    • Mom Nom Mom@nom.mom
      link
      fedilink
      English
      arrow-up
      4
      ·
      5 months ago

      This is what my family (and a few friends) use. We have been using it for a while now because it just works. Also, the kids have never complained about using Conversations, or about using it only for us (like if you have that one family member who won’t leave SMS behind - we’re that guy, I guess), and we can make as many channels as we need for the house, the kids, with each kid individually, for our MTG cards, with our couple of friends that use it, etc…

      I don’t personally do the hosting, so I can’t speak to that. That’s the hubby’s thing
      ¯\_(ツ)_/¯

  • ogarcia@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    5 months ago

    I recommend Matrix with the Conduit server. This server requires almost no resources and even runs on a Raspberry Pi.

    Cinny works perfectly as a desktop client (in case you want to escape from the ubiquitous Element). And for mobile I would use Element for Android/iOS although FluffyChat also works very well.

    • Flax@feddit.uk
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      Conduit seems to have next to no docs on actually installing it for some reason.

      • ogarcia@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 months ago

        They are very focused on development and therefore the documentation is a bit sparse (maybe).

        The truth is that it is not very complicated to install. It is simply to download the binary (it is statically compiled so it has no dependencies) place it in /usr/bin and execute it (the best is to create a user in the machine with the home in /var/lib/conduit and then launch it with systemd).

        Another option is to simply launch it with docker.

        In any case, if you have problems, comment it here and we will look to see what could be happening.

    • Lumisal@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 months ago

      This is nice to know. Cinny looks beautiful from a UX perspective, wish they made an app too. Not enough good UX in open source stuff.

      • ogarcia@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 months ago

        Yes, without a doubt, for me it is the most balanced client, a pity that there is not for Android, but well, in mobile Element does not give problems either.

  • Im_old@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    5 months ago

    I’ve been using matrix for years to this purpose, but moving to xmpp/prosody now

      • Im_old@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        5 months ago

        No.

        Yeah ok. First of all, because I can 😁. I mean z what’s good being an IT nerd if I can’t change stuff when I want?

        Jokes aside, I’ve been reading more recently on matrix and looks like there are some security issues in the design of the app/protocol. I’m on mobile now, I’ll look for sources when I’m on pc. Also I don’t like that it is a server centric system (so data is primarily on the server instead of the clients). Also it takes more resources than I was expecting. For less than 10 users I can’t have less than 4gb of ram (on a dedicated debian server, running docker) or it swaps so much it kills the system.

        So basically I’m testing out if xmpp is a better system for those issues.

        • chordsphere1@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          5 months ago

          Conversations being paid on the google play store is what’s stopping me from going xmpp… I can’t just say “message me via xmpp, you can use the Conversations app”. Now I’d have to explain what F-Droid is and why would they even get another app store and enable “unknown apps”. it’s not doable. I remember telling my mom to install Signal (before I got into self hosting) because I deleted whatsapp and she got angry like she worked for the zuck, saying “what do you mean you don’t use whatsapp” with an astonished face, started lecturing me on why I was destroying my social life… That just made me realize right now they probably wouldn’t download conversations either…welp I just wanted to share

          • Im_old@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            5 months ago

            I know exactly what you mean. Just for general information, I’ve found another android client that I think it’s better than Conversations. It’s called Monocles chat (and it’s on f-droid). On matrix/xmpp I install the whatsapp bridge. I can convert a few close family members but no way everyone. For me it’s an acceptable compromise. I get the close members to use my servers/apps, everyone else through the bridge so I can at least have all the chat in one place

      • Im_old@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 months ago

        Frienda no, but I do use whatsapp bridges so I can have all conversations in one place.

        Family with extreme nagging, and because I’m the IT guy of the house so they kinda trust me/can’t be bothered to try and out-talk me.

          • Im_old@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 months ago

            The chat server (matrix and xmpp have different ones, but same functionality) that act like a whatsapp desktop client. Have you ever run whatsapp desktop client on your pc, where you have to pair it with your phone? Same thing, but you do it withing a special “bridge” (usually as a bot) in matrix or xmpp. So you get all the messages in one place. But it doesn’t work for calls, just for messages.

  • bss03@infosec.pub
    link
    fedilink
    English
    arrow-up
    4
    ·
    5 months ago

    The other suggestions are probably better, but you can technically self-host Wire (from Wire Gmbh) but I’ve never done it successfully.

  • kugmo@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    5 months ago

    I know it’s not self hosted but why not Signal? Matrix is demanding on a SBC and your family would probably get the ‘unable to decrypt message, please re-verify keys’ error that happens in encrypted matrix group chats and Element does not have the best UI especially if you want your grandma to use it.

    • Senshi@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      5 months ago

      What’s your source on the reverify thing? I use matrix a lot, and this hasn’t been an issue I ever experienced anymore since they introduced cross-signing a couple years ago.

      Same goes for the common clients such as element. It has been clunky in the past, but after the past major overhauls ( also years ago now) everything has been silky smooth for me, if not better than others. The one thing left I prefer from Signal is the one-time photo share.

      Matrix is great, clients are great too, only the server part still is annoyingly complicated and messy. Would only recommend that for tinkerers, on that case it’s a great path to learning about the complexity of addressing lots of security concerns that others gloss over.

      Edit: to add - there’s a reason why the French government and the German military decided to build their secure internal IM infrastructure on Matrix. Obviously they are hosting their own private network, but if the concept is good enough for European government and military, it is an indicator for quality especially in terms of security and privacy.

  • Nine@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    5 months ago

    XMPP is fantastic IMHO

    If you want to support a great project and have great uptime check out conversations.im

    I don’t recommend self hosting something you want available all the time. That being said everyone has different needs/uses 😊

  • adr1an@programming.dev
    link
    fedilink
    English
    arrow-up
    2
    ·
    5 months ago

    E2E is complicated, if you self-host for a group, having TLS and encrypting data at rest (storage) may be enough. Get a threat model. That being said, I would recommend snikket.org which is a superset of extensions over XMPP which is the open source IM that was the base of almost every app out there. Matrix and Rocket are both alright too. Depends too on your resources, synapse requires too much RAM (or so I heard)

  • OSH@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 months ago

    Zulip hit’s the sweet spot for me, as it’s pretty straight forward to use and not too many bangs and whistle’s.

    Alternatively I’m also very happy with signal for communicating with other ones where Idon’t have to vother about user management too much.

      • EngineerGaming@feddit.nl
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 months ago

        I am suspicious of it because you pretty much cannot host a node. Well, you can - but you’d have to deposit an INSANE amount of money (like $2k or something). While Simplex, even though I do have a concern with its initial centralization by the power of default, is decidedly easy to selfhost.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    5 months ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    IP Internet Protocol
    RPi Raspberry Pi brand of SBC
    SBC Single-Board Computer
    SSL Secure Sockets Layer, for transparent encryption
    TLS Transport Layer Security, supersedes SSL
    VPS Virtual Private Server (opposed to shared hosting)
    XMPP Extensible Messaging and Presence Protocol (‘Jabber’) for open instant messaging

    5 acronyms in this thread; the most compressed thread commented on today has 7 acronyms.

    [Thread #809 for this sub, first seen 16th Jun 2024, 15:45] [FAQ] [Full list] [Contact] [Source code]

  • youmaynotknow@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    5 months ago

    I just have my kids, wife, close friends and in-laws on SimpleX.

    Sure, some of them use mainstream stuff as well, but if they want to reach me, that’s their only option.

    Matrix is a pretty good choice for self-hosted. The reason I don’t do it is because I’ve become lazy lately.